CMMC Level 1 · RequirementSEC / REQAC.L1-b.1.i
Access Control · AC.L1-b.1.i
Limit system access to authorized users
Requirement AC.L1-b.1.i of the fifteen CMMC Level 1 security requirements, in the Access Control domain.
Short Answer
Who is allowed to access systems that hold Federal Contract Information?
Only authorized users, the processes acting on their behalf, and authorized devices may reach systems that hold Federal Contract Information. Everything else is kept out.
Official Requirement
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Access Control (AC)
- Requirement ID
- AC.L1-b.1.i
- FAR Clause
- FAR 52.204-21(b.1.i)
- NIST SP 800-171 Mapping
- 3.1.1
Assessment Objectives
- AC.L1-b.1.i(a)authorized users are identified
- AC.L1-b.1.i(b)processes acting on behalf of authorized users are identified
- AC.L1-b.1.i(c)devices (and other systems) authorized to connect to the system are identified
- AC.L1-b.1.i(d)system access is limited to authorized users
- AC.L1-b.1.i(e)system access is limited to processes acting on behalf of authorized users
- AC.L1-b.1.i(f)system access is limited to authorized devices (including other systems)
Related Requirements
Common Questions
- Can my team use personal or home computers to access FCI?
- Any device or home network that stores, processes, or transmits Federal Contract Information comes into scope, and access to it is limited to authorized users. Level 1 does not ban personal devices outright, but a device that touches FCI is treated like any other in-scope system and access to it must be controlled. Whether a given device is in scope is a determination you make.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
