The Cybersecurity Maturity Model (CMMC) Level 1 Assessment Playbook addresses the following domains:
- Access Control (AC)
- Identification and Authentication (IA)
- Media Protection (MP)
- Physical Protection (PE)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
The CMMC Level 1 Assessment Playbook consists of:
- 6 CMMC Domains (as above)
- 17 Practices, and
- 44 Potential Assessment Considerations
Level 1 of CMMC addresses the protection of Federal Contract Information (FCI) and encompasses the basic safeguarding requirements for FCI specified in Federal Acquisition Regulation (FAR) Clause 52.204-21.
Department of Defense (DoD) contracts that specify the need for a contractor to process, store, or transmit FCI only require the contractor to comply with CMMC Level 1 practices. There is no CMMC process maturity assessed at Level 1.