CMMC Level 1 · GuideSEC / GDE

Guide

Does CMMC Level 1 require multi-factor authentication?

Short Answer

No. Multi-factor authentication is not one of the fifteen CMMC Level 1 requirements. It is a Level 2 requirement under NIST SP 800-171. Level 1 asks you to identify users and verify their identity before access, which unique accounts and passwords can satisfy.

What Level 1 does ask for on identity

Two of the fifteen requirements cover identity. Identification, IA.L1-b.1.v, is about telling users, processes, and devices apart. Authentication, IA.L1-b.1.vi, is about verifying that identity before granting access. Neither one names MFA.

Other things people think Level 1 requires but it does not

A System Security Plan, a third-party audit, FedRAMP authorization, and GCC High are not Level 1 requirements. They attach to Controlled Unclassified Information at Level 2. MFA is a strong control, and many small suppliers use it anyway. It is simply not one of the fifteen you are assessed against at Level 1.

Primary Sources

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.