CMMC Level 1 · Assessment ObjectiveSEC / OBJPE.L1-b.1.viii(a)
Physical Protection · PE.L1-b.1.viii(a)
Authorized individuals allowed physical access are identified
An assessment objective under requirement PE.L1-b.1.viii, Limit Physical Access, in the Physical Protection domain.
Objective Statement
authorized individuals allowed physical access are identified
Source · NIST SP 800-171A
Objective identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Physical Protection (PE)
- Objective ID
- PE.L1-b.1.viii(a)
- Parent Requirement
- PE.L1-b.1.viii · Limit physical access to systems and equipment
Assessment Procedures
The official government assessment method for this objective, from NIST SP 800-171A. An assessor examines artifacts, interviews people, and tests mechanisms to determine the result.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- facility security plan
- physical access control logs or records
- list of personnel with authorized physical access
- visitor access records
- inventory records of physical access devices
- other relevant documents or records
Interview
- Personnel with physical access control responsibilities
- personnel with information security responsibilities
Test
- Physical access control mechanisms
- organizational processes for managing and monitoring physical access
Related Objectives
Source Authority
- Primary Authority
- NIST SP 800-171A
- Requirement Authority
- FAR 52.204-21(b)(1)
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog logs the determination for this objective with its evidence and source record, so your Level 1 self-assessment stays traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make.
