CMMC Level 1 · RequirementSEC / REQSI.L1-b.1.xii

System and Information Integrity · SI.L1-b.1.xii

Identify, report, and correct system flaws

Requirement SI.L1-b.1.xii of the fifteen CMMC Level 1 security requirements, in the System and Information Integrity domain.

Short Answer

How quickly do we have to find and fix known security flaws?

Security flaws are found, reported, and fixed on a defined timeline rather than left unpatched.

Official Requirement

Identify, report, and correct information and information system flaws in a timely manner.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Information Integrity (SI)
Requirement ID
SI.L1-b.1.xii
FAR Clause
FAR 52.204-21(b.1.xii)
NIST SP 800-171 Mapping
3.14.1

Assessment Objectives

Common Questions

How fast do I have to patch?
The requirement is to identify, report, and correct flaws in a timely manner, and to define what timely means for you. Level 1 does not set a fixed number of days. Choosing a reasonable timeframe, such as applying important updates within a defined window, and keeping to it is how suppliers meet the intent.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.