What You Should Know About the Basics of CMMC 2.0 Level 1

Introduction

The Cybersecurity Maturity Model Certification (CMMC) is a standard developed by the United States Department of Defense (DoD) to ensure that companies that work with the government have adequate cybersecurity measures in place. The CMMC model has five levels of certification, with level 1 being the most basic. In this article, we will discuss the basics of CMMC Level 1 and what you need to know to achieve compliance.

What is CMMC Level 1?

CMMC Level 1 is the most basic level of certification in the CMMC model. It is designed for companies that only need access to Federal Contract Information (FCI). FCI is unclassified information that is provided by the government to a contractor for the purpose of performing a federal contract. CMMC Level 1 requires the implementation of 17 basic cybersecurity practices. These practices are based on the requirements of the National Institute of Standards and Technology (NIST) Special Publication 800-171.

What are the 17 basic cybersecurity practices?

The 17 basic cybersecurity practices are as follows:

  1. Access Control
  2. Awareness and Training
  3. Audit and Accountability
  4. Configuration Management
  5. Identification and Authentication
  6. Incident Response
  7. Maintenance
  8. Media Protection
  9. Personnel Security
  10. Physical Protection
  11. Risk Assessment
  12. Security Assessment
  13. Situational Awareness
  14. System and Communications Protection
  15. System and Information Integrity
  16. Incident Response
  17. Recovery

How to achieve compliance with CMMC Level 1?

To achieve compliance with CMMC Level 1, companies must implement the 17 basic cybersecurity practices mentioned above. The following are the steps that companies can take to achieve compliance:

  1. Identify the scope of the system that requires compliance with CMMC Level 1.
  2. Perform a self-assessment to determine the company's compliance with the 17 basic cybersecurity practices.
  3. Identify any gaps and deficiencies and develop a plan to address them.
  4. Implement the plan and ensure that all 17 basic cybersecurity practices are in place.
  5. Obtain a third-party assessment to verify compliance with CMMC Level 1.
  6. Upload the assessment results to the DoD's Supplier Performance Risk System (SPRS).

Conclusion

CMMC Level 1 is the most basic level of certification in the CMMC model. It is designed for companies that only need access to Federal Contract Information (FCI). Compliance with CMMC Level 1 requires the implementation of 17 basic cybersecurity practices. Companies can achieve compliance by identifying the scope of the system that requires compliance, performing a self-assessment, identifying any gaps and deficiencies, developing a plan to address them, implementing the plan, obtaining a third-party assessment, and uploading the assessment results to the DoD's SPRS.

Ways We Can Help You

Contact us to receive assistance in navigating cybersecurity risks and information compliance for your company. Here are some additional ways we can help:

  • Schedule a free discovery session with us during which we can learn about your company, answer your questions, and assist you in determining if Cleared Systems is the right fit for you.

  • Register for our upcoming cybersecurity and information compliance training.

  • Purchase our books on CMMC 2.0, CUI, Data Breaches, and ITAR.

  • Join our weekly free webinar sessions to ask questions and learn about the latest developments in cybersecurity and information compliance.

Author Profile

Carl B. Johnson, President of Cleared Systems, is a highly experienced and a ITAR, CMMC 2.0, Microsoft GCC High, and Microsoft DLP/AIP consultant. With over twenty years of experience in information assurance, cybersecurity, policy development, risk management, and regulatory compliance, he brings a wealth of knowledge and expertise to his clients.

Leave a Reply

Your email address will not be published. Required fields are marked *

Wait!

Have questions about compliance or cybersecurity?

Schedule a free call with our experts now and get your questions answered!