Back to Frameworks

CMMC 2.0 Level 1

United States
6 domains
17 controls

Cybersecurity Maturity Model Certification version 2.0 Level 1 (Foundational). 17 practices mapped to FAR 52.204-21.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Access Control

4 controls
Controls in the Access Control domain of CMMC 2.0 Level 14 controls
CodeTitle
AC.L1-3.1.1Authorized Access Control
AC.L1-3.1.2Transaction and Function Control
AC.L1-3.1.20External Connections
AC.L1-3.1.22Control Public Information

Identification and Authentication

2 controls
Controls in the Identification and Authentication domain of CMMC 2.0 Level 12 controls
CodeTitle
IA.L1-3.5.1Identification
IA.L1-3.5.2Authentication

Media Protection

1 controls
Controls in the Media Protection domain of CMMC 2.0 Level 11 controls
CodeTitle
MP.L1-3.8.3Media Disposal

Physical Protection

4 controls
Controls in the Physical Protection domain of CMMC 2.0 Level 14 controls
CodeTitle
PE.L1-3.10.1Limit Physical Access
PE.L1-3.10.3Escort Visitors
PE.L1-3.10.4Physical Access Logs
PE.L1-3.10.5Manage Physical Access

System and Communications Protection

2 controls
Controls in the System and Communications Protection domain of CMMC 2.0 Level 12 controls
CodeTitle
SC.L1-3.13.1Boundary Protection
SC.L1-3.13.5Public-Access System Separation

System and Information Integrity

4 controls
Controls in the System and Information Integrity domain of CMMC 2.0 Level 14 controls
CodeTitle
SI.L1-3.14.1Flaw Remediation
SI.L1-3.14.2Malicious Code Protection
SI.L1-3.14.4Update Malicious Code Protection
SI.L1-3.14.5System and File Scanning

Your Compliance Coverage

If you comply with CMMC 2.0 Level 1, you already cover:

Maps to 8 other frameworks

17 total controls
NIST SP 800-53 Rev 5
17 source controls mapped|11 target controls covered
100%
CMMC 2.0
17 source controls mapped|17 target controls covered
100%
NIST Cybersecurity Framework 2.0
4 source controls mapped|3 target controls covered
24%
ISO 27001:2022
1 source controls mapped|1 target controls covered
6%
ISO 27002:2022
1 source controls mapped|1 target controls covered
6%
ISO 22301:2019
1 source controls mapped|1 target controls covered
6%
ISO 9001:2015
1 source controls mapped|1 target controls covered
6%
ISO 10005:2005
1 source controls mapped|1 target controls covered
6%

Frequently Asked Questions

What is CMMC 2.0 Level 1?

CMMC 2.0 Level 1 is a compliance framework from United States with 6 domains and 17 controls. Cybersecurity Maturity Model Certification version 2.0 Level 1 (Foundational). 17 practices mapped to FAR 52.204-21. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CMMC 2.0 Level 1 have?

CMMC 2.0 Level 1 has 17 controls organised across 6 domains. The largest domains are Access Control (4 controls), Physical Protection (4 controls), System and Information Integrity (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CMMC 2.0 Level 1 map to?

CMMC 2.0 Level 1 maps to 8 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (100% coverage), CMMC 2.0 (100% coverage), NIST Cybersecurity Framework 2.0 (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CMMC 2.0 Level 1 compliance?

Start your CMMC 2.0 Level 1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CMMC 2.0 Level 1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required