Skip to main content
Power Up Boston
← Back to blog

September 13, 2026 · Power Up Boston

CMMC Level 1 Checklist for Massachusetts

#cmmc#compliance#cybersecurity#defense#manufacturing#massachusetts#south-shore

If your Massachusetts business supplies parts, services, or materials into the Department of Defense supply chain, you have probably been asked by a prime contractor about your "CMMC status" or your "SPRS score." For most small machine shops, electronics suppliers, engineering firms, and specialty manufacturers on the South Shore and along the Route 3 and Route 128 corridors, the answer starts with CMMC Level 1.

This post is the checklist we use when we walk a new client through Level 1. It covers what Level 1 is, who needs it, all 15 requirements grouped by domain, what an assessor (or you, during a self-assessment) expects to see for each, and how to document and report the result. Nothing here requires a consultant to interpret; it is meant to be printed and worked through.

What CMMC Level 1 Is

The Cybersecurity Maturity Model Certification (CMMC) is the DoD's program for verifying that contractors protect two kinds of government information:

  • Federal Contract Information (FCI): information provided by or generated for the government under a contract that is not intended for public release. Purchase orders, delivery schedules, and contract correspondence usually qualify.
  • Controlled Unclassified Information (CUI): more sensitive information that requires safeguarding under law or policy, such as technical drawings, specifications, and export-controlled data.

CMMC 2.0 has three levels. Level 1 applies when you handle FCI but not CUI. It consists of the 15 basic safeguarding requirements in paragraph (b)(1) of FAR 52.204-21, "Basic Safeguarding of Covered Contractor Information Systems," a clause that has been in most federal contracts since 2016. CMMC does not add new controls at Level 1; it adds verification. You perform a self-assessment every year, record the result in the Supplier Performance Risk System (SPRS), and a senior company official affirms that you continue to meet all 15 requirements.

A note on counting: older CMMC guides listed Level 1 as 17 practices. The physical-protection requirement in FAR (b)(1)(ix) was split into three practices, which brought the total to 17. The CMMC program rule at 32 CFR Part 170 (effective December 16, 2024) and the current Level 1 assessment guide count the same content as 15 requirements. If a prime contractor or an older article says 17, they mean the same list.

Level 2 applies when you handle CUI and covers the 110 requirements in NIST SP 800-171 Revision 2. Level 3 adds 24 requirements from NIST SP 800-172 for the most sensitive programs. Our CMMC compliance page covers the differences and the assessment types for each.

Does Your Massachusetts Business Need Level 1?

Ask three questions:

  1. Do you have a DoD prime contract or subcontract, at any tier?
  2. Does that contract involve any non-public government information (FCI)?
  3. Is the contract for something other than commercially available off-the-shelf (COTS) items?

If the answer to all three is yes and you do not handle CUI, Level 1 is your target. If you handle CUI, you need Level 2 and this checklist is still your foundation, since all 15 Level 1 requirements are also part of the 110 Level 2 requirements.

The DFARS rule that inserts CMMC into DoD solicitations (DFARS 252.204-7021) took effect November 10, 2025, and DoD is phasing the requirement into new contracts over roughly three years. Self-assessment requirements come first, which is exactly why Level 1 matters now. Confirm the level and phase against your specific solicitation; this post is general information, not contracting or legal advice.

The CMMC Level 1 Checklist

The 15 requirements below are grouped by the six CMMC domains they map to, with the FAR 52.204-21 paragraph reference for each. For every item, "What it means" is the plain-English version and "What to show" is the evidence a self-assessment should be able to point to.

Access Control (AC)

  • AC.L1 — FAR (b)(1)(i): Limit system access to authorized users, processes, and devices.
    What it means: every person and machine that touches systems holding FCI is one you have approved. No shared "shop" logins, no unknown devices on the network.
    What to show: a list of user accounts reconciled against current employees; a device inventory; a process for approving new accounts and removing old ones.

  • AC.L1 — FAR (b)(1)(ii): Limit access to the types of transactions and functions that authorized users are permitted to execute.
    What it means: users only get the permissions their job requires. A machinist does not need admin rights on the accounting server.
    What to show: role or group definitions; admin accounts separated from daily-use accounts; file share permissions that match roles.

  • AC.L1 — FAR (b)(1)(iii): Verify and control/limit connections to and use of external information systems.
    What it means: you know and control how your systems connect to outside systems, including personal devices, home networks, cloud services, and customer portals.
    What to show: a policy on personal devices and remote access; VPN or managed remote access rather than open RDP; a list of approved cloud services.

  • AC.L1 — FAR (b)(1)(iv): Control information posted or processed on publicly accessible information systems.
    What it means: FCI never ends up on your public website, social media, or a public file share, and someone reviews what is published.
    What to show: a named person who approves public content; a short written rule that FCI is never posted publicly.

Identification and Authentication (IA)

  • IA.L1 — FAR (b)(1)(v): Identify information system users, processes acting on behalf of users, or devices.
    What it means: every user, service account, and device has a unique identifier. No generic accounts.
    What to show: unique usernames for all staff; service accounts documented with an owner; device names in your inventory.

  • IA.L1 — FAR (b)(1)(vi): Authenticate (or verify) the identities of those users, processes, or devices as a prerequisite to allowing access.
    What it means: passwords (or better) are required before access is granted, and default passwords are gone.
    What to show: a password policy that is actually enforced by the domain or identity provider; vendor defaults changed on firewalls, switches, printers, and cameras. Multi-factor authentication is not required at Level 1, but it is required at Level 2 and is the single most effective step you can take now.

