AC Domain

Access Control CMMC Level 2

Limit system access to authorized users — 22 requirements covering 52 total SPRS points.

22 Requirements
52 SPRS Points at Risk
100% Complete Coverage

Access Control Domain Overview

The Access Control domain is the largest in CMMC Level 2 with 22 requirements. It governs who can access your systems, what they can do once inside, and how access is controlled, monitored, and terminated. Unauthorized access is the entry point for the vast majority of data breaches. Controlling who can access CUI systems — and what they can do within them — is foundational to protecting CUI. Without strong access controls, every other security domain is compromised.

All 22 Access Control Requirements

Every NIST SP 800-171 Rev 2 requirement in the AC family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
AC.L2-3.1.1Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).5Conditional
AC.L2-3.1.2Limit system access to the types of transactions and functions that authorized users are permitted to execute.5Conditional
AC.L2-3.1.3Control the flow of CUI in accordance with approved authorizations.1Yes
AC.L2-3.1.4Separate the duties of individuals to reduce the risk of malevolent activity without collusion.1Yes
AC.L2-3.1.5Employ the principle of least privilege, including for specific security functions and privileged accounts.3Yes
AC.L2-3.1.6Use non-privileged accounts or roles when accessing non-security functions.1Yes
AC.L2-3.1.7Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.1Yes
AC.L2-3.1.8Limit unsuccessful logon attempts.1Yes
AC.L2-3.1.9Provide privacy and security notices consistent with CUI rules.1Yes
AC.L2-3.1.10Use session lock with pattern-hiding displays after a period of inactivity.1Yes
AC.L2-3.1.11Terminate sessions after a defined condition.1Yes
AC.L2-3.1.12Monitor and control remote access sessions.5Conditional
AC.L2-3.1.13Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.5Conditional
AC.L2-3.1.14Route remote access via managed access control points.1Yes
AC.L2-3.1.15Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs.1Yes
AC.L2-3.1.16Authorize wireless access prior to allowing such connections.5Conditional
AC.L2-3.1.17Protect wireless access using authentication and encryption.5Conditional
AC.L2-3.1.18Control connection of mobile devices.5Conditional
AC.L2-3.1.19Encrypt CUI on mobile devices and mobile computing platforms.3Yes
AC.L2-3.1.20Verify and control/limit connections to external systems.1Yes
AC.L2-3.1.21Limit use of portable storage devices on external systems.1Yes
AC.L2-3.1.22Control CUI posted or processed on publicly accessible systems.1Yes

How 1TEN Covers This Domain

Role-Based Access Controls

The platform enforces role-based access on every module. Users see only what their role permits. Privilege escalation is logged and auditable, satisfying 3.1.1, 3.1.2, 3.1.5, and 3.1.7 with built-in evidence.

Session Management & Lockout

Configurable session timeout, automatic session lock with pattern-hiding display, and account lockout after failed logon attempts. Covers 3.1.8, 3.1.10, and 3.1.11 out of the box on the appliance.

Remote Access Documentation

Document your remote access architecture, VPN configurations, and managed access control points. The platform captures the evidence that 3.1.12, 3.1.13, and 3.1.14 require during assessment.

Mobile & Wireless Policy Enforcement

Track authorized wireless networks, mobile device encryption status, and portable storage policies. The Asset Inventory links each device to its access authorization, covering 3.1.16 through 3.1.21.

CUI Flow Documentation

Map where CUI enters, moves through, and exits your environment. The SSP Export generates CUI flow diagrams and boundary descriptions that satisfy 3.1.3 and 3.1.22.

Separation of Duties Matrix

Define and enforce duty separation across security-relevant functions. The platform prevents single users from holding conflicting roles and documents the separation for 3.1.4 compliance.

Common Tools for AC Compliance

These tools are commonly used by defense contractors to satisfy AC requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will request a list of privileged accounts and verify least privilege is enforced. They’ll test MFA for remote access, review VPN configurations, and check that session timeouts and logon attempt limits are configured. Expect requests for user access review records and a demonstration of account provisioning/deprovisioning procedures.

Why This Domain Matters
Access Control carries 54 SPRS points across 22 requirements. It is the single largest domain in CMMC Level 2. If you cannot demonstrate who has access, what they can do, and how remote connections are secured, you will not pass an assessment.

Related Domains

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo