CMMC

CMMC Level 1

The CMMC tier for defense contractors that handle only Federal Contract Information and not CUI. Level 1 requires implementation of the 17 basic safeguarding requirements drawn from FAR 52.204-21 and is satisfied by an annual self-assessment with senior official affirmation submitted to SPRS. No third-party assessment is required, but a knowingly false affirmation carries False Claims Act exposure.

The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.