Free · no signup · printable

CMMC Level 1 self-assessment checklist all 17 controls

The 15 FAR 52.204-21 safeguards, as the 17 NIST SP 800-171 controls DoD actually assesses. Each one in plain English, with what Met looks like and the evidence to keep. Level 1 has no POA&M: all 17 must be Met before you affirm in SPRS.

0of 17 met
16 to go before you can affirm
Track this in CMMC Map

Tick a control only when it is true for every system that stores, processes or sends Federal Contract Information. Open the details under each one to see what an assessor looks for.

Access Control (AC)0 / 4
3.1.1
L1 · 5 pts in SPRS
Authorized Access Control
Only people you have approved can get into systems holding CUI, each with their own account, on devices you control.
What Met looks like, evidence to keep, official text
Met means: Every user is listed and approved, no shared logins, and only company-managed devices reach CUI.
Evidence to keep: User list screenshot, admin console showing user accounts, device enrollment list, Access Control Policy.
NIST SP 800-171 3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices.
3.1.2
L1 · 5 pts in SPRS
Transaction & Function Control
People can only do what their job requires, a bookkeeper should not be able to change security settings.
What Met looks like, evidence to keep, official text
Met means: Permissions follow roles; nobody has more access than their job needs.
Evidence to keep: Access permissions screenshot, role configuration, Access Control Policy.
NIST SP 800-171 3.1.2: Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
3.1.20
L1 · 1 pt in SPRS
External System Connections
Check and limit connections to systems you do not control, personal devices, other companies’ networks.
What Met looks like, evidence to keep, official text
Met means: CUI accessed only from your own systems; any exception verified and approved in writing.
Evidence to keep: Network diagram, SSP interconnections table, documentation of platform as sole CUI system.
NIST SP 800-171 3.1.20: Verify and control/limit connections to and use of external information systems.
3.1.22
L1 · 1 pt in SPRS
Publicly Accessible Content
Make sure nobody posts CUI on your website or social media.
What Met looks like, evidence to keep, official text
Met means: Someone who knows what CUI is reviews public posts before they go live.
Evidence to keep: List of public systems, Content Review Policy, platform access documentation.
NIST SP 800-171 3.1.22: Control information posted or processed on publicly accessible information systems.
Identification & Authentication (IA)0 / 2
3.5.1
L1 · 5 pts in SPRS
User Identification
Every user, device, and process has its own identity.
What Met looks like, evidence to keep, official text
Met means: Individual accounts for everyone; devices identified through enrollment.
Evidence to keep: User account details, device enrollment list, Identification and Authentication Policy.
NIST SP 800-171 3.5.1: Identify users, processes, and devices.
3.5.2
L1 · 5 pts in SPRS
Device & Process Authentication
Verify identity before granting access, real authentication everywhere.
What Met looks like, evidence to keep, official text
Met means: Passwords plus MFA via your identity platform; no factory-default credentials anywhere.
Evidence to keep: Auth config, MFA documentation, device records.
NIST SP 800-171 3.5.2: Authenticate identities before allowing access.
Media Protection (MP)0 / 1
3.8.3
L1 · 5 pts in SPRS
Media Sanitization
Destroy or properly wipe CUI media before disposal, shred the paper, wipe the drives.
What Met looks like, evidence to keep, official text
Met means: Cross-cut shredder plus documented drive wiping; nothing with CUI goes in the trash.
Evidence to keep: Sanitization Policy, records, shredder documentation.
NIST SP 800-171 3.8.3: Sanitize or destroy media before disposal.
Physical Protection (PE)0 / 4
3.10.1
L1 · 5 pts in SPRS
Physical Access Limitation
Limit who can physically reach the computers and papers holding CUI.
What Met looks like, evidence to keep, official text
Met means: Locked office or room with keys held only by authorized people. Home office: a private, lockable space.
Evidence to keep: Physical security documentation, Physical Protection Policy.
NIST SP 800-171 3.10.1: Limit physical access to systems and equipment.
3.10.3
L1 · 1 pt in SPRS
Visitor Escort
Escort visitors anywhere CUI lives.
What Met looks like, evidence to keep, official text
Met means: No unescorted visitors: rule known and followed.
Evidence to keep: Visitor Policy, visitor log, Physical Protection Policy.
NIST SP 800-171 3.10.3: Escort visitors and monitor activity.
3.10.4
L1 · 1 pt in SPRS
Physical Access Logs
Keep a record of physical access, a visitor log counts.
What Met looks like, evidence to keep, official text
Met means: A visitor log, retained about 12 months.
Evidence to keep: Access/visitor log, Physical Protection Policy.
NIST SP 800-171 3.10.4: Maintain physical access audit logs.
3.10.5
L1 · 1 pt in SPRS
Physical Access Devices
Track keys, badges, and door codes, and recover them when people leave.
What Met looks like, evidence to keep, official text
Met means: An issuance list; lost keys mean changed locks.
Evidence to keep: Access device inventory, key management, Physical Protection Policy.
NIST SP 800-171 3.10.5: Control physical access devices.
System & Communications Protection (SC)0 / 2
3.13.1
L1 · 5 pts in SPRS
Boundary Protection
Guard the borders of your network and systems, firewall on-prem, controlled sign-in for cloud.
What Met looks like, evidence to keep, official text
Met means: Firewall with default-deny inbound; cloud access only through your controlled login.
Evidence to keep: Network diagram, firewall configs, encryption documentation.
NIST SP 800-171 3.13.1: Monitor, control, and protect communications at boundaries.
3.13.5
L1 · 5 pts in SPRS
Public Network Protection
Anything public-facing sits separated from your internal systems.
What Met looks like, evidence to keep, official text
Met means: Public website hosted outside the CUI environment. Often an easy Met for a COTS shop.
Evidence to keep: Network diagram, external hosting docs.
NIST SP 800-171 3.13.5: Separate publicly accessible components.
System & Information Integrity (SI)0 / 4
3.14.1
L1 · 5 pts in SPRS
Flaw Remediation
Patch security flaws promptly.
What Met looks like, evidence to keep, official text
Met means: Updates applied on a schedule (critical in ~15 days) and verified.
Evidence to keep: Patch records, update history, CISA reviews.
NIST SP 800-171 3.14.1: Identify, report, and correct flaws timely.
3.14.2
L1 · 5 pts in SPRS
Malicious Code Protection
Run malware protection where it matters, every computer, plus email.
What Met looks like, evidence to keep, official text
Met means: AV/EDR on every machine; email filtering on.
Evidence to keep: Antivirus config, scan logs, definition status.
NIST SP 800-171 3.14.2: Provide malicious code protection.
3.14.4
L1 · 5 pts in SPRS
Malicious Code Updates
Keep malware protection itself up to date.
What Met looks like, evidence to keep, official text
Met means: Auto-updates on, spot-checked periodically.
Evidence to keep: Update logs, version history.
NIST SP 800-171 3.14.4: Update malicious code protection.
3.14.5
L1 · 3 pts in SPRS
System & File Scanning
Scan on a schedule, and scan files from outside in real time.
What Met looks like, evidence to keep, official text
Met means: Real-time scanning on, plus periodic full scans.
Evidence to keep: Real-time config, weekly results, scan logs.
NIST SP 800-171 3.14.5: Perform periodic and real-time scans.

