FrameworkMapper
DoD Contractor Self-Assessment

CMMC Level 1 Assessment

Prepare for CMMC certification with our self-assessment tool covering the 17 foundational practices required to protect Federal Contract Information (FCI).

CMMC

What is CMMC Level 1?

The Cybersecurity Maturity Model Certification (CMMC) Level 1 represents the foundational tier of cybersecurity practices required for organizations handling Federal Contract Information (FCI) in Department of Defense contracts.

17 Practices

A focused set of basic cyber hygiene practices that form the foundation of cybersecurity for DoD contractors.

Annual Self-Assessment

Level 1 requires annual self-assessment — no third-party certification needed. Results must be entered into SPRS.

FCI Protection

Designed to protect Federal Contract Information — information not intended for public release provided by or generated for the government.

6 Security Domains

CMMC Level 1 practices are organized into 6 security domains, each addressing a specific area of cybersecurity protection.

AC

Access Control

Limit system access to authorized users, processes, and devices. Control what information users can access and what they can do with it.

4 Practices
IA

Identification & Authentication

Verify the identity of users, processes, and devices before granting access to organizational systems.

2 Practices
MP

Media Protection

Protect information system media containing FCI, both paper and digital, and limit access to authorized personnel.

1 Practice
PE

Physical Protection

Limit physical access to systems, equipment, and operating environments to authorized individuals.

4 Practices
SC

System & Communications Protection

Monitor, control, and protect communications at external and key internal boundaries of information systems.

2 Practices
SI

System & Information Integrity

Identify, report, and correct system flaws in a timely manner. Provide protection from malicious code.

4 Practices

Who Needs CMMC Level 1?

DoD Contractors

Any organization that handles Federal Contract Information (FCI) as part of a DoD contract.

Subcontractors

Companies in the defense supply chain that receive FCI from prime contractors.

New DoD Bidders

Organizations preparing to bid on DoD contracts that will require CMMC certification.

Level 2 Preparation

Organizations using Level 1 as a stepping stone toward CMMC Level 2 certification.

CMMC Level 1 Assessment Dashboard

How the Assessment Works

Our assessment tool guides you through all 17 practices with clear explanations and helps you document your compliance status for SPRS submission.

1

Select a Domain

Navigate through the 6 security domains, reviewing practices in each area.

2

Evaluate Each Practice

For each practice, assess your current implementation: Met, Partially Met, or Not Met.

3

Document Evidence

Add notes describing how you implement each practice and any supporting evidence.

4

Generate Reports

Download your assessment report for internal review and SPRS documentation.

Time Estimate

A complete Level 1 assessment typically takes 30-60 minutes for organizations with basic documentation already in place.

What to Have Ready

  • Current access control policies
  • Physical security procedures
  • Antivirus/malware protection info
  • User authentication methods
CMMC Level 1 Practice Assessment Interface

What You'll Receive

Generate comprehensive reports to document your CMMC Level 1 compliance status and support your SPRS submission requirements.

Assessment Report

Complete assessment results showing compliance status for each practice, organized by domain with summary statistics.

  • All 17 practices detailed
  • Domain-by-domain breakdown
  • Your implementation notes
Download Sample PDF

SPRS Documentation

Supporting documentation formatted to help with your Supplier Performance Risk System (SPRS) score submission.

  • Compliance status summary
  • Assessment date tracking
  • Gap identification
Download Sample PDF

Encrypted Backup

A password-protected JSON file containing all your assessment data. Use it to restore your assessment or transfer between devices.

  • AES-256 encryption
  • Complete data export
  • Easy restore process
Generated from your data
CMMC Level 1 Compliance Report
CMMC Level 1 POA&M Domain Summary

Level 1 vs Level 2: Which Do You Need?

The right CMMC level depends on the type of information you handle in your DoD contracts.

Level 1 You are here

Federal Contract Information (FCI)

  • 17 practices across 6 domains
  • Annual self-assessment
  • No third-party certification required
  • Basic cyber hygiene
Level 2

Controlled Unclassified Information (CUI)

  • 110 practices across 14 domains
  • Triennial third-party assessment (C3PAO)
  • Aligned with NIST SP 800-171
  • Advanced cyber hygiene
Learn about Level 2

Ready to Assess Your CMMC Level 1 Readiness?

Try our CMMC Level 1 assessment tool with a free trial. Document your compliance status and prepare for your SPRS submission.