Subcontractor CMMC Tracker

CMMC Level 1 (Self): what a subcontractor handling FCI only declares

Level 1 covers Federal contract information. 32 CFR 170.14(c)(2) sets its requirements as those of FAR 52.204-21(b)(1)(i) through (xv): fifteen requirements. They are set out below as seventeen practice codes because (b)(1)(ix), which asks for three things (escort visitors and monitor visitor activity, keep physical access logs, control and manage physical access devices), carries three codes, PE.L1-3.10.3, PE.L1-3.10.4 and PE.L1-3.10.5; every other paragraph carries one. A subcontractor that will only process, store or transmit FCI needs Level 1 (Self) (32 CFR 170.23(a)(1)). The self-assessment is annual, an affirmation follows it every year, and no POA&M is permitted.

The rule sentences

5 cited
32 CFR 170.23(a)(1)codified text, eCFR current to 24 Sep 2026

If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.

Threshold read: FCI only: Level 1 (Self). Source
32 CFR 170.15(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.

Threshold read: Level 1 (Self) assessment: annual. Source
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 1: not older than 1 year. Source
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026

An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.

Threshold read: affirmation after every assessment and annually thereafter. Source
32 CFR 170.21(a)(1)codified text, eCFR current to 24 Sep 2026

A POA&M is not permitted at any time for Level 1 self-assessments.

Threshold read: no POA&M at Level 1. Source

The fifteen requirements as seventeen practice codes

FAR 52.204-21(b)(1)(i) to (xv)
CMMC L1 AC.L1-3.1.1Authorized Access Control

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.1: Authorized Access Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(i) (3.1.1).

What an assessor asks to see: Account inventory limiting system access to authorized users, processes and devices; Access authorization records
Where subcontractors usually fall short: Shared/unauthorized accounts with FCI access
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 AC.L1-3.1.2Transaction and Function Control

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.2: Transaction and Function Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ii) (3.1.2).

What an assessor asks to see: Role/permission matrix limiting access to permitted transactions and functions
Where subcontractors usually fall short: Users able to execute functions beyond their role
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 AC.L1-3.1.20External Connections

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.20: External Connections - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iii) (3.1.20).

What an assessor asks to see: Inventory + authorization of external system connections; Controls verifying/limiting use of external systems
Where subcontractors usually fall short: Unverified external connections to FCI systems
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 AC.L1-3.1.22Control Public Information

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.22: Control Public Information - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iv) (3.1.22).

What an assessor asks to see: Review/approval process for information posted to publicly accessible systems
Where subcontractors usually fall short: FCI inadvertently posted publicly
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 IA.L1-3.5.1Identification

CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.1: Identification - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(v) (3.5.1).

What an assessor asks to see: Unique identifiers for users, processes and devices
Where subcontractors usually fall short: Shared or generic accounts
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 IA.L1-3.5.2Authentication

CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.2: Authentication - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vi) (3.5.2).

What an assessor asks to see: Authentication mechanism verifying identities before access; Authenticator management
Where subcontractors usually fall short: Identities not authenticated before granting FCI access
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 MP.L1-3.8.3Media Disposal

CMMC 2.0 Level 1 (Foundational) practice MP.L1-3.8.3: Media Disposal - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vii) (3.8.3).

What an assessor asks to see: Media sanitization/destruction procedure for FCI media before disposal or reuse; Sanitization records
Where subcontractors usually fall short: FCI media disposed without sanitization
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 PE.L1-3.10.1Limit Physical Access

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.1: Limit Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(viii) (3.10.1).

What an assessor asks to see: Physical access authorization limiting access to systems/equipment/operating environments
Where subcontractors usually fall short: Uncontrolled physical access to FCI systems
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 PE.L1-3.10.3Escort Visitors

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.3: Escort Visitors - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.3).

What an assessor asks to see: Visitor escort and activity-monitoring procedure
Where subcontractors usually fall short: Unescorted visitors in FCI areas
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 PE.L1-3.10.4Physical Access Logs

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.4: Physical Access Logs - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.4).

What an assessor asks to see: Audit logs of physical access maintained
Where subcontractors usually fall short: No physical access logging
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 PE.L1-3.10.5Manage Physical Access

CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.5: Manage Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.5).

What an assessor asks to see: Control and management of physical access devices (keys, badges, locks)
Where subcontractors usually fall short: Physical access devices not tracked/recovered
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SC.L1-3.13.1Boundary Protection

CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.1: Boundary Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(x) (3.13.1).

What an assessor asks to see: Boundary protection monitoring/controlling communications at external/key internal boundaries
Where subcontractors usually fall short: No boundary protection around FCI systems
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SC.L1-3.13.5Public-Access System Separation

CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.5: Public-Access System Separation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xi) (3.13.5).

What an assessor asks to see: Subnetworks for publicly accessible components separated from internal networks (DMZ)
Where subcontractors usually fall short: Public-facing components on the internal FCI network
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SI.L1-3.14.1Flaw Remediation

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.1: Flaw Remediation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xii) (3.14.1).

What an assessor asks to see: Flaw identification/reporting/remediation (patch management) records
Where subcontractors usually fall short: Known flaws unpatched
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SI.L1-3.14.2Malicious Code Protection

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.2: Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiii) (3.14.2).

What an assessor asks to see: Malicious-code protection deployed at appropriate locations
Where subcontractors usually fall short: No anti-malware on FCI systems
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SI.L1-3.14.4Update Malicious Code Protection

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.4: Update Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiv) (3.14.4).

What an assessor asks to see: Anti-malware signature/engine update process
Where subcontractors usually fall short: Outdated malware definitions
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L1 SI.L1-3.14.5System and File Scanning

CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.5: System and File Scanning - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xv) (3.14.5).

What an assessor asks to see: Periodic system scans + real-time scanning of external-source files
Where subcontractors usually fall short: No periodic or real-time scanning
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)

Confirm which deviation your contracting officer's agency has adopted. The register records what a subcontractor declares; it does not look anything up in SPRS.