Deadline

Nov 2026: DoD CMMC L2 enforcement begins for new prime contracts. Most DIB firms aren't ready. See your gap →

CMMC · Level 1 (FCI)

17 controls. Annual self-assessment. One executive affirmation.

If your DoD contracts cite FAR 52.204-21 but not CUI handling, Level 1 is your target. Cincra walks you through all 17 basic safeguards, generates the affirmation, and tracks the annual recertification.

PilotCincra is currently a pilot — not yet authorized for live CUI storage. Use representative or redacted artifacts only. GovCloud / FedRAMP on roadmap.
The 17 controls

What L1 actually requires.

The 17 FAR safeguards map to six 800-171 families: Access Control, Identification & Authentication, Media Protection, Physical Protection, System & Communications Protection, and System & Information Integrity. Cincra rewrites each in plain English and produces the evidence binder.

Illustration of a small defense contractor workshop showing basic Level 1 safeguards: a locked filing cabinet, shared workstation, simple firewall, and a short checklist of 17 controls — no CUI enclave or advanced encryption.
17 safeguards · Annual self-check · No C3PAO required
Frequently asked

L1 questions.

Any DoD contractor whose contracts include FAR 52.204-21 — basic safeguarding of Federal Contract Information. If your contracts do not yet mention CUI or DFARS 252.204-7012, L1 is your target.

Start your L1 program in an afternoon.

Cincra is not a C3PAO. This platform automates CMMC readiness, evidence collection, and audit preparation. It does not issue CMMC certifications and does not bind any C3PAO assessment outcome. Attestations generated here reflect the authoring auditor's professional opinion only.