CMMC Level 1 · RequirementSEC / REQAC.L1-b.1.iii
Access Control · AC.L1-b.1.iii
Verify and control connections to external systems
Requirement AC.L1-b.1.iii of the fifteen CMMC Level 1 security requirements, in the Access Control domain.
Short Answer
How does Level 1 treat connections to outside systems like cloud services?
Connections to and use of systems outside your control are verified and limited, rather than allowed by default.
Official Requirement
Verify and control/limit connections to and use of external information systems.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Access Control (AC)
- Requirement ID
- AC.L1-b.1.iii
- FAR Clause
- FAR 52.204-21(b.1.iii)
- NIST SP 800-171 Mapping
- 3.1.20
Assessment Objectives
- AC.L1-b.1.iii(a)connections to external systems are identified
- AC.L1-b.1.iii(b)the use of external systems is identified
- AC.L1-b.1.iii(c)connections to external systems are verified
- AC.L1-b.1.iii(d)the use of external systems is verified
- AC.L1-b.1.iii(e)connections to external systems are controlled/limited
- AC.L1-b.1.iii(f)the use of external systems is controlled/limited
Related Requirements
Common Questions
- Can I use Microsoft 365 or regular cloud email for FCI, or do I need GCC High or FedRAMP?
- FedRAMP authorization and GCC High are not Level 1 requirements. They come into play for Controlled Unclassified Information at Level 2. For Federal Contract Information at Level 1, commercial services like Microsoft 365 or Google Workspace are generally acceptable. What this requirement asks is that you identify the external and cloud systems your work touches and then verify and control those connections. A cloud service that stores your FCI is in scope and should be accounted for.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
