Identify the information
Confirm what FCI you receive or create, where it lives, and who needs access to it.
A practical starting point for small businesses in the defense supply chain. Learn what Level 1 covers, see the 17 required practices, and prepare for your annual self-assessment.
CMMC Level 1 is for organizations that handle FCI but not Controlled Unclassified Information. The objective is basic cyber hygiene across the people, devices, systems, and service providers that store, process, or transmit that information.
Confirm what FCI you receive or create, where it lives, and who needs access to it.
Document the users, computers, networks, cloud services, and external providers involved.
Keep policies, screenshots, settings, logs, and other proof showing each practice is performed.
Each practice must be met. A policy alone is not enough—the safeguard needs to be implemented and supported by evidence.
Move from contract review to affirmation with a repeatable, evidence-based process.
Review contract clauses and data requirements. Determine whether you handle FCI only or whether CUI raises the requirement to Level 2.
Record how FCI enters, moves through, and leaves your organization, including cloud and managed service providers.
Test actual settings and processes. Capture evidence and assign an owner to correct every gap.
Complete the self-assessment in the required government system and have a senior official affirm continuing compliance.
Have questions about CMMC Level 1, FCI, or your contract requirements? Contact the Dispatch Tech team for practical guidance.
Email address copied. If your email app did not open, paste it into a new message.
This guide is educational and does not replace contract review, legal advice, or an official assessment. Confirm current requirements with your contracting officer and official CMMC guidance.