CMMC Level 1 · RequirementSEC / REQSC.L1-b.1.xi
System and Communications Protection · SC.L1-b.1.xi
Separate publicly accessible systems from internal networks
Requirement SC.L1-b.1.xi of the fifteen CMMC Level 1 security requirements, in the System and Communications Protection domain.
Short Answer
Do public-facing systems have to be separated from our internal network?
Anything the public can reach sits on a separate subnetwork, so a public-facing component cannot open a path straight into internal systems.
Official Requirement
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
Source · FAR 52.204-21(b)(1)
Requirement identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- System and Communications Protection (SC)
- Requirement ID
- SC.L1-b.1.xi
- FAR Clause
- FAR 52.204-21(b.1.xi)
- NIST SP 800-171 Mapping
- 3.13.5
Assessment Objectives
Related Requirements
Common Questions
- We run a public website. Does it need to be separated from our internal network?
- Where you run publicly accessible components, this requirement asks you to place them on a subnetwork that is separated, physically or logically, from your internal systems. That keeps a public-facing component from opening a direct path into internal systems that hold FCI. Many small suppliers meet this by hosting public sites externally, away from the internal network.
Source Authority
- Primary Authority
- FAR 52.204-21(b)(1)
- Objectives Authority
- NIST SP 800-171A
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.
