CMMC Level 1 · RequirementSEC / REQAC.L1-b.1.iii

Access Control · AC.L1-b.1.iii

Verify and control connections to external systems

Requirement AC.L1-b.1.iii of the fifteen CMMC Level 1 security requirements, in the Access Control domain.

Short Answer

How does Level 1 treat connections to outside systems like cloud services?

Connections to and use of systems outside your control are verified and limited, rather than allowed by default.

Official Requirement

Verify and control/limit connections to and use of external information systems.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Access Control (AC)
Requirement ID
AC.L1-b.1.iii
FAR Clause
FAR 52.204-21(b.1.iii)
NIST SP 800-171 Mapping
3.1.20

Assessment Objectives

Common Questions

Can I use Microsoft 365 or regular cloud email for FCI, or do I need GCC High or FedRAMP?
FedRAMP authorization and GCC High are not Level 1 requirements. They come into play for Controlled Unclassified Information at Level 2. For Federal Contract Information at Level 1, commercial services like Microsoft 365 or Google Workspace are generally acceptable. What this requirement asks is that you identify the external and cloud systems your work touches and then verify and control those connections. A cloud service that stores your FCI is in scope and should be accounted for.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.