CMMC Level 1 · RequirementSEC / REQAC.L1-b.1.ii
Access Control · AC.L1-b.1.ii
Limit access to permitted transactions and functions
Requirement AC.L1-b.1.ii of the fifteen CMMC Level 1 security requirements, in the Access Control domain.
Short Answer
Do authorized users get access to everything, or only what their role needs?
Authorized users get only the transactions and functions their role permits, not blanket access to everything the system can do.
Official Requirement
Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- Access Control (AC)
- Requirement ID
- AC.L1-b.1.ii
- FAR Clause
- FAR 52.204-21(b.1.ii)
- NIST SP 800-171 Mapping
- 3.1.2
Assessment Objectives
Related Requirements
Common Questions
- Does this mean I have to build detailed roles and permissions?
- Not necessarily. The requirement is that users can only run the transactions and functions their role permits, not that you build an elaborate role system. For a small supplier, using the built-in roles in your systems and not handing everyone administrator rights usually covers the intent.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
