CMMC Level 1 is for FCI- Federal Contract Information that is not critical to national security but must be secured.
The DoD requires DIB Contractors to perform a self assessment for 17 Security Practices, then register
their self-assessments and affirmations in the SPRS (Supplier Performance Risk System).
Level 1 of CMMC addresses the protection of Federal Contract Information (FCI) and encompasses the basic safeguarding requirements for FCI specified in Federal Acquisition Regulation (FAR) Clause 52.204-21.
FAR defines FCI as:
Information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government,
but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.