How a Level 1 self-assessment works

  1. Scope it. List every system that stores, processes or transmits Federal Contract Information: email, file shares, laptops, the accounting system if contract documents live there. If any of it touches Controlled Unclassified Information, you are at Level 2, not Level 1.
  2. Walk the 17 controls. Each has to be true for every in-scope system, not most of them. Write down how you meet it and what shows it: a user list, a screenshot of the firewall rule, the patch report.
  3. Fix what is not met. There is no POA&M at Level 1. A control that is not met means you cannot affirm yet.
  4. Affirm in SPRS. Your Affirming Official enters the self-assessment in the Supplier Performance Risk System and affirms it. Repeat every year.
Level 1 covers FCI only. The moment CUI is in scope you owe all 110 NIST SP 800-171 controls and an SPRS score. Use the free SPRS calculator to see where that would land.

Why 15 requirements become 17 controls

FAR 52.204-21 lists 15 safeguards. Two of them each cover two NIST SP 800-171 controls: limiting access (3.1.1 and 3.1.2 in access control) and physical access (3.10.1 with 3.10.3, 3.10.4 and 3.10.5). DoD's Level 1 assessment guide walks the 17 controls, so that is what this checklist uses.

Frequently asked

Is CMMC Level 1 15 requirements or 17 controls?
Both. FAR 52.204-21 lists 15 basic safeguarding requirements. DoD assesses them as 17 NIST SP 800-171 controls, because two of the FAR items each map to two controls. Your self-assessment covers all 17, and every one must be Met.
Can I use a POA&M at CMMC Level 1?
No. Level 1 has no Plan of Action and Milestones. Every control must be fully implemented before your Affirming Official affirms the assessment in SPRS. If one is not met, fix it first.
How often do I have to do the Level 1 self-assessment?
Annually. You complete the self-assessment, enter the result in the Supplier Performance Risk System, and your Affirming Official affirms it every year. A lapsed affirmation invalidates your status.
Who needs CMMC Level 1?
Any contractor or subcontractor that handles Federal Contract Information, which is nearly everyone with a DoD contract, and does not handle Controlled Unclassified Information. If CUI is in scope you need Level 2, all 110 controls, and an SPRS score.
Is CMMC Level 1 still required now that certification is paused?
Yes. The July 2026 suspension paused third-party certification, not the self-assessments. Level 1 and Level 2 self-assessments remain a current requirement in new solicitations and prime flow-downs.
Does this checklist save anything?
Only in your own browser, so you can come back to it. Nothing is sent anywhere. To keep evidence with each control and produce a record an assessor or prime can read, open the same 17 controls in CMMC Map, which is free to assess.

Keep the evidence with the checklist

CMMC Map walks the same 17 controls with evidence checklists, keeps your answers year to year, and prints a record your prime or an assessor can read. Level 1 and the full 110-control assessment are free.

Start free Try the SPRS calculator

Free to assess · No credit card · Documents from $149/mo