CMMC Level 1 · Assessment ObjectiveSEC / OBJIA.L1-b.1.vi(b)

Identification and Authentication · IA.L1-b.1.vi(b)

The identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access

An assessment objective under requirement IA.L1-b.1.vi, Authentication, in the Identification and Authentication domain.

Objective Statement

the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access
Source · NIST SP 800-171A

Objective identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Identification and Authentication (IA)
Objective ID
IA.L1-b.1.vi(b)

Assessment Procedures

The official government assessment method for this objective, from NIST SP 800-171A. An assessor examines artifacts, interviews people, and tests mechanisms to determine the result.

Examine

  • Identification and authentication policy
  • procedures addressing user identification and authentication
  • system security plan
  • system design documentation
  • system configuration settings and associated documentation
  • list of system accounts
  • other relevant documents or records

Interview

  • Personnel with identification and authentication responsibilities
  • system or network administrators
  • personnel with information security responsibilities

Test

  • Organizational processes for uniquely identifying and authenticating users, processes, and devices
  • mechanisms supporting or implementing identification and authentication capability

Source Authority

Primary Authority
NIST SP 800-171A
Requirement Authority
FAR 52.204-21(b)(1)
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog logs the determination for this objective with its evidence and source record, so your Level 1 self-assessment stays traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make.