Overview
CMMC Level 1 Scoping
Defining the CMMC Assessment scope
Prior to conducting the Level 1 self-assessment, the Organization Seeking Assessment (OSA) must specify the CMMC Assessment Scope. This scope defines the assets within the OSA’s environment that will be assessed. A key difference for Level 1 is that there are no documentation requirements for the self-assessment, including documentation for In-Scope, Out-of-Scope, or Specialized Assets. However, developing a System Security Plan (SSP) is recommended as a best practice.
Asset Categorization for CMMC Level 1
The scoping process categorizes assets based on their relationship with Federal Contract Information (FCI)
-
In-Scope Assets: In-Scope assets are those that are part of the CMMC Assessment Scope and are assessed against all Level 1 requirements. These include all assets that:
- Process FCI: FCI is used by the asset, such as when it is accessed, entered, edited, generated, manipulated, or printed
- Store FCI: FCI is inactive or at rest on the asset, such as when it is located on electronic media, in system component memory, or in physical format (like paper documents)
- Transmit FCI: FCI is being transferred from one asset to another using physical or digital transport methods (data in transit)
- Out-of-Scope Assets: Assets that are considered out of scope are those that do not process, store, or transmit FCI. These assets are not part of the self-assessment
-
Specialized Assets: Specialized Assets are those that can process, store, or transmit FCI but are defined in regulations as being unable to be fully secured. These assets are explicitly not part of the Level 1 self-assessment scope and are not assessed against CMMC requirement.
Examples of Specialized Assets for Level 1 include:- Government Furnished Equipment (GFE): Property provided by the government to the contractor for contract performance
- Internet of Things (IoT) or Industrial Internet of Things (IIoT): Interconnected devices with sensing/actuation and programmability features, such as smart electric grids or lighting systems
- Operational Technology (OT): Programmable systems or devices that interact with the physical environment to monitor or control processes, including industrial control systems, building management systems, and Supervisory Control and Data Acquisition (SCADA)
- Restricted Information Systems: Systems configured entirely based on government security requirements to support a contract (e.g., fielded systems or obsolete systems)
- Test Equipment: Hardware and/or associated IT components utilized in the testing of products, system components, and contract deliverables
Considerations for CMMC Level 1 Scoping
To appropriately scope a Level 1 self-assessment, the following four components of its environment that process, store, or transmit FCI should be considered:
| People | Individuals who interact with FCI | Researchers, IT staff, contractors, vendors, external service providers, etc. |
|---|---|---|
| Technology | Information systems and components | Servers, client computers/endpoints, mobile devices, network appliances (firewalls, switches, APs, routers), VoIP devices, applications, virtual machines, database systems, etc. |
| Facilities | Physical locations related to FCI handling | Physical office locations, satellite/off-site offices, server rooms, datacenters, manufacturing plants, and secured rooms |
| External Service Providers (ESPs) | External entities utilized for comprehensive IT and/or cybersecurity services provision and management on behalf of the OSA | External people, technology, or facilities utilized by the OSA |
The CMMC compliance boundary should be strictly limited to only the systems, personnel, and facilities that process, store, and transmit FCI. By limiting the scope, you drastically reduce the number of controls to implement, simplifying documentation, and accelerating the path to compliance.
CMMC Level 1 Security Requirements
This table itemizes the security requirements for each domain and at each level. Each requirement has a requirement identification number in the format – DD.L#-REQ – where:
- DD is the two-letter domain abbreviation that align with the families specified in NIST 800-171 Rev. 2;
- L# is the level number; and
- REQ is the FAR Clause 52.204-21 paragraph number, NIST SP 800-171 Rev 2, or NIST SP 800-172 security requirement number.
| ID # | Control Name | Description |
|---|---|---|
| ACCESS CONTROL (AC) | ||
| AC.L1-b.1.i | Authorized Access Control [FCI Data] | Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). |
| AC.L1-b.1.ii | Transaction & Function Control [FCI Data] | Limit information system access to the types of transactions and functions that authorized users are permitted to execute. |
| AC.L1-b.1.iii | External Connections [FCI Data] | Verify and control/limit connections to and use of external information systems. |
| AC.L1-b.1.iv | Control Public Information [FCI Data] | Control information posted or processed on publicly accessible information systems. |
| IDENTIFICATION AND AUTHENTICATION (IA) | ||
| IA.L1-b.1.v | Identification [FCI Data] | Identify information system users, processes acting on behalf of users, or devices. |
| IA.L1-b.1.vi | Authentication [FCI Data] | Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. |
| MEDIA PROTECTION (MP) | ||
| MP.L1-b.1.vii | Media Disposal [FCI Data] | Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. |
| PHYSICAL PROTECTION (PE) | ||
| PE.L1-b.1.viii | Limit Physical Access [FCI Data] | Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. |
| PE.L1-b.1.ix | Manage Visitors & Physical Access [FCI Data] | Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices. |
| SYSTEM AND COMMUNICATIONS PROTECTION (SC) | ||
| SC.L1-b.1.x | Boundary Protection [FCI Data] | Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. |
| SC.L1-b.1.xi | Public-Access System Separation [FCI Data] | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. |
| SYSTEM AND INFORMATION INTEGRITY (SI) | ||
| SI.L1-b.1.xii | Flaw Remediation [FCI Data] | Identify, report, and correct information and information system flaws in a timely manner. |
| SI.L1-b.1.xiii | Malicious Code Protection [FCI Data] | Provide protection from malicious code at appropriate locations within organizational information systems. |
| SI.L1-b.1.xiv | Update Malicious Code Protection [FCI Data] | Update malicious code protection mechanisms when new releases are available. |
| SI.L1-b.1.xv | System & File Scanning [FCI Data] | Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed. |