Guide
Does CMMC Level 1 require multi-factor authentication?
Short Answer
No. Multi-factor authentication is not one of the fifteen CMMC Level 1 requirements. It is a Level 2 requirement under NIST SP 800-171. Level 1 asks you to identify users and verify their identity before access, which unique accounts and passwords can satisfy.
What Level 1 does ask for on identity
Two of the fifteen requirements cover identity. Identification, IA.L1-b.1.v, is about telling users, processes, and devices apart. Authentication, IA.L1-b.1.vi, is about verifying that identity before granting access. Neither one names MFA.
Other things people think Level 1 requires but it does not
A System Security Plan, a third-party audit, FedRAMP authorization, and GCC High are not Level 1 requirements. They attach to Controlled Unclassified Information at Level 2. MFA is a strong control, and many small suppliers use it anyway. It is simply not one of the fifteen you are assessed against at Level 1.
Related Requirements
Related Definitions
Related Questions
Primary Sources
Build the Record Behind This
AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.
