KNOWLEDGE BASE • UNDERSTANDING CMMC LEVEL 1 AND SPRS
Maintained by AffirmReady Support
If you have read the official CMMC Level 1 requirements and found the wording hard to follow, this article explains each one in everyday terms, along with what meeting it commonly looks like in a small business.
Where the requirements come from
CMMC Level 1 is made up of 15 basic safeguarding requirements taken from the federal contract clause FAR 52.204-21. They are grouped into six areas below. Their purpose is to protect Federal Contract Information (FCI) on the systems your company uses to do government work.
The examples below are common ways small businesses meet each requirement. They are not the only acceptable approach, and your company should decide what fits its own environment.
Access Control
- Only authorized people and devices can use your systems
Everyone who uses your computers, email, and business applications has their own account, and only approved company devices connect to your systems. Former employees are removed promptly. Example: each employee has an individual Microsoft 365 account, and accounts are disabled on an employee's last day.
- People can only do what their job requires
Users only have the permissions they need. Not everyone should be an administrator or have access to every folder. Example: only one or two people have admin rights, and accounting files are limited to the accounting team.
- Control connections to outside systems
You know and control which outside systems are used for company work, such as personal devices, personal email, or personal cloud storage. Example: a written rule that company information is not sent to personal email or stored on personal file-sharing accounts.
- Control what is posted publicly
Nothing that should stay private ends up on your public website, social media, or other public sites. Example: a named person reviews content before it is posted publicly.
Identification and Authentication
- Know who and what is on your systems
Every user and device can be identified. No shared or generic logins. Example: no shared "office@" account used by several people to sign in to systems.
- Verify identity before granting access
People prove who they are before getting in, usually with a password, and often with multi-factor authentication as well. Default passwords on devices are changed. Example: strong passwords are required, and the default password on the office router has been changed.
Media Protection
- Wipe or destroy media before disposal or reuse
Old computers, hard drives, USB drives, and paper records that contain FCI are wiped or destroyed before they are thrown away, donated, or reused. Example: retired hard drives are shredded by a disposal vendor who provides a certificate of destruction.
Physical Protection
- Limit physical access
Only authorized people can get into areas where your computers, servers, and network equipment are located. Example: the office is locked after hours and the network closet is kept locked.
- Manage visitors, keep access records, and control keys and badges
Visitors are escorted and supervised, you keep a record of who entered, and you know who has keys, badges, or door codes. Example: a visitor sign-in log at the front desk, a key list, and door codes changed when an employee leaves.
System and Communications Protection
- Protect your network boundary
A firewall monitors and controls traffic coming into and going out of your network. Example: a business-grade firewall at the office, and the built-in firewall turned on for every laptop.
- Separate anything public from your internal network
Systems the public can reach, such as guest Wi-Fi or a publicly accessible server, are kept separate from your internal business network. Example: guest Wi-Fi runs on its own network that cannot reach company computers.
System and Information Integrity
- Find and fix security flaws promptly
Operating systems and software are kept up to date with security patches. Example: Windows and Microsoft Office updates install automatically, and unsupported software is replaced.
- Protect against malware
Antivirus or endpoint protection runs on your computers. Example: Microsoft Defender or another endpoint protection product is active on every company device.
- Keep malware protection up to date
Your antivirus or endpoint protection automatically receives the latest updates. Example: automatic updates are turned on and checked periodically.
- Scan regularly and scan files from outside sources
Your protection scans systems on a schedule and checks files as they are downloaded, opened, or received from outside, such as email attachments and USB drives. Example: real-time protection is on, and a full scan is scheduled at least weekly.
How AffirmReady helps
AffirmReady's guided walkthrough explains each requirement in plain English, right next to the official regulatory text, with examples of what meeting it looks like. The evidence register lets you record what supports each requirement and where it is stored in your own systems. For help gathering evidence, see the evidence collection guides starting with KB-031.
Important
This article is a plain-language summary to help you understand the requirements. It is not legal advice and does not replace the official requirements. Your company is responsible for how it meets each requirement and for the accuracy of its affirmation.
Still need help?
If you have a question about a specific requirement, Email our support team at support@affirmready.com and include your company name and the email address on your AffirmReady account. We typically respond within one business day.