CMMC Level 1 (Foundational)
The basic CMMC tier requiring the 15 safeguarding requirements at FAR 52.204-21(b)(1)(i)-(xv) for protecting Federal Contract Information (32 CFR 170.14(c)(2)). Allows annual self-assessment.
Related Terms
CMMC
A DoD framework requiring defense contractors to meet specific cybersecurity standards before handling federal contract information.
FCI
Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service.
CMMC Level 2 (Advanced)
The mid-tier CMMC level requiring all 110 NIST SP 800-171 controls. Third-party (C3PAO) assessment at this level was suspended as an award condition in July 2026 pending review; Level 2 self-assessment remains in force.
Related Guides
Check Your CMMC Readiness
Run our free compliance tools to see where your organization stands.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This CMMC Level 1 (Foundational) explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessment