Model Architecture
CMMC L1 Domains
CMMC L1 Practices
Evidence Requirements
Assessment Methods and objects
100

Within each CMMC domain, every security practice is assigned a unique identifier following the numbering scheme “DD.L#-REQ”. Here, DD is the two-letter domain abbreviation (e.g., AC for Access Control, SI for System & Information Integrity), L# is the level (1, 2, or 3), and REQ is the corresponding paragraph or control number from FAR 52.204-21, NIST SP 800-171 Rev 2, or NIST SP 800-172. For instance, AC.L2-3.1.5 refers to the “Least Privilege” control drawn from NIST SP 800-171 Section 3.1.5.

What is the Requirement Identification Number?

100

This term refers to an activity or set of activities that are performed to meet the defined objectives of the Cybersecurity Maturity Model Certification (CMMC).

What is a practice?

100

An assessor would review these which include documents such as the access control policy, procedures addressing account management, system security plan, lists of active system accounts, notifications of terminated employees, and system audit logs.

What are objects?

100

This criterion determines if a given artifact, interview response, or demonstration meets the CMMC practice and answers "Does the Assessment Team have the right Evidence?"

What is adequacy of evidence?

100

Evidence that is relevant to the domain/practice, satisfies the practice objectives, and fully represents the performance of the control or practice meets these standards for CMMC assessments.

What is acceptable evidence in a CMMC assessment?

200

This concept highlights that each higher CMMC Maturity Level builds upon the requirements and practices of the preceding lower levels. For instance, an organization seeking CMMC Level 2 certification must also demonstrate its implementation of all Level 1 practices, ensuring foundational controls are established before more advanced measures are introduced.

What is the cumulative nature of CMMC Maturity levels?

200

This domain deals with meticulously limiting who and what can access an organization's information systems, specifying that access must be confined solely to authorized users, processes operating on their behalf, and approved devices, fundamentally relying on the prerequisite establishment of a trusted identity to enforce these critical safeguarding requirements for Federal Contract Information.

What is the Access Control (AC) domain?

200

To meet this practice, you must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems), focusing on account management for systems and applications.

What is AC.L1-3.1.1?

200

This criterion verifies that coverage by domain, practice, and organizational units is enough to rate against each practice, answering "Does the Assessment Team have enough of the right Evidence?"

What is sufficiency of evidence?

200

This assessment method involves reviewing, inspecting, and analyzing artifacts—such as policies, procedures, and system configurations—to gather evidence that directly maps to the CMMC practice objectives without interacting with live systems or personnel.

What is Examine?

300

This term in CMMC 2.0 refers to a grouping of like practices based on the 14 control families set forth in NIST SP 800-171, with each domain focusing on a specific area of security.

What is a Domain?

300

This domain's scope within CMMC Level 1 addresses the crucial safeguarding of Federal Contract Information by requiring specific consideration and management of systems that are exposed to external entities, exemplified by the handling of publicly accessible systems, which, depending on their existence within the contractor's environment, may necessitate specific practices or be deemed not applicable during assessment.

What is the System & Communications Protection (SC) domain?

 

300

OSCs or OSAs must produce this kind of evidence to demonstrate their implementation of CMMC practices. It should be tangible and verifiable, such as documented policies, system configurations, audit logs, or records of security activities.

What is objective evidence?

300

When examined artifacts do not sufficiently answer both adequacy and sufficiency questions, this exists and may point to deficiencies in the OSC's cybersecurity implementation.
 

What is an Evidence gap?

300

This assessment method requires observing or exercising a mechanism or activity under specified conditions—such as attempting to log in with revoked credentials or running a vulnerability scan—to verify if the actual behavior meets the CMMC practice’s expected results.

What is Test?

400

As defined in 32 CFR § 170.4, this term refers to a set of determination statements that collectively express the desired outcome for assessing a security requirement. Successful implementation of the corresponding CMMC security requirement necessitates meeting all of them.

What is an Assessment Objective?

400

This domain focuses on keeping information and information systems reliable and protected from harm. It requires identifying, reporting, and correcting system flaws within specified timeframes by applying necessary updates. Additionally, practices in this domain mandate placing safeguards at appropriate locations to defend against malicious code like viruses, ensuring these protective measures are updated frequently, and conducting regular scans of the information system and files from outside sources.

What is the System and Information Integrity (SI) domain?

400

This CMMC Practice requires that assessors determine the following

[a] connections to external systems are identified;

[b] the use of external systems is identified;

[c] connections to external systems are verified;

 [d] the use of external systems is verified;

[e] connections to external systems are controlled/limited; and

[f] the use of external systems is controlled/limited.

 What is AC.L1-3.1.20?

400

These tangible and reviewable records are the direct outcome of a practice or process being performed and can be hard-copy, electronic, or embedded in software, but must be a result from performance of a process within the OSC.

What are artifacts?

400

These refer to hardware, software, or firmware safeguards—such as firewalls, encryption modules, or access control mechanisms—that enforce security controls and can be directly examined or tested to verify conformance with CMMC requirements.

 What are Mechanisms?

500

These are the specific items undergoing evaluation during an assessment, which can encompass specifications like policies and procedures, mechanisms such as hardware and software safeguards, protection-related activities involving people, and the individuals themselves who apply these elements.

What is Assessment Objects?

500

Practices in this domain mandate the rigorous provision of a vetted and trusted identity for subjects seeking access to information systems, serving as a pivotal foundational element that is subsequently leveraged by other critical security domains, such as Access Control, to enforce precise and secure limitations on system utilization and data protection within the CMMC framework.

What is the Identification & Authentication (IA) domain?

500

This CMMC level 1 Practice mandates contractors to institute measures for identifying, controlling and managing physical access devices.

What is PE.L1-3.10.5?

500

To demonstrate compliance with SC.L2-3.13.11 (CUI Encryption), assessors must obtain proof that any cryptographic module used for CUI-at-rest protection this. Evidence typically includes a certificate or listing that shows the module is approved under the NIST Cryptographic Module Validation Program (CMVP).

What is an assessor validate that the cryptographic modules is FIPS 140-2 compliant?

500

This can be performing a scheduled system backup and restoring a test file—done to verify that backup procedures meet CMMC objectives for data availability and integrity under Test and belongs to this type of assessment object.

What is an Activity?