Guide
Does CMMC Level 1 Require Encryption?
Short Answer
None of the 15 CMMC Level 1 requirements in FAR 52.204-21(b)(1) names encryption, and none of the 59 Level 1 assessment objectives requires it. FIPS-validated cryptography is NIST SP 800-171 requirement 3.13.11, which the CMMC rule treats as a Level 2 requirement for protecting CUI. Level 1 does require you to protect communications at your system boundaries and to sanitize or destroy media containing FCI. Encryption is one way to do either, and you may choose it.
Why the Confusion Exists
Encryption runs through most security advice, and CMMC material often discusses it without saying which level it belongs to. The best known example is the Level 2 requirement for FIPS-validated cryptography, which the CMMC rule singles out in its Level 2 scoring.
The Level 1 guide uses the word too. The DoD CMMC Assessment Guide, Level 1, Version 2.13, names encrypted tunnels among the kinds of boundary components (page 35), lists cryptographic erase among sanitization techniques (page 27), and asks, among its potential assessment considerations, whether boundary data is protected, for example by "applying encryption when required or prudent" (page 36). Examples like these are easy to read as requirements.
The guide describes its examples as insight, not as a prescription of how a requirement must be implemented, and its assessment considerations as potential questions that may be asked when assessing the objectives (page 10).
What the Current Authority Says
Under 32 CFR 170.14(c)(2), the Level 1 security requirements are FAR 52.204-21(b)(1)(i) through (xv). The 15 items cover access, identification and authentication, media disposal, physical access, boundary protection, separation of public systems, flaw remediation, and malicious code protection. None of them names encryption or cryptography.
32 CFR 170.15(c)(1)(i) requires the Level 1 self-assessment to use the objectives of NIST SP 800-171A (June 2018) for the NIST requirements that Table 2 to 32 CFR 170.15(c)(1)(ii) maps to Level 1. NIST requirement 3.13.11 is not in that table, and none of the 59 objectives it produces mentions encryption.
FIPS-validated cryptography is NIST SP 800-171 requirement 3.13.11, identified in the CMMC rule as SC.L2-3.13.11. 32 CFR 170.24(c)(2) states that FIPS-validated encryption is required to protect the confidentiality of CUI and sets how that requirement is scored at Level 2. Level 1 has no numeric score. Under 32 CFR 170.24(c)(1), Level 1 results are MET or NOT MET in their entirety.
Two Level 1 requirements touch the subject without naming it. SC.L1-b.1.x requires you to monitor, control, and protect organizational communications at the external and key internal boundaries of your systems, and its objectives include "communications are protected at the external system boundary". MP.L1-b.1.vii requires you to sanitize or destroy system media containing FCI before disposal or release for reuse. Each objective states what must be achieved, not which technology achieves it.
FAR 52.204-21(b)(2) adds that the clause does not relieve a contractor of other safeguarding requirements specified by federal agencies, or of the federal requirements for CUI. Another clause in a contract can carry its own terms.
What This Means
Encryption is not a separate item you assess at Level 1. You assess the 15 requirements against their 59 objectives. If your systems use encryption to protect communications at a boundary or to make media unreadable before disposal, that encryption can be part of your evidence for those objectives.
Nothing in Level 1 discourages encryption, and you may use it wherever it fits. If your work involves CUI, that is the Level 2 world, where FIPS-validated cryptography is required to protect it.
Read each contract for other clauses. A requirement that comes from another clause or agency applies on its own terms, whatever Level 1 says.
Related Requirements
Related Definitions
Related Questions
Primary Sources
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Written By
- AssessrLog, from the primary sources listed above
Cite This Page
“Does CMMC Level 1 Require Encryption?.” AssessrLog, a product of ProfytAI Pte. Ltd.. https://assessrlog.com/cmmc/guides/does-cmmc-level-1-require-encryption/
Build the Record Behind This
AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.
