Enterprise GRC Platform
CMMC Level 1 — Foundational
CMMC Level 1 represents foundational cybersecurity practices required for organizations handling Federal Contract Information (FCI). This is the entry-level tier for DoD contractors, verified by an annual self-assessment. Tyndora automates implementation of the 17 core practices and prepares organizations for that self-assessment.
Level 1 — Foundational Practices
17 basic cybersecurity practices, drawn from the 15 safeguarding requirements of FAR 52.204-21, focused on basic hygiene. Suitable for small to medium organizations with limited specialized IT resources.
Level 1 Scope
- Data Scope: Federal Contract Information (FCI)
- Practice Count: 17 basic practices
- Assessment: Annual self-assessment with an affirming senior official
- Applicability: Small contractors with basic compliance needs
Who Needs Level 1?
Organizations handling Federal Contract Information but not Controlled Unclassified Information (CUI).
- ✓ Small DoD subcontractors
- ✓ Organizations with basic FCI handling
- ✓ Limited IT security resources
- ✓ Organizations beginning compliance journey
17 Foundational Practices Across 6 Domains
The 17 Level 1 practices map to the basic safeguarding requirements of FAR 52.204-21. Select any domain to expand it and see the practices within and what each one requires.
The 17 Level 1 practices are grouped by their 6 domains; each practice ID carries its NIST SP 800-171 source requirement (the 3.x.x number) and maps to a basic safeguarding requirement of FAR 52.204-21. Descriptions are a faithful plain-language summary, not verbatim official text — refer to the CMMC model and FAR 52.204-21 for authoritative wording.
Implementation Approach
How to implement Level 1 practices with Tyndora
Phase 1: Documentation
Map your current state to the 17 practices. Identify gaps and create implementation plan.
Phase 2: Implementation
Deploy controls, collect evidence, document procedures. Typical timeline: 2-3 months for small organizations.
Phase 3: Assessment
Self-assess or hire C3PAO. Remediate findings. Achieve Level 1 certification.
Next Steps
Ready to move beyond Level 1?
As your organization grows and handles Controlled Unclassified Information (CUI), you may need to advance to CMMC Level 2 or Level 3. Tyndora supports your maturity progression.
Implement CMMC Level 1
Let's assess your current state and create a roadmap to Level 1 certification.
Book a discovery