CMMC Level 1 · RequirementSEC / REQIA.L1-b.1.v
Identification and Authentication · IA.L1-b.1.v
Identify system users, processes, and devices
Requirement IA.L1-b.1.v of the fifteen CMMC Level 1 security requirements, in the Identification and Authentication domain.
Short Answer
Does Level 1 mean every user, process, and device needs its own identity?
Every user, automated process, and device on the system can be told apart, so access can be tied to a known identity.
Official Requirement
Identify information system users, processes acting on behalf of users, or devices.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Identification and Authentication (IA)
- Requirement ID
- IA.L1-b.1.v
- FAR Clause
- FAR 52.204-21(b.1.v)
- NIST SP 800-171 Mapping
- 3.5.1
Assessment Objectives
Related Requirements
Common Questions
- Does this mean everyone needs their own login, with no shared accounts?
- The requirement is that each user, each process acting for a user, and each device can be told apart. Shared, generic accounts make that hard, because you cannot tie an action back to a known identity. Giving each person their own account is the usual way suppliers meet the intent here.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
