image

i2ACT FAR | CMMC Level 1 Software

CMMC Level 1 is the most basic level of certification and consists of several practices that correspond directly to essential safety conditions outlined in the Federal Acquisition Regulation (FAR). Level 1 consists of 17 basic cybersecurity practices such as implementing Access Control as well as Identity and Authentication. These 17 controls are designed to protect Federal Contract Information (FCI) and are mapped directly from the 15 basic safeguarding requirements found in Federal Acquisition Regulation (FAR) clause 52.204-21. The goal is to create a basic “Foundational Level” of cybersecurity for any organization that has FCI.

The i2ACT Level 1 software includes enhanced functionality which allows for multiple remediation tasks per practice to be defined in the assessment process thereby enhancing the detail in the POA&M produced directly from the tool. The tool also allows for multiple evidentiary artifacts for each practice/requirement and, in turn, each evidentiary artifact can be associated with multiple practices/requirements.

The i2ACT Assessment and Compliance Tool
CMMC Level 1 Domains

Baselines for CMMC Level 1

A baseline is the set of controls you choose for the security standard or configuration you want to meet and fully implement.

As the lowest level of security controls required for a defense contractor to earn CMMC certification, Level 1 focuses on implementing basic cyber hygiene practices to protect FCI. These practices align with the basic safeguarding requirements specified in FAR Clause 52.204-21.

  • Focus on FCI: The primary goal is to protect FCI, which is any information generated or received during the execution of a government contract.
  • Cybersecurity Practices: Level 1 encompasses the most fundamental security practices, such as strong password management, user access controls, and basic data protection measures.
  • Self-Assessment: Unlike higher CMMC levels, Level 1 compliance is typically verified through a self-assessment by the contractor, where they affirm their adherence to the FAR Clause 52.204-21 requirements and can produce their own reports right from the i2ACT Tool. See Image Below Right
  • NIST 800-171 | 800-53 NFO's | DFARS Assessment Profiles: Each of these Assessment Profiles can be selected for the Assessment and provide a unique User Interface/User Experience for this Assessment Type. Note: Click the images below for a detailed screen shot of each.
  • No Third-Party Audit: There is no external third-party audit required for Level 1 compliance.

Click on the images below for larger screen shots of how to select a baseline and how each looks to the user.

CMMC Level 1 Baseline Setting

CMMC is Good For Any Business!

While CMMC is officially required only for Department of Defense (DoD) contractors handling Federal Contract Information (FCI), Level 1 is essentially a formalization of basic cybersecurity hygiene practices that any organization should adopt.

i2ACT For Non-DoD, Nonfederal Firms & Commercial Entities

The Imprimis i2ACT Assessment and Compliance Tool is effective for commercial entities outside the Defense Industrial Base (DIB) or Department of Defense (DoD) because it functions as a comprehensive scalable risk management platform that translates complex cybersecurity standards into actionable, affordable steps for any business. While originally designed for DoD compliance, the tool's core functionality—based on frameworks like NIST—addresses the universal need for security, making it applicable to commercial firms.

  • Based on FAR/NIST Standards: CMMC Level 1 is not "new" invented security. It is based directly on the 17 requirements found in Federal Acquisition Regulation (FAR) Clause 52.204-21, which in turn are mapped to NIST SP 800-171.

    Focus on Essential Hygiene: Covers basic, critical practices that defend against common, low sophistication cyberattacks (phishing, malware, weak password theft).

    Foundation for Growth: Is the building block for higher-level certifications (CMMC Level 2), other frameworks (ISO 27001 or SOC 2), or simply a more stringent level of security.

    No "Plan of Action" (POA&Ms): CMMC Level 1 requires full implementation of all 17 controls – a POA&M will not be accepted. You cannot start with security gaps which forces a truly secure foundation.

  • The 17 practices grouped into 6 domains:

    1. Access Control: Limits system access to authorized users.
    2. Identification and Authentication: Identifies users and verifies their identity (passwords).
    3. Media Protection: Protects physical data (USB drives, hard copies).
    4. Physical Protection: Limits physical access to systems.
    5. System and Communication Protection: Controls traffic on your network.
    6. System and Information Integrity: Requires software updates, scans for malware, and reporting of incidents.
  • Benefits for Commercial Companies are:

    1. Cost-Effective Security: Complying with CMMC Level 1 standards provides a structured, low-cost approach to security that doesn't require expensive enterprise tools.
    2. Builds Customer Trust: Demonstrating that your company follows DoD-approved standards can be a very real marketing advantage.
    3. Reduces Risk of Business Interruption: Ransomware attacks are devastating; these controls help prevent them. Small businesses make up the majority of ransomware and other cyber incidents in the US and it is not slowing down.
  • Some Advantages:

    • No Third-Party Needed: Level 1 requires an annual self-assessment and a affirmation from a company officer. It does not require a C3PAO (Certified Third-Party Assessment Organization), saving on assessment costs, but it requires diligent self-monitoring.
    • Not Enough for High-Risk Data: If your company handles highly sensitive intellectual property, personally identifiable information (PII), or health data (HIPAA), Level 1 is too weak. You should aim for CMMC Level 2 (NIST 800-171) or ISO 27001 compliance.
    • It’s a Snapshot: Like all compliance, it only measures your security posture at the moment of the self-assessment.

