The entry point of the CMMC 2.0 framework, designed to ensure contractors handling Federal Contract Information (FCI) implement basic cybersecurity hygiene. Level 1 requires organizations to put in place 17 fundamental security practices, which are derived directly from the safeguarding requirements in FAR 52.204-21.
These practices include straightforward measures such as enforcing strong passwords, limiting system access to authorized users, protecting devices with updated antivirus software, and properly sanitizing or destroying media before disposal. While not as rigorous as higher levels, Level 1 establishes the minimum safeguards needed to prevent unauthorized disclosure of government contract data.
Certification at Level 1 is achieved through annual self-assessments submitted into the Supplier Performance Risk System (SPRS). This tier applies to contractors who do not handle Controlled Unclassified Information (CUI) but still need to demonstrate a baseline commitment to protecting DoD information.