Skip to content
CMMC Level 1 — FAR 52.204-21

Free CMMC Level 1 Self-Assessment

Check all 17 FAR 52.204-21 controls in about 5 minutes. See your gap report instantly — no account, no CSV, no upload. Email required to unlock gaps beyond the first 3.

17 Level 1 controlsClick Met / Not MetNo account requiredFree gap report

Progress — 0/17 answered

0/17 answered

0

/ 17 met

017 controls
1
AC3.1.1

Authorized Access Control

Limit system access to authorized users, processes acting on behalf of authorized users, and devices.

2
AC3.1.2

Transaction & Function Control

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

3
AC3.1.20

External Connections

Verify and control/limit connections to external information systems.

4
AC3.1.22

Control CUI on Public Systems

Control information posted or processed on publicly accessible information systems.

5
AT3.2.1

Security Awareness Training

Ensure managers, system administrators, and users are made aware of security risks and applicable policies.

6
IA3.5.1

Identify Users & Devices

Identify information system users, processes acting on behalf of users, or devices.

7
IA3.5.2

Authenticate Users & Devices

Authenticate (or verify) the identities of users, processes, or devices before allowing access.

8
MP3.8.3

Media Sanitization

Sanitize or destroy information system media before disposal or reuse.

9
PE3.10.1

Limit Physical Access

Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.

10
PE3.10.3

Escort Visitors

Escort visitors and monitor visitor activity; maintain audit logs of physical access.

11
SC3.13.1

Boundary Protection

Monitor, control, and protect organizational communications at external boundaries and key internal boundaries.

12
SC3.13.2

Security Engineering

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security.

13
SC3.13.5

Public Access DMZ

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

14
SI3.14.1

Flaw Remediation

Identify, report, and correct information system flaws in a timely manner.

15
SI3.14.2

Malware Protection

Provide protection from malicious code at appropriate locations within organizational systems.

16
SI3.14.4

Update Malware Definitions

Update malicious code protection mechanisms when new releases are available.

17
SI3.14.5

Periodic System Scans

Perform periodic scans of the information system and real-time scans of files from external sources.

This tool is for estimation and educational purposes only. It does not constitute a formal CMMC self-assessment or a valid SPRS submission. For an official Level 2 certification, a C3PAO assessment is required. Nothing in this tool constitutes legal advice.

About CMMC Level 1

Who needs Level 1?

Any contractor who handles Federal Contract Information (FCI) — information provided by or generated for the government under a contract — but does NOT handle CUI must meet Level 1 requirements.

How is Level 1 certified?

Level 1 is a self-assessment. No C3PAO required. The contractor's senior official must annually affirm compliance and submit the SPRS score to SPRS.mil. A false affirmation is a False Claims Act violation.

What happens with CUI?

If your contract involves Controlled Unclassified Information, Level 2 applies — all 110 NIST SP 800-171 Rev 2 controls and a third-party C3PAO assessment. Use our Level 2 SPRS calculator for that.

The 17 controls cover which domains?

Access Control (4), Awareness & Training (1), Identification & Authentication (2), Media Protection (1), Physical Protection (2), System & Communications Protection (3), System & Information Integrity (4).

Need Level 2? If your DoD contract includes DFARS 252.204-7021 or handles CUI, Level 2 applies — 110 controls and a C3PAO assessment. Use the full SPRS calculator or start your Level 2 program in Aegis Firma.

Ready for full CMMC management?

Aegis Firma tracks your SPRS over time, manages POA&M deadlines, generates your SSP, and prepares you for the C3PAO assessment.

Start free assessment