CHECKLIST: The 15 Foundational CMMC 2.0 Level 1 Requirements
Navigating cybersecurity for your shop can seem like a labyrinth, especially for manufacturers handling Federal Contract Information (FCI). With the DoD’s CMMC 2.0 final rule posted, we’re here to help simplify the process.
CMMC 2.0 Level 1 is the entry point for compliance, focusing on securing Federal Contract Information (FCI). Unlike higher levels, Level 1 allows for self-assessment, which must be completed annually and reported to the Supplier Performance Risk System (SPRS). To complete a CMMC 2.0 Level 1 self-assessment, manufacturers must follow 15 foundational practices outlined in FAR Clause 52.204-21 and ensure they are implemented across all systems.
To ensure you’re on the easiest path to success, check out our on-demand webinar, How to Streamline Your CMMC 2.0 Compliance. Then, download our comprehensive CMMC 2.0 Level 1 checklist to start your journey toward compliance. The checklist outlines the 15 foundational practices focused on cyber hygiene across your systems. Implementing these controls establishes a foundational layer of security to protect FCI and helps your shop mitigate risk.
Key Dates to Remember
This phased approach provides contractors with a clear roadmap for achieving compliance while minimizing disruptions*.
Update (July 2026): On July 13, 2026, the Department of War suspended CMMC Phase 2 — the November 10, 2026 deadline — along with all pending and future CMMC rollout milestones, and opened a 60-day review of the program. Phase 1 self-assessment requirements remain firmly in place. For Level 1 shops, this changes almost nothing: Level 1 was always self-assessed, never third-party assessed, so your path is intact. You still self-assess against the 15 requirements below.
Here’s where each phase stands now:
Phase 1 — November 10, 2025 (in effect): CMMC clauses appear in new DoD solicitations and contract awards. Level 1 and Level 2 self-assessments are required as a condition of award for applicable contracts. This is the piece that’s still live.
Phase 2 — was November 10, 2026 (suspended): Would have made third-party (C3PAO) Level 2 the default for CUI contracts and stopped self-assessments from counting. Suspended July 13, 2026, pending the reform review. No replacement date has been set.
Phase 3 — was November 10, 2027 (suspended): Would have made C3PAO Level 2 a condition for option exercises on existing contracts, and made Level 3 (DIBCAC) mandatory in applicable solicitations. Swept up in the suspension of future milestones.
Phase 4 — was November 10, 2028 (suspended): Full implementation across all applicable DoD contracts above the micro-purchase threshold. Also on hold.
What applies in the meantime: During the review, the DoW is enforcing cybersecurity through NIST SP 800-171 Rev 2 self-assessments and DFARS 252.204-7012 — the safeguarding obligation that never went away. A CMMC Reform Task Force will report to the DoW CIO within 60 days, drawing on a public request for information due August 14, 2026.
Start Your Free Assessment
If you’re preparing for CMMC 2.0 Level 1 compliance, our technology partner, Carbide, offers a free Self-Assessment Tool to help you navigate the process. This tool provides step-by-step guidance and generates a report identifying any gaps that must be addressed to meet the requirements.
*For more guidance, consult resources such as the DoD’s CMMC documentation and self-assessment guides.
