Foundational safeguarding for FCI

Make CMMC Level 1 understandable.

A practical starting point for small businesses in the defense supply chain. Learn what Level 1 covers, see the 17 required practices, and prepare for your annual self-assessment.

17security practices
6security domains
Annualself-assessment and affirmation
Know your scope

Level 1 protects Federal Contract Information.

CMMC Level 1 is for organizations that handle FCI but not Controlled Unclassified Information. The objective is basic cyber hygiene across the people, devices, systems, and service providers that store, process, or transmit that information.

01

Identify the information

Confirm what FCI you receive or create, where it lives, and who needs access to it.

02

Define the environment

Document the users, computers, networks, cloud services, and external providers involved.

03

Collect evidence

Keep policies, screenshots, settings, logs, and other proof showing each practice is performed.

The requirement set

17 practices across 6 domains

Each practice must be met. A policy alone is not enough—the safeguard needs to be implemented and supported by evidence.

Access Control — 4 practicesLimit systems, transactions, and external connections to authorized use.
Identification & Authentication — 2Identify users and authenticate them before granting access.
Media Protection — 1Sanitize or destroy media before disposal or reuse.
Physical Protection — 4Control, escort, monitor, and log physical access.
System & Communications Protection — 2Monitor boundaries and separate public-facing components.
System & Information Integrity — 4Correct flaws, use malware protection, and scan files and systems.
A practical sequence

Your Level 1 readiness path

Move from contract review to affirmation with a repeatable, evidence-based process.

Confirm Level 1 applies

Review contract clauses and data requirements. Determine whether you handle FCI only or whether CUI raises the requirement to Level 2.

Map your FCI flow

Record how FCI enters, moves through, and leaves your organization, including cloud and managed service providers.

Assess all 17 practices

Test actual settings and processes. Capture evidence and assign an owner to correct every gap.

Submit and affirm annually

Complete the self-assessment in the required government system and have a senior official affirm continuing compliance.

Common questions

CMMC Level 1 FAQ

Straightforward answers for contractors beginning their compliance journey.

Who needs Level 1?

Organizations that handle Federal Contract Information but do not process, store, or transmit Controlled Unclassified Information.

Is an outside assessment required?

Level 1 uses an annual self-assessment, followed by an affirmation from a senior company official.

What if we handle CUI?

Handling CUI generally places the organization at Level 2. Review the contract and data flow before choosing a path.

Talk to a CMMC specialist

Have questions about CMMC Level 1, FCI, or your contract requirements? Contact the Dispatch Tech team for practical guidance.

Call 858-344-3988

This guide is educational and does not replace contract review, legal advice, or an official assessment. Confirm current requirements with your contracting officer and official CMMC guidance.