CMMC Level 1 · RequirementSEC / REQPE.L1-b.1.viii

Physical Protection · PE.L1-b.1.viii

Limit physical access to systems and equipment

Requirement PE.L1-b.1.viii of the fifteen CMMC Level 1 security requirements, in the Physical Protection domain.

Short Answer

Who is allowed to physically reach our systems and equipment?

Only authorized people can physically reach the systems, equipment, and rooms where the work happens.

Official Requirement

Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
Physical Protection (PE)
Requirement ID
PE.L1-b.1.viii
FAR Clause
FAR 52.204-21(b.1.viii)
NIST SP 800-171 Mapping
3.10.1

Assessment Objectives

Common Questions

For paper FCI, is a locked building good enough?
A locked door is part of it, but it is not the whole requirement. Level 1 also expects you to escort and monitor visitors, keep a log of physical access, and control your physical access devices such as keys and badges. Those sit in the related requirement PE.L1-b.1.ix. Limiting who can get in is one piece, and tracking visitors and access is another.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.