CMMC Level 1 · FY2026
The federal info
is locked down.
Cedar Ridge Machine Works, LLC met all 15 safeguarding requirements that protect its Federal Contract Information. Every one is done, each answered with a plain English narrative.
Signed, filed, and bid ready.
The bid ready packet bundles the SSP, the signed affirmation, and every evidence artifact. It is filed in SPRS and ready for any prime or contracting officer.
The 15 safeguarding
requirements.
Every practice is MET, each with a narrative written from the business. Click any one to read how it was answered.
Who can get in
Access Control- AC.L1-b.1.iAuthorized Access Control[FCI Data]MET100%
FAR 52.204-21(b)(1)(i)·NIST 800-171 r2 3.1.1
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
- AC.L1-b.1.iiTransaction & Function Control[FCI Data]MET100%
FAR 52.204-21(b)(1)(ii)·NIST 800-171 r2 3.1.2
Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
- AC.L1-b.1.iiiExternal Connections[FCI Data]MET100%
FAR 52.204-21(b)(1)(iii)·NIST 800-171 r2 3.1.20
Verify and control/limit connections to and use of external information systems.
- AC.L1-b.1.ivControl Public Information[FCI Data]MET100%
FAR 52.204-21(b)(1)(iv)·NIST 800-171 r2 3.1.22
Control information posted or processed on publicly accessible information systems.
Proving who they are
Identification and Authentication- IA.L1-b.1.vIdentification[FCI Data]MET100%
FAR 52.204-21(b)(1)(v)·NIST 800-171 r2 3.5.1
Identify information system users, processes acting on behalf of users, or devices.
- IA.L1-b.1.viAuthentication[FCI Data]MET100%
FAR 52.204-21(b)(1)(vi)·NIST 800-171 r2 3.5.2
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
Handling media safely
Media Protection- MP.L1-b.1.viiMedia Disposal[FCI Data]MET100%
FAR 52.204-21(b)(1)(vii)·NIST 800-171 r2 3.8.3
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
Protecting your workspace
Physical Protection- PE.L1-b.1.viiiLimit Physical Access[FCI Data]MET100%
FAR 52.204-21(b)(1)(viii)·NIST 800-171 r2 3.10.1
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
- PE.L1-b.1.ixManage Visitors & Physical Access[FCI Data]MET100%
FAR 52.204-21(b)(1)(ix)·NIST 800-171 r2 3.10.3, 3.10.4, 3.10.5
Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
Protecting your network
System and Communications Protection- SC.L1-b.1.xBoundary Protection[FCI Data]MET100%
FAR 52.204-21(b)(1)(x)·NIST 800-171 r2 3.13.1
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
- SC.L1-b.1.xiPublic-Access System Separation[FCI Data]MET100%
FAR 52.204-21(b)(1)(xi)·NIST 800-171 r2 3.13.5
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
Keeping systems healthy
System and Information Integrity- SI.L1-b.1.xiiFlaw Remediation[FCI Data]MET100%
FAR 52.204-21(b)(1)(xii)·NIST 800-171 r2 3.14.1
Identify, report, and correct information and information system flaws in a timely manner.
- SI.L1-b.1.xiiiMalicious Code Protection[FCI Data]MET100%
FAR 52.204-21(b)(1)(xiii)·NIST 800-171 r2 3.14.2
Provide protection from malicious code at appropriate locations within organizational information systems.
- SI.L1-b.1.xivUpdate Malicious Code Protection[FCI Data]MET100%
FAR 52.204-21(b)(1)(xiv)·NIST 800-171 r2 3.14.4
Update malicious code protection mechanisms when new releases are available.
- SI.L1-b.1.xvSystem & File Scanning[FCI Data]MET100%
FAR 52.204-21(b)(1)(xv)·NIST 800-171 r2 3.14.5
Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
