← Custodia
32 CFR 170.15

CMMC Level 1 Self-Assessment and Affirmation Requirements

Effective: December 16, 2024

In plain English

32 CFR 170.15 sets the procedural requirements for CMMC Level 1: an annual self-assessment against the 15 safeguarding requirements of FAR 52.204-21, scored on a binary MET / NOT MET basis with no POA&Ms permitted, followed by an annual affirmation posted in SPRS by a senior official with authority to bind the organization.

Who must comply

Any contractor or subcontractor whose covered information systems process, store, or transmit only FCI and not CUI.

What it requires

  1. 01Conduct a self-assessment of the contractor's compliance with the 15 safeguarding requirements in FAR 52.204-21(b)(1) at least annually.
  2. 02Score every assessment objective as MET or NOT MET — no partial credit, no scoring, no Plan of Action and Milestones permitted.
  3. 03Achieve MET on every objective to be considered CMMC Level 1 compliant.
  4. 04Have a senior official with authority to bind the company affirm continued compliance in SPRS at least annually after the initial self-assessment.

Key points

  • Level 1 is exclusively self-assessed — there is no C3PAO involvement at Level 1.
  • Because POA&Ms are not allowed, every requirement must be fully implemented before the affirmation is posted.
Primary source
Read 32 CFR 170.15 at its source

Related clauses

Related terms

Read more in the Library

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)