    Conclusion: Using the CMMC Level 1 Assessment Guide as a checklist for your internal IT department or MSP is a smart, proactive approach to cybersecurity, even if you never intend to do business with the DoD

Complete NIST/CMMC Reference Section

The i2ACT Software Tool has a complete online reference section that includes all FAR, NIST 800-171 and CMMC standards, Auditor Guides, DoD regulations and much more. In addition it includes NIST 800-53 NFO Evaluations and DFARS Evaluations. These reference sections can be used to familiarize the user with their content and layout. These are provided to clarify the information about the Security Controls and each control within the standard. NIST 800-171 refers to their Security Controls as Requirements, and CMMC Level 2 refers to their Security Controls as Practices.

In the i2ACT Software tool, the term "Control" is used throughout as a generic way to reference Security Controls in both standards when needed to keep explanations simple. These reference guides are available at the click of a button and can "float" in a separate window for quick and easy reference. In addition as you "step through" your assessment at each requirement level, these screens update dynamically for each requirement.

  • image

    FAR Regulations

    The Federal Acquisition Regulation (“FAR”) Proposed Rule on Controlled Unclassified Information (“CUI”) was finally released on January 15, 2025 and comes as part of the Government’s broader efforts to identify, detect, and respond to ever-evolving threats targeting Federal contractors. The final FAR CUI rule has not yet been published, and the public comment phase closed on March 17, 2025. The FAR Council will adjudicate the comments before issuing the final rule, which may take approximately one year after the comment period ends, though this timeline can vary. Publication of proposed rule: The proposed rule was published in the Federal Register on January 15, 2025. Public comment period: The public comment period ended on March 17, 2025. Finalization timeline: The FAR Council will review all comments before publishing the final rule, which is expected to take about a year after the comment period ends. Key changes: The rule aims to standardize CUI handling, implement NARA's policies, and introduce new reporting and compliance obligations for federal contractors.

  • image

    DFARS Regulations

    The DFARS Regulations in the i2ACT are specifically curated from Part 252 for Defense Contractors. It is a set of regulations that apply to all U.S. Department of Defense (DoD) contracts and subcontracts. The regulations are designed to ensure that the DoD receives quality goods and services at fair and reasonable prices. DFARS is important because it provides essential regulations and guidelines for the DoD to acquire goods and services in a way that supports defense objectives and promotes national security. These regulations help ensure that the DoD conducts acquisitions in a transparent, accountable, and compliant manner. DFARS includes requirements related to contract award and administration, cybersecurity, intellectual property, small business utilization, and other critical areas.

  • image

    NIST 800-171

    NIST Special Publication 800-171 Rev2, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, was originally published in February 2020, and included an update in January 2021. The Rev. 2 publication provides agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations; when the nonfederal organization is not collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency; and where there are no specific safeguarding requirements for protecting the confidentiality of CUI prescribed by the authorizing law, regulation, or government-wide policy for the CUI category listed in the CUI Registry.

  • image

    DoD CMMC Practices

    The DoD CMMC Practices Reference contains Tabs for the CMMC Discussion, the practice itself; various references from the 800-171A Assessment Guidelines and NIST Guidance from Handbook 162, (which was withdrawn and archived back in September of 2022 but still had a lot of good best practice information). This includes the details from the Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in response to DFARS Cybersecurity Requirements and provides guidance on implementing NIST SP 800-171 in response to the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012. The original NIST Handbook provided a step-by-step guide to assessing a small manufacturer’s information systems against the security requirements in NIST SP 800-171 rev 1, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations". All of this information is right at your fingertips in context-oriented pop-up windows.

  • image

    NFO Controls

    The SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations NIST CSRC (Computer Security Resource Center) provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. "NFO controls" in the context of NIST 800-53 refer to "Non-Federal Organization controls" which are essentially basic security practices considered so fundamental to any organization's operations that NIST does not provide detailed guidance on them; they are expected to be implemented as part of regular business practices, without requiring additional specific instructions. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk.