CMMC Level 1 is the basic safeguarding level for Federal Contract Information, but 'basic' should not be read as 'paperwork only.' The current program ties Level 1 to the 15 requirements in FAR 52.204-21, an annual self-assessment, and an annual affirmation. A small contractor can keep the evidence set lean, provided the controls are actually present in the system that handles FCI.
A practical Level 1 review works best when it follows how people use the environment: who can sign in, which devices can reach the data, how media is handled, what protects the network boundary, how flaws are corrected, and how access ends when someone leaves. That sequence turns the regulation into observable work instead of a list of copied sentences.
Identify where FCI arrives and where it can go. For many small businesses, the path may include email, a file share, a collaboration tenant, a few managed laptops, printers, and backup. Write down the actual path instead of labeling the whole company 'Level 1.' If a personal device or unmanaged mailbox can still receive the information, include that fact in the review rather than designing the scope around what you hope users do.
1. Draw the FCI boundary before checking controls
Your asset record does not need enterprise-CMDB complexity. A stable device or service identifier, owner, location, purpose, management method, and reason it is in scope are enough to make the boundary testable. Reconcile the list with the tools you already have, such as endpoint management, identity administration, and purchasing records.
2. Check access and identity with real accounts
Several of the FAR safeguards are easiest to test by looking at user and administrator access. Confirm that only authorized users, devices, and processes can reach the covered system; that users are limited to the functions they are permitted to perform; and that remote or external connections are controlled. Shared logins make those questions much harder to answer because they erase individual accountability.
Pull a current user list and compare it with employees and contractors who actually need access. Look for departed users, dormant accounts, generic administrator IDs, and exceptions that were granted temporarily but never removed. Keep the review record. A dated access review is stronger evidence than a policy paragraph saying access is 'reviewed periodically.'
3. Protect devices, media, and public exposure
Level 1 includes requirements around physical access, media sanitation, and limiting what a covered system exposes to public-facing systems. Walk the office and the workflow. Can visitors reach a workstation? Do printers retain jobs? Are USB drives used for FCI? Can employees copy files into personal cloud storage? Is any sensitive contract material accidentally present on a public website or support portal?
For media disposal or reuse, document the method used to sanitize or destroy the media. For portable storage, define what is allowed, who approves it, and how it is protected. Do not create a complicated policy that the business cannot follow. A short rule backed by device settings and purchasing practice will outperform a polished document that users routinely bypass.
4. Verify boundary and malicious-code protections
The safeguarding requirements also cover monitoring and control of communications at system boundaries, protection against malicious code, and timely updates when flaws are identified. For a small cloud-first environment, evidence may come from firewall or secure-access settings, endpoint-protection consoles, operating-system update reports, and service-provider configuration rather than from a rack of network hardware.
Test a sample instead of taking screenshots of everything. Pick one managed laptop and confirm its protection agent is healthy, recent updates are installed, and the device is receiving the intended configuration. Then check the administrative console showing the broader population. That combination demonstrates both the system-level design and an operating endpoint.
5. Do not use a POA&M to hide a Level 1 miss
Level 1 has no POA&M safety valve. When a required safeguard is missing, fix the condition first and assess the environment that exists after the change. This makes Level 1 less tolerant of 'we plan to do that next quarter' answers than many teams expect.
Keep a normal internal remediation list if work remains; just do not confuse that project tracker with permission to claim a successful Level 1 result. Before affirmation, have someone other than the implementer sample the evidence and ask a simple question for each safeguard: can we show what is configured, who owns it, and a recent example that it operates?
6. Package the annual evidence so next year is easier
Create one folder or evidence index for the annual cycle. Store the scope note, asset list, assessment worksheet, selected evidence, remediation records, and affirmation confirmation with dates in the filenames or metadata. Avoid dumping every security screenshot into the folder. Keep only the artifacts that explain the control and can be reproduced when needed.
At the end of the cycle, write down what would force an early re-review: a new collaboration platform, unmanaged remote work, a merger, a new office, a change in identity provider, or a new way of receiving FCI. That trigger list keeps the Level 1 record connected to the living system instead of turning it into a once-a-year compliance photograph.
A small-business walkthrough from inbox to archive
Imagine a six-person machine shop that receives non-public delivery instructions and contract correspondence by email but no CUI. The owner, estimator, and production manager use company laptops; accounting uses a separate system. The Level 1 boundary review begins with the mailboxes and file locations that hold FCI, then follows access to the three users and the devices they use.
The shop discovers that the owner's old laptop still has an active account, the production manager prints contract instructions to a shared device near the lobby, and a generic 'shopadmin' account is used to install software. None of those findings requires a sophisticated security platform. They require account cleanup, a controlled print workflow, and named administrative access with basic evidence that the changes occurred.
Where the walkthrough usually breaks
For annual evidence, the shop keeps a user list, a device-management export, a screenshot of boundary or endpoint protections, a media-handling procedure, a record of the annual review, and proof of the assessment and affirmation. It does not create a 200-page policy manual that nobody uses.
The next-year review starts from the same boundary and asks what changed: new employee, new laptop, new cloud storage, new printer, or a new way of receiving contract data. That continuity is the real value of the Level 1 file. The assessment becomes a maintenance exercise rather than a fresh compliance project every 12 months.
A short working check
- ✓Map the system that handles FCI
- ✓Review all 15 FAR 52.204-21 safeguards
- ✓Remove shared or stale access where possible
- ✓Document device and media controls
- ✓Collect evidence for each safeguard
- ✓Complete and affirm the self-assessment as required
- ✓Retain the dated annual review record
Common questions
How many practices are in CMMC Level 1?
Level 1 aligns to 15 basic safeguarding requirements from FAR 52.204-21.
Can Level 1 use a POA&M?
The CMMC Level 1 model does not use a POA&M to defer unmet requirements for the assessment result.
Does Level 1 mean a contractor can handle CUI in the same environment?
Level 1 is the FCI safeguarding level. If the work involves CUI, review the solicitation and the Level 2 requirements and scope rather than assuming a Level 1 environment is sufficient.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.



