CMMC Level 1 · RequirementSEC / REQSC.L1-b.1.x
System and Communications Protection · SC.L1-b.1.x
Monitor and control communications at the boundary
Requirement SC.L1-b.1.x of the fifteen CMMC Level 1 security requirements, in the System and Communications Protection domain.
Short Answer
What does Level 1 expect us to do at our network boundary?
Traffic in and out of the network, and across key internal boundaries, is monitored and controlled rather than left open.
Official Requirement
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- System and Communications Protection (SC)
- Requirement ID
- SC.L1-b.1.x
- FAR Clause
- FAR 52.204-21(b.1.x)
- NIST SP 800-171 Mapping
- 3.13.1
Assessment Objectives
- SC.L1-b.1.x(a)the external system boundary is defined
- SC.L1-b.1.x(b)key internal system boundaries are defined
- SC.L1-b.1.x(c)communications are monitored at the external system boundary
- SC.L1-b.1.x(d)communications are monitored at key internal boundaries
- SC.L1-b.1.x(e)communications are controlled at the external system boundary
- SC.L1-b.1.x(f)communications are controlled at key internal boundaries
- SC.L1-b.1.x(g)communications are protected at the external system boundary
- SC.L1-b.1.x(h)communications are protected at key internal boundaries
Related Requirements
Common Questions
- Is a firewall enough to meet this?
- A firewall is the core of it. The requirement is to monitor, control, and protect communications at your network boundary and at key internal boundaries. A properly configured firewall, with a record that it is reviewed, is the usual way a small supplier meets it.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
