CMMC Level 1 · RequirementSEC / REQSC.L1-b.1.xi

System and Communications Protection · SC.L1-b.1.xi

Separate publicly accessible systems from internal networks

Requirement SC.L1-b.1.xi of the fifteen CMMC Level 1 security requirements, in the System and Communications Protection domain.

Short Answer

Do public-facing systems have to be separated from our internal network?

Anything the public can reach sits on a separate subnetwork, so a public-facing component cannot open a path straight into internal systems.

Official Requirement

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
Source · FAR 52.204-21(b)(1)

Requirement identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Communications Protection (SC)
Requirement ID
SC.L1-b.1.xi
FAR Clause
FAR 52.204-21(b.1.xi)
NIST SP 800-171 Mapping
3.13.5

Assessment Objectives

Common Questions

We run a public website. Does it need to be separated from our internal network?
Where you run publicly accessible components, this requirement asks you to place them on a subnetwork that is separated, physically or logically, from your internal systems. That keeps a public-facing component from opening a direct path into internal systems that hold FCI. Many small suppliers meet this by hosting public sites externally, away from the internal network.

Source Authority

Primary Authority
FAR 52.204-21(b)(1)
Objectives Authority
NIST SP 800-171A
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog connects this requirement to its assessment objectives, your evidence, and your determination, and keeps the whole record traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make and record.