Skip to content
CMMC Level 1 — 17 Practices

CMMC Level 1 Self-Assessment

Answer 17 questions and get your SPRS score instantly. Takes 5 minutes.

0 / 17

Access Control

Limit system access to authorised users

Only authorised employees can access your company systems (computers, email, cloud tools).

Limit system access to authorised functions

Users can only access data and functions their role requires — not everything.

Control information flow on external connections

Your network has a firewall or router that controls what traffic comes in and out.

Separate duties of individuals

No single person has unrestricted access to all critical systems (e.g., approve and pay invoices).

Identification & Authentication

Identify users before allowing access

Every user has a unique username — no shared accounts used.

Authenticate users before allowing access

Users must provide a password (or better — MFA) to access systems.

Media Protection

Sanitise or destroy media before disposal

Old hard drives, USB sticks, and phones are wiped before disposal or reuse.

Physical Protection

Limit physical access to authorised individuals

Only authorised people can physically enter your office / server room.

Escort visitors and monitor activity

Visitors to your premises are escorted or supervised while on-site.

Maintain audit logs of physical access

You keep a record (even a sign-in sheet) of who visits your physical locations.

System & Comms Protection

Monitor communications at system boundaries

You have tools that detect unusual network activity (e.g., firewall logs, router alerts).

Implement subnetworks for publicly accessible systems

Your public-facing website/app is separated from your internal business network.

System & Info Integrity

Identify, report, and correct information system flaws

You apply software updates and security patches in a timely manner.

Provide protection from malicious code

All computers and servers have anti-malware / antivirus software installed and updated.

Update malicious code protection mechanisms

Anti-malware definitions are updated automatically or at least weekly.

Perform periodic scans and real-time scanning

You run regular malware scans and have real-time protection enabled.

Monitor information systems to detect attacks

You have some form of monitoring or alerting for potential cyber attacks.