SC Domain

System & Communications Protection CMMC Level 2

Protect communications and system boundaries — 16 requirements covering 42 total SPRS points.

16 Requirements
42 SPRS Points at Risk
100% Complete Coverage

System & Communications Protection Domain Overview

The System and Communications Protection domain has 16 requirements governing how communications containing CUI are protected, how system boundaries are enforced, and how cryptography is used to protect data in transit and at rest. Communications channels are a primary target for interception. Without encryption on remote access, email, and file transfers, CUI transmitted between systems is vulnerable to capture. SC controls also address network architecture — segmentation, boundary protection, and denial-of-service resilience.

All 16 System & Communications Protection Requirements

Every NIST SP 800-171 Rev 2 requirement in the SC family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
SC.L2-3.13.1Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.5Conditional
SC.L2-3.13.2Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.5Conditional
SC.L2-3.13.3Separate user functionality from system management functionality.1Yes
SC.L2-3.13.4Prevent unauthorized and unintended information transfer via shared system resources.1Yes
SC.L2-3.13.5Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.5Conditional
SC.L2-3.13.6Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).5Conditional
SC.L2-3.13.7Prevent remote devices from simultaneously using remote connections with the system and communicating via some other pathway to resources in other networks (i.e., split tunneling).1Yes
SC.L2-3.13.8Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.3Yes
SC.L2-3.13.9Terminate network connections associated with communications sessions after a defined period of inactivity.1Yes
SC.L2-3.13.10Establish and manage cryptographic keys for cryptography employed in organizational systems.1Yes
SC.L2-3.13.11Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.5No
SC.L2-3.13.12Prohibit remote activation of collaborative computing devices and provide indication of use to present users.1Yes
SC.L2-3.13.13Control and monitor the use of mobile code.1Yes
SC.L2-3.13.14Control and monitor the use of VoIP technologies.1Yes
SC.L2-3.13.15Protect the authenticity of communications sessions.5Conditional
SC.L2-3.13.16Protect CUI at rest.1No

How 1TEN Covers This Domain

Boundary Protection Monitor

Continuously monitor and document communications at external and key internal boundaries, generating assessment-ready evidence for boundary protection controls including 3.13.1, 3.13.5, and 3.13.6.

Network Segmentation Validator

Validate that publicly accessible components are properly segmented from internal networks and that deny-all firewall rules are correctly configured and documented for 3.13.5, 3.13.6, and 3.13.7.

Cryptographic Compliance Checker

Verify FIPS-validated cryptography is deployed for CUI in transit and at rest, track certificate lifecycles, and manage cryptographic key inventories across the environment for 3.13.8, 3.13.10, and 3.13.11.

Session Management Controls

Enforce session termination after inactivity, protect session authenticity, and document session management configurations for assessor review covering 3.13.9 and 3.13.15.

Data-at-Rest Encryption Tracker

Track encryption status of all storage locations containing CUI, verify FIPS validation of encryption modules, and alert when protection gaps are detected for 3.13.16 and 3.13.11.

Architecture Review Automation

Document and validate system architecture against security engineering principles, including user-management separation, shared resource controls, and collaborative device policies for 3.13.2, 3.13.3, 3.13.4, and 3.13.12.

Common Tools for SC Compliance

These tools are commonly used by defense contractors to satisfy SC requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will verify encryption is in use for all CUI in transit and look at network diagrams to verify boundary protections. They'll check that FIPS-validated cryptography is used where required, review firewall rules, and ask about network monitoring. Expect questions about how your network is segmented to isolate CUI systems.

Why This Domain Matters
System and communications protection is the largest CMMC domain for a reason. Your network boundaries define where CUI lives, how it moves, and who can intercept it. Get the boundary wrong and every other control is built on sand.

Related Domains

Miss nothing.

1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.

Request a Demo