CMMC Level 1 · RequirementSEC / REQAC.L1-b.1.iv

Access Control · AC.L1-b.1.iv

Control information posted to publicly accessible systems

Requirement AC.L1-b.1.iv of the fifteen CMMC Level 1 security requirements, in the Access Control domain.

Short Answer

What keeps Federal Contract Information off our public website and other public systems?

What goes onto public-facing systems is reviewed and controlled so Federal Contract Information is never posted where anyone can see it.

Official Requirement

Control information posted or processed on publicly accessible information systems.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Access Control (AC)
Requirement ID
AC.L1-b.1.iv
FAR Clause
FAR 52.204-21(b.1.iv)
NIST SP 800-171 Mapping
3.1.22

Assessment Objectives

Common Questions

We do not post to any public systems. Does this requirement apply to us?
This requirement applies to publicly accessible systems that your organization posts information to, such as a public website or portal. Where you have such a system, the point is to keep Federal Contract Information off it. Where you have none, there may be nothing here to control. Whether it applies to your situation is a determination you make.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.