15 practices focused on cyber hygiene
|

CHECKLIST: The 15 Foundational CMMC 2.0 Level 1 Requirements

Navigating cybersecurity for your shop can seem like a labyrinth, especially for manufacturers handling Federal Contract Information (FCI). With the DoD’s CMMC 2.0 final rule posted, we’re here to help simplify the process.


CMMC 2.0 Level 1 is the entry point for compliance, focusing on securing Federal Contract Information (FCI). Unlike higher levels, Level 1 allows for self-assessment, which must be completed annually and reported to the Supplier Performance Risk System (SPRS). To complete a CMMC 2.0 Level 1 self-assessment, manufacturers must follow 15 foundational practices outlined in FAR Clause 52.204-21 and ensure they are implemented across all systems.

To ensure you’re on the easiest path to success, check out our on-demand webinar, How to Streamline Your CMMC 2.0 Compliance. Then, download our comprehensive CMMC 2.0 Level 1 checklist to start your journey toward compliance. The checklist outlines the 15 foundational practices focused on cyber hygiene across your systems. Implementing these controls establishes a foundational layer of security to protect FCI and helps your shop mitigate risk.

Key Dates to Remember

This phased approach provides contractors with a clear roadmap for achieving compliance while minimizing disruptions*.

Update (July 2026): On July 13, 2026, the Department of War suspended CMMC Phase 2 — the November 10, 2026 deadline — along with all pending and future CMMC rollout milestones, and opened a 60-day review of the program. Phase 1 self-assessment requirements remain firmly in place. For Level 1 shops, this changes almost nothing: Level 1 was always self-assessed, never third-party assessed, so your path is intact. You still self-assess against the 15 requirements below.

Here’s where each phase stands now:

Phase 1 — November 10, 2025 (in effect): CMMC clauses appear in new DoD solicitations and contract awards. Level 1 and Level 2 self-assessments are required as a condition of award for applicable contracts. This is the piece that’s still live.

Phase 2 — was November 10, 2026 (suspended): Would have made third-party (C3PAO) Level 2 the default for CUI contracts and stopped self-assessments from counting. Suspended July 13, 2026, pending the reform review. No replacement date has been set.

Phase 3 — was November 10, 2027 (suspended): Would have made C3PAO Level 2 a condition for option exercises on existing contracts, and made Level 3 (DIBCAC) mandatory in applicable solicitations. Swept up in the suspension of future milestones.

Phase 4 — was November 10, 2028 (suspended): Full implementation across all applicable DoD contracts above the micro-purchase threshold. Also on hold.

What applies in the meantime: During the review, the DoW is enforcing cybersecurity through NIST SP 800-171 Rev 2 self-assessments and DFARS 252.204-7012 — the safeguarding obligation that never went away. A CMMC Reform Task Force will report to the DoW CIO within 60 days, drawing on a public request for information due August 14, 2026.

Start Your Free Assessment

If you’re preparing for CMMC 2.0 Level 1 compliance, our technology partner, Carbide, offers a free Self-Assessment Tool to help you navigate the process. This tool provides step-by-step guidance and generates a report identifying any gaps that must be addressed to meet the requirements.

*For more guidance, consult resources such as the DoD’s CMMC documentation and self-assessment guides.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

Similar Posts