CMMC Level 1 · RequirementSEC / REQIA.L1-b.1.vi

Identification and Authentication · IA.L1-b.1.vi

Authenticate users before granting access

Requirement IA.L1-b.1.vi of the fifteen CMMC Level 1 security requirements, in the Identification and Authentication domain.

Short Answer

How do users prove who they are before they are given access?

Identities are proven, not just claimed, before access is granted. A password, token, or equivalent verifies who is connecting.

Official Requirement

Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Identification and Authentication (IA)
Requirement ID
IA.L1-b.1.vi
FAR Clause
FAR 52.204-21(b.1.vi)
NIST SP 800-171 Mapping
3.5.2

Assessment Objectives

Common Questions

Does CMMC Level 1 require multi-factor authentication (MFA)?
No. MFA is not one of the fifteen Level 1 requirements. It is a Level 2 requirement under NIST SP 800-171. Level 1 asks you to identify your users and devices and then verify their identity before access, for example with unique accounts and passwords. MFA is a strong control that many small suppliers still choose to use. It is simply not one of the fifteen you are assessed against at Level 1.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.