Skip to content
Framework · DoD CMMC 2.0 / FAR 52.204-21

CMMC L1

The fifteen basic safeguarding requirements from FAR 52.204-21, across six domains. The floor for any contractor handling Federal Contract Information.

15 Talarity controls mapped
Who it's for: Defence contractors and suppliers handling Federal Contract Information (FCI) but not Controlled Unclassified Information.
Talarity coverage

Mapped, monitored, and audit-ready.

Every CMMC L1 control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

15
Talarity controls mapped

Talarity's pre-built control library covering CMMC L1, with linked evidence, owners, and testing schedules.

Cross-maps to
CMMC Level 2NIST SP 800-171NIST CSF

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • IAM access reviews and account inventory
  • Endpoint inventory and patch status
  • Boundary protection and firewall configuration
  • Media handling and disposal records
  • Physical access logs

Your CMMC L1 dashboard

Every completed CMMC L1 assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed CMMC Level 1 (Foundational) assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

Level 1 is treated as trivial until a self-assessment has to be affirmed in SPRS.

Talarity

Each requirement is assessed with evidence attached, so the affirmation rests on artifacts rather than recollection.

Pain

Contractors who will need Level 2 later start again from zero.

Talarity

Level 1 requirements are cross-mapped into Level 2 and NIST SP 800-171, so the work carries forward.

Pain

Annual re-affirmation arrives with nothing kept from last year.

Talarity

Every completed assessment is retained and trended, so re-affirmation is a delta rather than a restart.

CMMC L1 — common questions

What are the six domains?
Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity.
Is Level 1 self-assessed?
Yes — CMMC Level 1 is an annual self-assessment with an affirmation by a company official. Talarity holds the assessment, the evidence and the history behind that affirmation.
What if we handle CUI as well as FCI?
Then Level 2 applies. Talarity carries Level 1 answers and evidence into the Level 2 assessment rather than asking for them twice.

Working with CMMC L1

Step-by-step walkthroughs from the Talarity library.

Ready to ship CMMC L1?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.