Want to learn more about our services? Book a free introductory call - "Here"

CMMC Level 1: Why You'll See Both "15 Requirements" and "17 Practices" (And Why It Matters)

CMMC Level 1 is described as both "15 requirements" and "17 practices." Here's why both numbers are correct - and what it means for your self-assessment.

CMMC BLOG

Daniel McLain

9/16/20264 min read

CMMC Level 1: Why You'll See Both "15 Requirements" and "17 Practices" (And Why It Matters)

If you've started digging into CMMC Level 1, you've probably run into a small but confusing inconsistency: some sources say Level 1 covers 15 requirements, while others - including the official self-assessment checklist you'll actually use - say 17 practices. Neither is wrong. They're counting two different things, and knowing the difference matters once you sit down to actually run your self-assessment.

Here's the short version, followed by the detail.

The Short Answer

CMMC Level 1 is built on the 15 basic safeguarding requirements in FAR Clause 52.204-21 - the federal regulation that protects Federal Contract Information (FCI). When CMMC translated those 15 requirements into individually assessable practices, one of them (the physical access requirement) was split into three separate practices. That turns 15 requirements into 17 practices - the actual number of line items you check off, one at a time, when you run a Level 1 self-assessment.

Same scope. Same regulation. Different counting unit.

What CMMC Level 1 Actually Protects

Before getting into the numbers, it helps to know what Level 1 is for. It exists to protect Federal Contract Information (FCI) - information the government provides to a contractor, or that a contractor generates on the government's behalf, that isn't intended for public release but also isn't classified as Controlled Unclassified Information (CUI). If your business touches FCI on a federal contract, Level 1 is very likely your compliance floor.

Level 1 is self-assessed (no third-party certification required), performed annually, and closed out with a senior company official affirming the result in the Supplier Performance Risk System (SPRS).

Where "15" Comes From: FAR Clause 52.204-21

FAR 52.204-21(b)(1) lists 15 basic safeguarding requirements, labeled (i) through (xv), covering things like limiting system access, authenticating users, sanitizing media before disposal, and protecting network boundaries. This FAR clause is the original legal source of Level 1's scope - it predates CMMC itself and applies to federal contractors handling FCI regardless of whether CMMC is even in the picture.

If you see a source describe Level 1 as having "15 controls" or "15 requirements," it's referencing this FAR clause directly.

Where "17" Comes From: The CMMC Practice Mapping

CMMC restates each FAR requirement as a numbered practice, cross-referenced to NIST SP 800-171. For 14 of the 15 FAR requirements, that's a clean one-to-one mapping - one FAR line, one CMMC practice.

The exception is FAR 52.204-21(b)(1)(ix), which reads: "Escort visitors and monitor visitor activity; maintain audit logs of physical access devices; and control and manage physical access devices." That single FAR requirement actually bundles three distinct physical-security activities together. CMMC splits it into three separate, independently assessable practices:

  • PE.L1-3.10.3 - Escort visitors and monitor visitor activity

  • PE.L1-3.10.4 - Maintain audit logs of physical access devices

  • PE.L1-3.10.5 - Control and manage physical access devices

That's the whole discrepancy: 15 FAR requirements, minus the one that gets split, plus the three practices it becomes, equals 17 CMMC Level 1 practices.

The Full Mapping, Domain by Domain

DomainCMMC Practice FAR 52.204-21 ReferenceWhat It CoversAccess Control (AC)AC.L1-3.1.1(b)(1)(i)Limit system access to authorized usersAccess Control (AC)AC.L1-3.1.2(b)(1)(ii)Limit access to authorized transactions/functionsAccess Control (AC)AC.L1-3.1.20(b)(1)(iii)Verify/control connections to external systemsAccess Control (AC)AC.L1-3.1.22(b)(1)(iv)Control information on public-facing systemsIdentification & Authentication (IA)IA.L1-3.5.1(b)(1)(v)Identify system users, processes, and devicesIdentification & Authentication (IA)IA.L1-3.5.2(b)(1)(vi)Authenticate identities before granting accessMedia Protection (MP)MP.L1-3.8.3(b)(1)(vii)Sanitize/destroy media before disposalPhysical Protection (PE)PE.L1-3.10.1(b)(1)(viii)Limit physical access to authorized individualsPhysical Protection (PE)PE.L1-3.10.3(b)(1)(ix)Escort visitors and monitor visitor activityPhysical Protection (PE)PE.L1-3.10.4(b)(1)(ix)Maintain audit logs of physical access devicesPhysical Protection (PE)PE.L1-3.10.5(b)(1)(ix)Control and manage physical access devicesSystem & Communications Protection (SC)SC.L1-3.13.1(b)(1)(x)Monitor/control communications at boundariesSystem & Communications Protection (SC)SC.L1-3.13.5(b)(1)(xi)Separate public-facing subnetworks internallySystem & Information Integrity (SI)SI.L1-3.14.1(b)(1)(xii)Identify, report, and correct system flawsSystem & Information Integrity (SI)SI.L1-3.14.2(b)(1)(xiii)Protect against malicious codeSystem & Information Integrity (SI)SI.L1-3.14.4(b)(1)(xiv)Update malicious code protection mechanismsSystem & Information Integrity (SI)SI.L1-3.14.5(b)(1)(xv)Perform periodic and real-time scans

That's 6 domains, 17 practices, 15 distinct FAR citations - with (b)(1)(ix) doing triple duty.

Why the Distinction Actually Matters

You assess 17 items, not 15. When you sit down with the official CMMC Level 1 Self-Assessment Checklist, you'll mark MET or NOT MET on 17 separate lines - including three separate physical-security lines that all trace back to the same FAR paragraph. Someone expecting only 15 checkboxes will come up short.

Level 1 allows zero exceptions. Unlike Level 2, CMMC Level 1 does not permit Plans of Action and Milestones (POA&Ms). Every one of the 17 practices must be fully MET - with evidence - before your senior official can affirm compliance in SPRS.

No System Security Plan is required at Level 1. A System Security Plan (SSP) is a Level 2 requirement (CA.L2-3.12.4), not a Level 1 one.

The count is a good gut check. If a self-assessment framework, spreadsheet, or vendor pitch lists something other than 17 line items for Level 1, it's worth asking why.

Key Takeaways

Fifteen and seventeen are both correct descriptions of the same regulatory scope. Fifteen is the number of underlying FAR 52.204-21 safeguarding requirements. Seventeen is the number of individually assessable CMMC practices those requirements become. When actually running a self-assessment, 17 is the number that matters.

Frequently Asked Questions

Is CMMC Level 1 15 controls or 17 controls? Both numbers describe the same scope. FAR Clause 52.204-21 defines 15 basic safeguarding requirements. CMMC restates those as 17 individually assessable practices, because one FAR requirement covering physical access is split into three separate CMMC practices.

Do I need a System Security Plan (SSP) for CMMC Level 1? No. An SSP is required starting at CMMC Level 2 (practice CA.L2-3.12.4). CMMC Level 1 self-assessment does not require an SSP.

Can I have open Plans of Action (POA&Ms) and still pass a Level 1 self-assessment? No. CMMC Level 1 requires all 17 practices to be marked MET, with evidence, before a senior official can affirm compliance in SPRS.

How often do I need to complete a CMMC Level 1 self-assessment? Annually, with an accompanying affirmation of compliance from a senior company official entered into SPRS.

Disclaimer used in the post: general informational purposes only, not legal advice; consult a qualified compliance professional or RPO for guidance specific to your organization.

Copyright © 2026 ICTS USA LLC - All Rights Reserved.