Home / Resources / CMMC basics

CMMC basics

How many controls is CMMC Level 1? 15. Here is what that really means.

The short answer is 15 practices. The useful answer is 15 practices, 59 assessment objectives, and 6 domains, and the difference matters the moment someone assesses you.

The numbers, precisely

CMMC Level 1 requires the 15 basic safeguarding requirements of FAR 52.204-21, carried into the CMMC Program by 32 CFR Part 170. You will still see "17 practices" quoted around the internet. That figure is from the retired CMMC 1.0 model, which counted three of the requirements as five separate practices. Under the current rule it is 15, and citing 17 is a reliable sign of outdated guidance.

15 practices 59 assessment objectives 6 domains Annual self-assessment

Each practice breaks down into assessment objectives defined in the CMMC Assessment Guide for Level 1, 59 of them in total. A practice is only met when every one of its objectives is met, and that is the level at which an assessment actually happens. Treating the 15 as simple checkboxes is the most common Level 1 mistake we see.

The six domains

The 15 practices fall into six of the fourteen CMMC domains: Access Control (AC), Identification & Authentication (IA), Media Protection (MP), Physical Protection (PE), System & Communications Protection (SC), and System & Information Integrity (SI). They cover fundamentals like limiting system access to authorized users, sanitizing media before disposal, escorting visitors, and keeping malware protection current.

Who needs Level 1, and what it takes

Level 1 applies when you handle Federal Contract Information (FCI): information provided by or generated for the government under contract and not intended for public release. Verification is an annual self-assessment, with the result and an affirmation submitted in SPRS by a senior company official. There is no third-party assessor at Level 1 and no POA&M option: every practice must be fully met to report compliance.

Scope matters as much as the count. The official Level 1 scoping guide draws the boundary around assets that process, store, or transmit FCI, and a sensible scope is often the difference between a weekend of work and a quarter of it.

Questions about your situation?

A short conversation usually settles it. No pitch, just answers.

Talk to CyberDeka