CMMC Level 1 Checklist: A Practical Guide for Austin and Houston Contractors

Table of Contents

A useful CMMC Level 1 checklist connects each safeguarding requirement to the systems, people, and evidence in your business. Use the review below to organize preparation and identify corrective work before completing your self-assessment.

Business Communication Solutions helps Austin and Houston contractors turn findings into a practical readiness plan. Our CMMC consulting services combine scope reviews, gap identification, implementation, and evidence organization.

Download the CMMC Level 1 checklist

Use this free four-page worksheet to organize your assessment scope, review all 15 safeguards, track evidence and task owners, and plan SPRS submission and annual renewal.

Download the CMMC Level 1 Checklist (PDF)

A preparation worksheet to use alongside the official assessment guidance.

Who should use this CMMC Level 1 checklist?

This checklist is intended for contractors preparing to safeguard Federal Contract Information (FCI) under applicable Level 1 requirements. Confirm the required CMMC level and assessment type in your contract or subcontract first.

If your work involves Controlled Unclassified Information (CUI), do not assume Level 1 is sufficient. Read What Is FCI vs. CUI? and Do I Need CMMC Level 1 or Level 2?.

Start by defining your assessment scope

Follow the information through your actual workflow: where it arrives, who uses it, where copies are stored, and how it leaves your business. Consider email, computers, servers, cloud services, external devices, and remote access.

  • Identify the systems that process, store, or transmit FCI.
  • Record the users, devices, services, and relevant boundaries.
  • Identify the CAGE codes associated with the assessed systems.
  • Assign an implementation owner and reviewer for each safeguard.
  • Organize evidence references so another reviewer can locate the supporting records.

Illustrative example: An Austin contractor stores project files on a company share, but employees also download them to laptops. A review focused only on the server could miss part of the actual workflow.

CMMC Level 1 checklist: the 15 safeguarding requirements

The table summarizes the 15 safeguards in FAR 52.204-21(b)(1). Evidence examples are preparation suggestions, not a complete set of assessment objectives.

Item Safeguard summary Evidence ideas
1 Restrict access to authorized users, processes, and devices.
FAR 52.204-21(b)(1)(i)
Review account approvals, device records, service identities, and departed-user removal.
2 Restrict users to permitted functions and transactions.
FAR 52.204-21(b)(1)(ii)
Review role permissions and sample access tests for users with different duties.
3 Control connections to external systems.
FAR 52.204-21(b)(1)(iii)
Review approved remote access, outside devices, services, and connection restrictions.
4 Control information on public systems.
FAR 52.204-21(b)(1)(iv)
Review public website publishing approvals and checks for unintended disclosure.
5 Identify users, processes, and devices.
FAR 52.204-21(b)(1)(v)
Review inventories and identifiers, including service accounts and connected devices.
6 Verify identities before granting access.
FAR 52.204-21(b)(1)(vi)
Review authentication settings and tests for relevant users, devices, and processes.
7 Sanitize or destroy FCI media before disposal or reuse.
FAR 52.204-21(b)(1)(vii)
Review media handling procedures, sanitization records, and disposal receipts.
8 Restrict physical access to authorized people.
FAR 52.204-21(b)(1)(viii)
Review authorized-access lists and how rooms and equipment are secured.
9 Escort and monitor visitors; log access; manage access devices.
FAR 52.204-21(b)(1)(ix)
Review visitor procedures, access logs, and key or badge issuance and revocation.
10 Protect communications at external and key internal boundaries.
FAR 52.204-21(b)(1)(x)
Review network diagrams, boundary configurations, rules, and verification records.
11 Separate public-facing components from internal networks.
FAR 52.204-21(b)(1)(xi)
Review public-facing systems and physical or logical separation and access tests.
12 Identify, report, and correct flaws promptly.
FAR 52.204-21(b)(1)(xii)
Review patching records, reported flaws, remediation tickets, and follow-up checks.
13 Provide malicious-code protection where appropriate.
FAR 52.204-21(b)(1)(xiii)
Review protection deployment, coverage, configurations, and alerts.
14 Keep malicious-code protection updated.
FAR 52.204-21(b)(1)(xiv)
Review update settings, current versions, and recent update or failure records.
15 Scan systems periodically and external files in real time.
FAR 52.204-21(b)(1)(xv)
Review scan schedules, results, real-time settings, and handling of external files.

How to use the checklist with your team

For each row, record an owner, evidence location, review finding, and next action. Separate work that is implemented from work that is only planned.

Useful evidence might include configuration records, inventories, access reviews, disposal records, scan results, or observations of procedures in practice. A policy describes intended behavior; verification helps establish whether people and systems actually follow it.

Illustrative example: A Houston shop may have a written visitor procedure. Review whether visitors are actually escorted, whether access records are maintained, and whether issued keys or badges are controlled.

Does completing this checklist mean we pass Level 1?

No. This is a preparation worksheet. The actual self-assessment must evaluate the mapped assessment objectives using the applicable official guidance. Review the official Level 1 Assessment Guide.

All requirements must be MET to achieve Final Level 1 (Self). Level 1 does not allow assessment gaps to be carried into conditional status using a Plan of Action and Milestones (POA&M). Assign corrective work and verify its completion before claiming a requirement is met.

What happens after the assessment?

Enter the results in SPRS and have the company’s authorized Affirming Official complete the affirmation. Follow our guide: How to Submit a CMMC Level 1 Self-Assessment in SPRS.

Maintain compliance, complete the annual self-assessment and required affirmation, and retain assessment evidence artifacts for six years from the CMMC Status Date. See 32 CFR Part 170, including sections 170.15 and 170.22.

Common checklist mistakes

  • Reviewing only the main office: follow remote-user and external-service workflows too.
  • Counting software subscriptions as proof: review configuration, coverage, operation, and evidence.
  • Overlooking physical access: visitor procedures, access records, and keys or badges need attention.
  • Leaving tasks without an owner: identify who implements and who verifies the correction.
  • Assuming last year’s review is enough: track changes to accounts, systems, and providers.

Get CMMC Level 1 readiness help in Austin and Houston

BCS can work alongside your current IT staff to organize the scope, review gaps, implement agreed corrections, and prepare evidence. Our cybersecurity and IT support connects the written plan to the environment your employees use.

Need help turning checklist findings into completed work?

Explore BCS CMMC consulting services or schedule a readiness consultation.

Austin: 512-257-1433
Houston: 281-815-8784

Reviewed September 30, 2026. This checklist summarizes requirements for preparation; it does not replace the official assessment objectives. Your authorized company officials remain responsible for assessment reporting and affirmation.