CMMC Level 1 Requirements and the AIC Level 1 Kit

Cybersecurity Maturity Model Certification (CMMC) Level 1 protects Federal Contract Information (FCI) with the 15 safeguarding requirements in Federal Acquisition Regulation (FAR) clause 52.204-21(b)(1). The Analog Informatics Corporation (AIC) Level 1 kit includes the Assessment Binder, Current State Compliance, the server, and the document sharing vault. Configuration compliance is included when workstations connect. Governed mail is optional.

Requirement identifiers and short names follow the CMMC Model in 32 CFR 170.14 and the CMMC Level 1 Assessment Guide. Each identifier ends with the FAR 52.204-21 paragraph it comes from: AC.L1-b.1.i is paragraph (b)(1)(i).

What Availability Means

How to read the kit role

Kit roleMeaning
PerformsOn the systems and paths the kit manages, the named feature carries out the requirement.
AssistsThe feature supplies the tool, workflow, or record. People carry out the requirement.
RecordsThe work is physical, personnel, or policy work. The Assessment Binder stores the organization's record.

Feature names used in the table

  • Multi-factor authentication (MFA): a password plus a second step.
  • Role-based access control (RBAC): permission checks on every console page and interface.
  • Current State Compliance: the console page that lists control findings and runs Rescan.
  • Configuration compliance: checks of each enrolled system against its approved baseline configuration.
  • Transport Layer Security (TLS): encryption for data moving across the network.
  • Federal Information Processing Standards (FIPS) 140-3: the federal standard for validated cryptographic modules.
  • Fix-It: the console action that repairs a known setting on an enrolled system.

The 15 Level 1 requirements

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
AC.L1-b.1.iAuthorized Access ControlPerformsOnly people with a kit account and an assigned role can sign in, through your directory or a local account, with MFA. RBAC checks every console page. Vault documents open only for named users.Grant and remove access on systems the kit does not manage.
AC.L1-b.1.iiTransaction & Function ControlPerformsEach role allows only its assigned console functions. Each vault folder and document carries named-user permissions.Limit transactions and functions on other systems.
AC.L1-b.1.iiiExternal ConnectionsPerformsConfiguration compliance checks each connecting system and can block one that fails. Conditional access limits sign-in by country and network address.Approve and document connections to external systems.
AC.L1-b.1.ivControl Public InformationRecordsThe Assessment Binder stores the organization's record.Review and approve what is posted on public systems.
IA.L1-b.1.vIdentificationPerformsEvery user is a named person from your directory or a local account. Each enrolled system has its own Agent identity.Give each user and device a unique identity on other systems.
IA.L1-b.1.viAuthenticationPerformsSign-in checks your directory or a local password, then MFA. Repeated failures lock the account.Set password and MFA policy on other systems.
MP.L1-b.1.viiMedia DisposalRecordsThe Assessment Binder stores the organization's record.Wipe or destroy media that held FCI with physical tools and a witnessed procedure.
PE.L1-b.1.viiiLimit Physical AccessRecordsThe Assessment Binder stores the organization's record.Control locks, badges, and facility boundaries.
PE.L1-b.1.ixManage Visitors & Physical AccessRecordsThe Assessment Binder stores the organization's record.Escort visitors, monitor their activity, keep physical access logs, and manage keys and badges.
SC.L1-b.1.xBoundary ProtectionPerformsThe secure enclave has an isolated network and a secure gateway. Kit traffic is encrypted with TLS through a cryptographic module that holds a FIPS 140-3 certificate.Operate the firewalls and routers at the organization's boundary.
SC.L1-b.1.xiPublic-Access System SeparationRecordsThe Assessment Binder stores the organization's record.Put public-facing systems on their own subnetwork.
SI.L1-b.1.xiiFlaw RemediationAssistsConfiguration compliance reports flaws on enrolled systems. Fix-It repairs known settings, Current State Compliance Rescan confirms the repair, and product updates are signed.Patch every host on schedule.
SI.L1-b.1.xiiiMalicious Code ProtectionAssistsConfiguration compliance reports whether antimalware is installed and running, and flags the system for IT when it is not.Select and operate antimalware or Endpoint Detection and Response (EDR) software.
SI.L1-b.1.xivUpdate Malicious Code ProtectionRecordsThe Assessment Binder stores the organization's record.Update antimalware signatures and engines.
SI.L1-b.1.xvSystem & File ScanningRecordsThe Assessment Binder stores the organization's record.Schedule periodic scans and real-time scans of files from outside sources.

Screenshots

Measurement and Mitigation checks the environment against the selected framework and level.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.