Free CMMC Level 1 readiness check
The 15 basic safeguarding requirements behind FAR 52.204-21 (they map to 17 NIST SP 800-171 control checks) — answer honestly and see where you stand in about two minutes. No signup, nothing stored about your systems.
1. Only people, accounts, and devices you've approved should be able to get onto your systems.
2. Users should only be able to do the specific things their job requires, not everything.
3. Control how outside systems and personal devices connect to or handle your data.
4. Make sure sensitive information never ends up on your public website or other public systems.
5. Every user and device on your systems should have a unique identity.
6. Verify that users and devices are who they claim before letting them in.
7. Wipe or destroy media before throwing it away or reusing it.
8. Limit physical access to your systems, equipment, and facilities to authorized people.
9. Escort visitors and monitor their activity.
10. Keep records of who physically accessed your facility.
11. Manage and control physical access devices like keys, badges, and locks.
12. Monitor and control communications at the external boundary and key internal boundaries of your network.
13. Put publicly accessible systems on a separate subnetwork from your internal network.
14. Find, report, and fix system flaws in a timely way.
15. Protect your systems from malicious code.
16. Keep your malicious-code protection up to date.
17. Scan your systems periodically and scan files in real time as they are used.
0 of 17 answered
Informational only — not a compliance determination, an assessment, or legal advice.