Protect communications and system boundaries — 16 requirements covering 42 total SPRS points.
The System and Communications Protection domain has 16 requirements governing how communications containing CUI are protected, how system boundaries are enforced, and how cryptography is used to protect data in transit and at rest. Communications channels are a primary target for interception. Without encryption on remote access, email, and file transfers, CUI transmitted between systems is vulnerable to capture. SC controls also address network architecture — segmentation, boundary protection, and denial-of-service resilience.
Every NIST SP 800-171 Rev 2 requirement in the SC family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| SC.L2-3.13.1 | Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. | 5 | Conditional |
| SC.L2-3.13.2 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. | 5 | Conditional |
| SC.L2-3.13.3 | Separate user functionality from system management functionality. | 1 | Yes |
| SC.L2-3.13.4 | Prevent unauthorized and unintended information transfer via shared system resources. | 1 | Yes |
| SC.L2-3.13.5 | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | 5 | Conditional |
| SC.L2-3.13.6 | Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). | 5 | Conditional |
| SC.L2-3.13.7 | Prevent remote devices from simultaneously using remote connections with the system and communicating via some other pathway to resources in other networks (i.e., split tunneling). | 1 | Yes |
| SC.L2-3.13.8 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. | 3 | Yes |
| SC.L2-3.13.9 | Terminate network connections associated with communications sessions after a defined period of inactivity. | 1 | Yes |
| SC.L2-3.13.10 | Establish and manage cryptographic keys for cryptography employed in organizational systems. | 1 | Yes |
| SC.L2-3.13.11 | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. | 5 | No |
| SC.L2-3.13.12 | Prohibit remote activation of collaborative computing devices and provide indication of use to present users. | 1 | Yes |
| SC.L2-3.13.13 | Control and monitor the use of mobile code. | 1 | Yes |
| SC.L2-3.13.14 | Control and monitor the use of VoIP technologies. | 1 | Yes |
| SC.L2-3.13.15 | Protect the authenticity of communications sessions. | 5 | Conditional |
| SC.L2-3.13.16 | Protect CUI at rest. | 1 | No |
Continuously monitor and document communications at external and key internal boundaries, generating assessment-ready evidence for boundary protection controls including 3.13.1, 3.13.5, and 3.13.6.
Validate that publicly accessible components are properly segmented from internal networks and that deny-all firewall rules are correctly configured and documented for 3.13.5, 3.13.6, and 3.13.7.
Verify FIPS-validated cryptography is deployed for CUI in transit and at rest, track certificate lifecycles, and manage cryptographic key inventories across the environment for 3.13.8, 3.13.10, and 3.13.11.
Enforce session termination after inactivity, protect session authenticity, and document session management configurations for assessor review covering 3.13.9 and 3.13.15.
Track encryption status of all storage locations containing CUI, verify FIPS validation of encryption modules, and alert when protection gaps are detected for 3.13.16 and 3.13.11.
Document and validate system architecture against security engineering principles, including user-management separation, shared resource controls, and collaborative device policies for 3.13.2, 3.13.3, 3.13.4, and 3.13.12.
These tools are commonly used by defense contractors to satisfy SC requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.
Assessors will verify encryption is in use for all CUI in transit and look at network diagrams to verify boundary protections. They'll check that FIPS-validated cryptography is used where required, review firewall rules, and ask about network monitoring. Expect questions about how your network is segmented to isolate CUI systems.
System and communications protection is the largest CMMC domain for a reason. Your network boundaries define where CUI lives, how it moves, and who can intercept it. Get the boundary wrong and every other control is built on sand.
1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.
Request a Demo