CMMC Level 1 · RequirementSEC / REQIA.L1-b.1.vi
Identification and Authentication · IA.L1-b.1.vi
Authenticate users before granting access
Requirement IA.L1-b.1.vi of the fifteen CMMC Level 1 security requirements, in the Identification and Authentication domain.
Short Answer
How do users prove who they are before they are given access?
Identities are proven, not just claimed, before access is granted. A password, token, or equivalent verifies who is connecting.
Official Requirement
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Identification and Authentication (IA)
- Requirement ID
- IA.L1-b.1.vi
- FAR Clause
- FAR 52.204-21(b.1.vi)
- NIST SP 800-171 Mapping
- 3.5.2
Assessment Objectives
- IA.L1-b.1.vi(a)the identity of each user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(b)the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(c)the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access
Related Requirements
Common Questions
- Does CMMC Level 1 require multi-factor authentication (MFA)?
- No. MFA is not one of the fifteen Level 1 requirements. It is a Level 2 requirement under NIST SP 800-171. Level 1 asks you to identify your users and devices and then verify their identity before access, for example with unique accounts and passwords. MFA is a strong control that many small suppliers still choose to use. It is simply not one of the fifteen you are assessed against at Level 1.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
