CMMC 2.0 Level 1
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.1: Authorized Access Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(i) (3.1.1).
- Account inventory limiting system access to authorized users, processes and devices
- Access authorization records
- Shared/unauthorized accounts with FCI access
CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.2: Transaction and Function Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ii) (3.1.2).
- Role/permission matrix limiting access to permitted transactions and functions
- Users able to execute functions beyond their role
CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.20: External Connections - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iii) (3.1.20).
- Inventory + authorization of external system connections
- Controls verifying/limiting use of external systems
- Unverified external connections to FCI systems
CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.22: Control Public Information - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(iv) (3.1.22).
- Review/approval process for information posted to publicly accessible systems
- FCI inadvertently posted publicly
Identification and Authentication
CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.1: Identification - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(v) (3.5.1).
- Unique identifiers for users, processes and devices
- Shared or generic accounts
CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.2: Authentication - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vi) (3.5.2).
- Authentication mechanism verifying identities before access
- Authenticator management
- Identities not authenticated before granting FCI access
Media Protection
CMMC 2.0 Level 1 (Foundational) practice MP.L1-3.8.3: Media Disposal - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(vii) (3.8.3).
- Media sanitization/destruction procedure for FCI media before disposal or reuse
- Sanitization records
- FCI media disposed without sanitization
Physical Protection
CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.1: Limit Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(viii) (3.10.1).
- Physical access authorization limiting access to systems/equipment/operating environments
- Uncontrolled physical access to FCI systems
CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.3: Escort Visitors - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.3).
- Visitor escort and activity-monitoring procedure
- Unescorted visitors in FCI areas
CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.4: Physical Access Logs - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.4).
- Audit logs of physical access maintained
- No physical access logging
CMMC 2.0 Level 1 (Foundational) practice PE.L1-3.10.5: Manage Physical Access - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(ix) (3.10.5).
- Control and management of physical access devices (keys, badges, locks)
- Physical access devices not tracked/recovered
System and Communications Protection
CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.1: Boundary Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(x) (3.13.1).
- Boundary protection monitoring/controlling communications at external/key internal boundaries
- No boundary protection around FCI systems
CMMC 2.0 Level 1 (Foundational) practice SC.L1-3.13.5: Public-Access System Separation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xi) (3.13.5).
- Subnetworks for publicly accessible components separated from internal networks (DMZ)
- Public-facing components on the internal FCI network
System and Information Integrity
CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.1: Flaw Remediation - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xii) (3.14.1).
- Flaw identification/reporting/remediation (patch management) records
- Known flaws unpatched
CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.2: Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiii) (3.14.2).
- Malicious-code protection deployed at appropriate locations
- No anti-malware on FCI systems
CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.4: Update Malicious Code Protection - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xiv) (3.14.4).
- Anti-malware signature/engine update process
- Outdated malware definitions
CMMC 2.0 Level 1 (Foundational) practice SI.L1-3.14.5: System and File Scanning - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(xv) (3.14.5).
- Periodic system scans + real-time scanning of external-source files
- No periodic or real-time scanning
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CMMC 2.0 Level 1 framework page.