Most defense subcontractors handle FCI but not CUI — janitorial, landscaping, food service, basic supplies. For these contractors, Level 1 is the floor and Level 2 is not required.
What FCI is
Federal Contract Information is non-public information provided by or generated for the government under a contract that is not intended for public release. It covers contract terms, performance data, communications with the contracting officer, and similar artifacts. FCI is not:
- Press releases or other public-release information.
- Information about basic transactions (the FAR exempts simple commercial purchases).
- Controlled Unclassified Information (CUI) — a separate, more sensitive category with its own markings.
If your contract has any FCI handling, FAR 52.204-21 applies, which makes CMMC Level 1 the floor under 32 CFR § 170.15.
The 17 Level 1 practices
Level 1 implements the 15 basic safeguarding requirements from FAR 52.204-21(b)(1) as 17 CMMC practices. They cover:
- Access control (limit access to authorized users and authorized functions; control external connections; control public-facing systems).
- Identification and authentication (identify users and authenticate them).
- Media protection (sanitize or destroy media before disposal).
- Physical protection (limit physical access, escort visitors, maintain physical access logs and physical access devices).
- System and communications protection (monitor and control communications at external boundaries; subnetwork publicly accessible systems).
- System and information integrity (patch flaws; antivirus / malicious code protection; update protection mechanisms; scan files from external sources).
The Level 1 process
- Annual self-assessment against the 17 practices.
- Score submitted to the Supplier Performance Risk System (SPRS).
- Annual affirmation by a senior company official affirming compliance.
- No C3PAO involvement.
When you cross into Level 2
The Level 1 floor stops applying the moment any of the following is true:
- A contract delivers or generates information marked CUI.
- The contract includes DFARS clauses governing CUI handling.
- Your organization generates information that would be CUI under 32 CFR Part 2002.
At that point you are at CMMC Level 2 under 32 CFR § 170.16 (self-assessment, where allowed) or § 170.17 (C3PAO certification assessment), and the L2 scoping guide applies.
Common errors
- Assuming Level 1 covers CUI. It doesn't. FAR 52.204-21 protections are weaker than the protections required for CUI.
- Skipping the annual affirmation. Without the affirmation, you are not Level 1 compliant regardless of technical controls in place.
- Not reading contract clauses carefully. Contracts often include CMMC-relevant clauses without a sentence calling out "CMMC" by name.