CMMC Level 1 Requirements and the AIC Level 1 Kit
Cybersecurity Maturity Model Certification (CMMC) Level 1 protects Federal Contract Information (FCI) with the 15 safeguarding requirements in Federal Acquisition Regulation (FAR) clause 52.204-21(b)(1). The Analog Informatics Corporation (AIC) Level 1 kit includes the Assessment Binder, Current State Compliance, the server, and the document sharing vault. Configuration compliance is included when workstations connect. Governed mail is optional.
Requirement identifiers and short names follow the CMMC Model in 32 CFR 170.14 and the CMMC Level 1 Assessment Guide. Each identifier ends with the FAR 52.204-21 paragraph it comes from: AC.L1-b.1.i is paragraph (b)(1)(i).
How to read the kit role
| Kit role | Meaning |
|---|---|
| Performs | On the systems and paths the kit manages, the named feature carries out the requirement. |
| Assists | The feature supplies the tool, workflow, or record. People carry out the requirement. |
| Records | The work is physical, personnel, or policy work. The Assessment Binder stores the organization's record. |
Feature names used in the table
- Multi-factor authentication (MFA): a password plus a second step.
- Role-based access control (RBAC): permission checks on every console page and interface.
- Current State Compliance: the console page that lists control findings and runs Rescan.
- Configuration compliance: checks of each enrolled system against its approved baseline configuration.
- Transport Layer Security (TLS): encryption for data moving across the network.
- Federal Information Processing Standards (FIPS) 140-3: the federal standard for validated cryptographic modules.
- Fix-It: the console action that repairs a known setting on an enrolled system.
The 15 Level 1 requirements
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| AC.L1-b.1.i | Authorized Access Control | Performs | Only people with a kit account and an assigned role can sign in, through your directory or a local account, with MFA. RBAC checks every console page. Vault documents open only for named users. | Grant and remove access on systems the kit does not manage. |
| AC.L1-b.1.ii | Transaction & Function Control | Performs | Each role allows only its assigned console functions. Each vault folder and document carries named-user permissions. | Limit transactions and functions on other systems. |
| AC.L1-b.1.iii | External Connections | Performs | Configuration compliance checks each connecting system and can block one that fails. Conditional access limits sign-in by country and network address. | Approve and document connections to external systems. |
| AC.L1-b.1.iv | Control Public Information | Records | The Assessment Binder stores the organization's record. | Review and approve what is posted on public systems. |
| IA.L1-b.1.v | Identification | Performs | Every user is a named person from your directory or a local account. Each enrolled system has its own Agent identity. | Give each user and device a unique identity on other systems. |
| IA.L1-b.1.vi | Authentication | Performs | Sign-in checks your directory or a local password, then MFA. Repeated failures lock the account. | Set password and MFA policy on other systems. |
| MP.L1-b.1.vii | Media Disposal | Records | The Assessment Binder stores the organization's record. | Wipe or destroy media that held FCI with physical tools and a witnessed procedure. |
| PE.L1-b.1.viii | Limit Physical Access | Records | The Assessment Binder stores the organization's record. | Control locks, badges, and facility boundaries. |
| PE.L1-b.1.ix | Manage Visitors & Physical Access | Records | The Assessment Binder stores the organization's record. | Escort visitors, monitor their activity, keep physical access logs, and manage keys and badges. |
| SC.L1-b.1.x | Boundary Protection | Performs | The secure enclave has an isolated network and a secure gateway. Kit traffic is encrypted with TLS through a cryptographic module that holds a FIPS 140-3 certificate. | Operate the firewalls and routers at the organization's boundary. |
| SC.L1-b.1.xi | Public-Access System Separation | Records | The Assessment Binder stores the organization's record. | Put public-facing systems on their own subnetwork. |
| SI.L1-b.1.xii | Flaw Remediation | Assists | Configuration compliance reports flaws on enrolled systems. Fix-It repairs known settings, Current State Compliance Rescan confirms the repair, and product updates are signed. | Patch every host on schedule. |
| SI.L1-b.1.xiii | Malicious Code Protection | Assists | Configuration compliance reports whether antimalware is installed and running, and flags the system for IT when it is not. | Select and operate antimalware or Endpoint Detection and Response (EDR) software. |
| SI.L1-b.1.xiv | Update Malicious Code Protection | Records | The Assessment Binder stores the organization's record. | Update antimalware signatures and engines. |
| SI.L1-b.1.xv | System & File Scanning | Records | The Assessment Binder stores the organization's record. | Schedule periodic scans and real-time scans of files from outside sources. |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.