Defense suppliers

CMMC Level 1 self-check: the 15 FAR 52.204-21 requirements

A yes/no walk-through of every CMMC Level 1 requirement, written for a shop owner rather than an assessor. If you handle Federal Contract Information but no CUI, this is your whole list.

By Ed Wirsing, CISSP · Reviewed September 2026 · Not legal advice

First: are you Level 1 or Level 2?

If you receive or create Federal Contract Information (FCI) but not Controlled Unclassified Information (CUI), you are a Level 1 case. FCI is information "not intended for public release" that is provided by or generated for the government under a contract. Purchase orders, drawings marked for a government end item, and delivery schedules often qualify. CUI is a narrower, marked category (export controlled technical data, for example). If your prime sends anything marked CUI, or your contract carries DFARS 252.204-7012, you are a Level 2 case and this list is the floor, not the ceiling.

What Level 1 requires

Level 1 is an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, with an affirmation submitted in SPRS by a senior official. There is no POA&M at Level 1: every requirement must be met. Here is each one, with what it means in a small shop.

(i)

Limit system access to authorized users, processes acting on behalf of authorized users, and devices.

In plain terms: Everyone has their own login. No shared "shop" account. Ex-employees are removed the day they leave.

(ii)

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

In plain terms: The front desk cannot open the CNC programs folder. Admin rights are not the default.

(iii)

Verify and control/limit connections to and use of external information systems.

In plain terms: You know which personal devices and cloud services touch contract data, and you have a rule about it.

(iv)

Control information posted or processed on publicly accessible information systems.

In plain terms: Someone checks that nothing contract-related ends up on the website or a public share.

(v)

Identify information system users, processes acting on behalf of users, or devices.

In plain terms: Every user and device has a unique identity. Again: no shared accounts.

(vi)

Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access.

In plain terms: Passwords at minimum. MFA is not required at Level 1, but it is required at Level 2, so start now.

(vii)

Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

In plain terms: Old drives and USB sticks get wiped or shredded, and you can show that you did it.

(viii)

Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

In plain terms: The server closet locks. The office is not open to walk-ins after hours.

(ix)

Escort visitors and monitor visitor activity; maintain audit logs of physical access; control and manage physical access devices.

In plain terms: A visitor log, an escort rule, and you know who has keys and badges.

(x)

Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of the information systems.

In plain terms: A real firewall between you and the internet, configured by someone, not left on defaults.

(xi)

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

In plain terms: Guest Wi-Fi and anything public-facing are on a separate network from the shop.

(xii)

Identify, report, and correct information and information system flaws in a timely manner.

In plain terms: Patches get applied. Windows updates are not "postponed" for a year.

(xiii)

Provide protection from malicious code at appropriate locations within organizational information systems.

In plain terms: Antivirus or EDR on every machine.

(xiv)

Update malicious code protection mechanisms when new releases are available.

In plain terms: It updates itself, and someone would notice if it stopped.

(xv)

Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

In plain terms: Scheduled scans are on, and downloads get scanned.

Scoring yourself honestly

Go through the list with whoever runs your IT. Mark each one "met," "partly," or "no." Anything that is not fully "met" has to be fixed before you can truthfully affirm in SPRS. A false affirmation is not a paperwork problem; the Department of Justice has pursued False Claims Act cases over inaccurate cybersecurity attestations.

What usually needs fixing

  • Shared logins on shop-floor machines (requirements i, v, vi).
  • Guest Wi-Fi on the same network as the office (xi).
  • No written media-disposal process (vii).
  • No visitor log (ix).
  • A consumer router as the "firewall" (x).

Most Level 1 shops can close every gap in a few weeks with their existing IT provider. The Level 1 package is a fixed price for exactly that: scoping, assessment, the fix list, and the SPRS walkthrough.

Where things stand (September 2026)

CMMC requirements began appearing in DoD solicitations on November 10, 2025. In July 2026 DoD paused the Phase 2 rollout of third-party (C3PAO) certification pending a Reform Task Force review. Level 1 self-assessments, DFARS 7012 safeguarding, and SPRS scoring were not paused, and primes continue to flow requirements down to their suppliers regardless.

This guide pairs with the program page:

CMMC & NIST 800-171 readiness →

Get your program started

Talk to Ed

[email protected] · (772) 403-3088