---
kind: "section"
citation: "32 C.F.R. § 170.15"
title: "32"
number: "170.15"
heading: "CMMC Level 1 self-assessment and affirmation requirements."
url: "https://uscodex.org/cfr/32/170.15"
---

# §170.15. CMMC Level 1 self-assessment and affirmation requirements.

- (a) **Level 1 self-assessment.** To comply with CMMC Level 1 self-assessment requirements, the OSA must meet the requirements detailed in paragraphs [(a)(1)](#a-1) and [(2)](#a-2) of this section. An OSA conducts a Level 1 self-assessment as detailed in [paragraph (c)](#c) of this section to achieve a CMMC Status of Final Level 1 (Self).
  - (1) **Level 1 self-assessment requirements.** The OSA must complete and achieve a MET result for all security requirements specified in [§ 170.14(c)(2)](/cfr/32/170.14.md?p=c-2) to achieve the CMMC Status of Final Level 1 (Self). No POA&Ms are permitted for CMMC Level 1. The OSA must conduct a self-assessment in accordance with the procedures set forth in [§ 170.15(c)(1)](#c-1) and submit assessment results in SPRS. To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.
    - (i) **Inputs to SPRS.** The Level 1 self-assessment results in the Supplier Performance Risk System (SPRS) shall include, at minimum, the following items:
      - (A) **CMMC Level.**
      - (B) **CMMC Status Date.**
      - (C) **CMMC Assessment Scope.**
      - (D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.
      - (E) **Compliance result.**
    - (ii) [Reserved]
  - (2) **Affirmation.** Affirmation of the Level 1 (Self) CMMC Status is required for all Level 1 self-assessments. Affirmation procedures are set forth in [§ 170.22](/cfr/32/170.22.md).
- (b) **Contract eligibility.** Prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 1 (Self), OSAs must both achieve a CMMC Status of Level 1 (Self) and have submitted an affirmation of compliance into SPRS for all information systems within the CMMC Assessment Scope.
- (c) **Procedures—**
  - (1) **Level 1 self-assessment.** The OSA must conduct a Level 1 self-assessment scored in accordance with the CMMC Scoring Methodology described in [§ 170.24](/cfr/32/170.24.md). The Level 1 self-assessment must be performed in accordance with the CMMC Level 1 scope requirements set forth in § [170.19(a)](/cfr/32/170.19.md?p=a) and [(b)](/cfr/32/170.19.md?p=b) and the following:
    - (i) The Level 1 self-assessment must be performed using the objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference, see [§ 170.2](/cfr/32/170.2.md)) for the security requirement that maps to the CMMC Level 1 security requirement as specified in table 1 to [paragraph (c)(1)(ii)](#c-1-ii) of this section. In any case where an objective addresses CUI, FCI should be substituted for CUI in the objective.
    - (ii) **Mapping table for CMMC Level 1 security requirements to the NIST SP 800-171A Jun2018 objectives.**
    - (iii) Additional guidance can be found in the guidance document listed in [paragraph (b)](#b) of appendix A to this part.
  - (2) **Artifact retention.** The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date.

## Notes

### Authority

Authority: 5 U.S.C. 301; Sec. 1648, Pub. L. 116-92, 133 Stat. 1198.

### Source

Source: 89 FR 83214, Oct. 15, 2024, unless otherwise noted.
