Example, read only. A sample account that shows what finished CMMC looks like.

← Back to the workspace

CMMC Level 1 · FY2026

The federal info
is locked down.

Cedar Ridge Machine Works, LLC met all 15 safeguarding requirements that protect its Federal Contract Information. Every one is done, each answered with a plain English narrative.

100%
Progress
Ready to attest
All 15 secured

Signed, filed, and bid ready.

The bid ready packet bundles the SSP, the signed affirmation, and every evidence artifact. It is filed in SPRS and ready for any prime or contracting officer.

Secured
15
In progress
0
Doesn't apply
0
To do
0

The 15 safeguarding
requirements.

Every practice is MET, each with a narrative written from the business. Click any one to read how it was answered.

AC

Who can get in

4 of 4 done
  1. AC.L1-b.1.iAuthorized Access ControlMET

    FAR 52.204-21(b)(1)(i)·NIST 800-171 r2 3.1.1

    Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

  2. AC.L1-b.1.iiTransaction & Function ControlMET

    FAR 52.204-21(b)(1)(ii)·NIST 800-171 r2 3.1.2

    Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

  3. AC.L1-b.1.iiiExternal ConnectionsMET

    FAR 52.204-21(b)(1)(iii)·NIST 800-171 r2 3.1.20

    Verify and control/limit connections to and use of external information systems.

  4. AC.L1-b.1.ivControl Public InformationMET

    FAR 52.204-21(b)(1)(iv)·NIST 800-171 r2 3.1.22

    Control information posted or processed on publicly accessible information systems.

IA

Proving who they are

2 of 2 done
  1. IA.L1-b.1.vIdentificationMET

    FAR 52.204-21(b)(1)(v)·NIST 800-171 r2 3.5.1

    Identify information system users, processes acting on behalf of users, or devices.

  2. IA.L1-b.1.viAuthenticationMET

    FAR 52.204-21(b)(1)(vi)·NIST 800-171 r2 3.5.2

    Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

MP

Handling media safely

1 of 1 done
  1. MP.L1-b.1.viiMedia DisposalMET

    FAR 52.204-21(b)(1)(vii)·NIST 800-171 r2 3.8.3

    Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

PE

Protecting your workspace

2 of 2 done
  1. PE.L1-b.1.viiiLimit Physical AccessMET

    FAR 52.204-21(b)(1)(viii)·NIST 800-171 r2 3.10.1

    Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

  2. PE.L1-b.1.ixManage Visitors & Physical AccessMET

    FAR 52.204-21(b)(1)(ix)·NIST 800-171 r2 3.10.3, 3.10.4, 3.10.5

    Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

SC

Protecting your network

2 of 2 done
  1. SC.L1-b.1.xBoundary ProtectionMET

    FAR 52.204-21(b)(1)(x)·NIST 800-171 r2 3.13.1

    Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

  2. SC.L1-b.1.xiPublic-Access System SeparationMET

    FAR 52.204-21(b)(1)(xi)·NIST 800-171 r2 3.13.5

    Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

SI

Keeping systems healthy

4 of 4 done
  1. SI.L1-b.1.xiiFlaw RemediationMET

    FAR 52.204-21(b)(1)(xii)·NIST 800-171 r2 3.14.1

    Identify, report, and correct information and information system flaws in a timely manner.

  2. SI.L1-b.1.xiiiMalicious Code ProtectionMET

    FAR 52.204-21(b)(1)(xiii)·NIST 800-171 r2 3.14.2

    Provide protection from malicious code at appropriate locations within organizational information systems.

  3. SI.L1-b.1.xivUpdate Malicious Code ProtectionMET

    FAR 52.204-21(b)(1)(xiv)·NIST 800-171 r2 3.14.4

    Update malicious code protection mechanisms when new releases are available.

  4. SI.L1-b.1.xvSystem & File ScanningMET

    FAR 52.204-21(b)(1)(xv)·NIST 800-171 r2 3.14.5

    Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.