Media Protection (MP)

  • MP.L1 — FAR (b)(1)(vii): Sanitize or destroy information system media containing FCI before disposal or release for reuse.
    What it means: hard drives, USB sticks, backup tapes, and copier drives are wiped or physically destroyed before they leave your control.
    What to show: a disposal procedure; certificates of destruction from your recycler; a log of drives wiped or destroyed.

Physical Protection (PE)

  • PE.L1 — FAR (b)(1)(viii): Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
    What it means: servers, network closets, and workstations holding FCI are behind locked doors that only authorized people can open.
    What to show: locked server room or rack; a list of who holds keys or access credentials; door access control logs if you have them.

  • PE.L1 — FAR (b)(1)(ix): Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
    What it means: three things. Visitors are signed in and escorted. You keep a record of who entered secure areas. You track keys, fobs, and badges and recover them when people leave.
    What to show: a visitor log at the front desk; a key and badge inventory; a termination checklist that includes returning access devices. (This is the requirement older guides split into three practices.)

System and Communications Protection (SC)

  • SC.L1 — FAR (b)(1)(x): Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of information systems.
    What it means: a properly configured business firewall sits between your network and the internet, and traffic through it is controlled and logged.
    What to show: a business-class firewall with current firmware; a documented rule set (deny by default inbound); logging turned on.

  • SC.L1 — FAR (b)(1)(xi): Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
    What it means: anything the public can reach, such as a web server or guest Wi-Fi, lives on its own network segment, not alongside your file server.
    What to show: a network diagram showing a DMZ or separate VLAN for public-facing systems and guest Wi-Fi; or a statement that no publicly accessible components are hosted internally.

System and Information Integrity (SI)

  • SI.L1 — FAR (b)(1)(xii): Identify, report, and correct information and information system flaws in a timely manner.
    What it means: operating systems, applications, and firmware are patched on a schedule, and you can prove it.
    What to show: patch management reports from your RMM or update service; a defined patch window; a process for out-of-band critical patches.

  • SI.L1 — FAR (b)(1)(xiii): Provide protection from malicious code at appropriate locations within organizational information systems.
    What it means: endpoint protection is installed on every workstation and server.
    What to show: the management console for your antivirus or endpoint detection and response tool showing 100 percent coverage.

  • SI.L1 — FAR (b)(1)(xiv): Update malicious code protection mechanisms when new releases are available.
    What it means: that endpoint protection updates itself automatically and nobody has switched it off.
    What to show: console report of definition and engine versions; alerts configured for out-of-date agents.

  • SI.L1 — FAR (b)(1)(xv): Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
    What it means: scheduled full scans run, and real-time scanning catches files coming in by email, download, or USB.
    What to show: scan schedules and results; real-time protection enabled in policy; email filtering in place.

That is the whole list. Fifteen items, six domains, and every one of them is something a competent managed IT provider should already be doing for you.

How to Complete the Level 1 Self-Assessment

  1. Define the scope. List every system, device, and network segment that stores, processes, or transmits FCI. If your whole office network is in scope, that is fine at Level 1; it just means the checklist applies everywhere.
  2. Assess each requirement as MET or NOT MET. Level 1 has no partial credit and no Plan of Action and Milestones. All 15 must be MET to report a passing self-assessment.
  3. Collect evidence. For each item, save the report, screenshot, policy, or log described under "What to show." Keep them in one folder with a date.
  4. Fix the gaps. Most Level 1 gaps are quick: change default passwords, remove stale accounts, turn on automatic updates, buy a visitor log, lock the server closet.
  5. Report in SPRS. Enter the Level 1 self-assessment in the Supplier Performance Risk System and have a senior official complete the annual affirmation. Repeat every year.

Where Level 1 Overlaps With Massachusetts Law

If you have employees in Massachusetts, you are already required to maintain a Written Information Security Program under 201 CMR 17.00. The overlap with Level 1 is substantial: unique user IDs and secure passwords (17.04(1)–(2)), firewall and patching (17.04(6)), current malware protection (17.04(7)), physical access restrictions (17.03(2)(g)), and media disposal (M.G.L. c. 93I) are all in both. A business that has done its WISP properly is most of the way to Level 1, and the reverse is also true. We usually build the two together so there is one set of policies and one evidence folder.

The state's data breach notification law also applies if an incident on a CUI or FCI system exposes personal information, so your incident procedure should cover both DoD reporting obligations and Massachusetts notification.

Getting Ready for Level 2

If your contracts involve CUI, Level 1 is the floor and Level 2's 110 requirements are the goal. The items that require the most lead time are multi-factor authentication on every account, retained and reviewed audit logs, encryption of CUI at rest and in transit, a written and tested incident response plan, and configuration baselines for workstations and shop-floor systems. Shrinking the CUI environment to as few systems as possible is the single biggest cost and time saver before a C3PAO assessment. Our cybersecurity and backup and disaster recovery services cover the technical side of those requirements.

Get a Second Set of Eyes

Power Up Boston has been supporting South Shore and Greater Boston businesses from Plymouth for 17+ years, including manufacturers and engineering firms in the defense supply chain. We will walk through this checklist with you on-site, tell you which of the 15 requirements you already meet, close the gaps, and assemble the evidence folder for your SPRS submission. For Level 2, we prepare the environment and documentation; the certification assessment itself is performed by an authorized C3PAO.

Contact us for a free CMMC gap assessment, or start with the CMMC compliance overview.

Related Services

Intent-matched next steps based on this article topic.

Need Reliable IT Support in Plymouth or the South Shore?

Schedule a free on-site assessment. We’ll review your IT, cybersecurity, and physical security setup, then give you a clear plan with practical next steps.

Trusted since 2009 · 5-star rated on Google · On-site support across Plymouth, South Shore, Cape Cod & Greater Boston

CallTextContact