Limit system access to authorized users — 22 requirements covering 52 total SPRS points.
The Access Control domain is the largest in CMMC Level 2 with 22 requirements. It governs who can access your systems, what they can do once inside, and how access is controlled, monitored, and terminated. Unauthorized access is the entry point for the vast majority of data breaches. Controlling who can access CUI systems — and what they can do within them — is foundational to protecting CUI. Without strong access controls, every other security domain is compromised.
Every NIST SP 800-171 Rev 2 requirement in the AC family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| AC.L2-3.1.1 | Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). | 5 | Conditional |
| AC.L2-3.1.2 | Limit system access to the types of transactions and functions that authorized users are permitted to execute. | 5 | Conditional |
| AC.L2-3.1.3 | Control the flow of CUI in accordance with approved authorizations. | 1 | Yes |
| AC.L2-3.1.4 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion. | 1 | Yes |
| AC.L2-3.1.5 | Employ the principle of least privilege, including for specific security functions and privileged accounts. | 3 | Yes |
| AC.L2-3.1.6 | Use non-privileged accounts or roles when accessing non-security functions. | 1 | Yes |
| AC.L2-3.1.7 | Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. | 1 | Yes |
| AC.L2-3.1.8 | Limit unsuccessful logon attempts. | 1 | Yes |
| AC.L2-3.1.9 | Provide privacy and security notices consistent with CUI rules. | 1 | Yes |
| AC.L2-3.1.10 | Use session lock with pattern-hiding displays after a period of inactivity. | 1 | Yes |
| AC.L2-3.1.11 | Terminate sessions after a defined condition. | 1 | Yes |
| AC.L2-3.1.12 | Monitor and control remote access sessions. | 5 | Conditional |
| AC.L2-3.1.13 | Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. | 5 | Conditional |
| AC.L2-3.1.14 | Route remote access via managed access control points. | 1 | Yes |
| AC.L2-3.1.15 | Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs. | 1 | Yes |
| AC.L2-3.1.16 | Authorize wireless access prior to allowing such connections. | 5 | Conditional |
| AC.L2-3.1.17 | Protect wireless access using authentication and encryption. | 5 | Conditional |
| AC.L2-3.1.18 | Control connection of mobile devices. | 5 | Conditional |
| AC.L2-3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms. | 3 | Yes |
| AC.L2-3.1.20 | Verify and control/limit connections to external systems. | 1 | Yes |
| AC.L2-3.1.21 | Limit use of portable storage devices on external systems. | 1 | Yes |
| AC.L2-3.1.22 | Control CUI posted or processed on publicly accessible systems. | 1 | Yes |
The platform enforces role-based access on every module. Users see only what their role permits. Privilege escalation is logged and auditable, satisfying 3.1.1, 3.1.2, 3.1.5, and 3.1.7 with built-in evidence.
Configurable session timeout, automatic session lock with pattern-hiding display, and account lockout after failed logon attempts. Covers 3.1.8, 3.1.10, and 3.1.11 out of the box on the appliance.
Document your remote access architecture, VPN configurations, and managed access control points. The platform captures the evidence that 3.1.12, 3.1.13, and 3.1.14 require during assessment.
Track authorized wireless networks, mobile device encryption status, and portable storage policies. The Asset Inventory links each device to its access authorization, covering 3.1.16 through 3.1.21.
Map where CUI enters, moves through, and exits your environment. The SSP Export generates CUI flow diagrams and boundary descriptions that satisfy 3.1.3 and 3.1.22.
Define and enforce duty separation across security-relevant functions. The platform prevents single users from holding conflicting roles and documents the separation for 3.1.4 compliance.
These tools are commonly used by defense contractors to satisfy AC requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will request a list of privileged accounts and verify least privilege is enforced. They’ll test MFA for remote access, review VPN configurations, and check that session timeouts and logon attempt limits are configured. Expect requests for user access review records and a demonstration of account provisioning/deprovisioning procedures.
Access Control carries 54 SPRS points across 22 requirements. It is the single largest domain in CMMC Level 2. If you cannot demonstrate who has access, what they can do, and how remote connections are secured, you will not pass an assessment.
1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.
Request a Demo