Guide

CMMC Compliance with Remote Employees and Offshore Teams (2026)

Last updated: June 1, 2026

The Short Answer Remote Employees and CUI Boundary Controls for Remote Access Offshore Teams: Hard Stops What Offshore Teams Can Do Personnel Screening Structuring Your Team FAQ

The Short Answer

Yes, you can achieve CMMC Level 2 certification with remote employees. The rules do not prohibit distributed workforces, and many certified organizations have remote staff. What the rules require is that remote access to CUI systems is controlled, encrypted, monitored, and authenticated with more than a password.

Offshore development teams are a different question. The answer is not no, but it has significant conditions. Whether offshore team members can have any access to systems within your CUI boundary depends heavily on the nature of the information involved and the export control status of that information. For most defense contractors handling Controlled Technical Information, the answer is that offshore access to CUI is prohibited under ITAR and EAR regardless of what CMMC itself requires.

The rest of this article breaks down exactly where the lines are, which NIST SP 800-171 controls govern remote and offshore work, and how to structure your team so that a C3PAO assessor sees a coherent, defensible approach.

Remote Employees and Your CUI Boundary

CMMC compliance is about protecting CUI within a defined boundary. That boundary follows the data. If your remote employees access CUI, the systems they use to do it are part of your CUI boundary, and those systems must implement the required controls.

There are three common configurations for remote employees accessing CUI, and each has different implications for your assessment scope.

Company-managed endpoint with VPN The remote employee uses a company-issued device and connects to on-premises or cloud systems via encrypted VPN. The endpoint device is in scope for your assessment. Your organization controls the device, enforces configuration baselines on it, and can install endpoint protection. This is the preferred configuration because the CUI boundary stays well-defined and auditable.
Personal device (BYOD) The remote employee uses their own computer. If that device accesses CUI in any form, the personal device is in scope for your assessment. You either must bring it into compliance (apply MDM, enforce configuration baselines, install required security tools) or implement technical controls that prevent CUI from ever reaching the device. Most organizations choose the prohibition approach and enforce it through VDI or browser-isolated access.
Virtual Desktop Infrastructure (VDI) The remote employee accesses a virtual machine that processes CUI. The CUI never leaves the server. The endpoint device sees only screen pixels. In this configuration, the endpoint device may fall outside the CUI boundary if you can demonstrate that no CUI data is transferred to or from it. VDI reduces remote access scope complexity and is commonly used by contractors with large remote workforces.

The device is only part of the scoping question. The physical location also matters. NIST SP 800-171 includes Physical and Environmental Protection requirements. If a remote employee accesses CUI from a home office, your SSP must address how physical access to that workspace is controlled and how CUI is protected from observation by unauthorized individuals. This does not mean C3PAOs inspect home offices, but it does mean your policies and procedures must acknowledge and address the physical environment where remote work occurs.

Controls Required for Remote Access to CUI

NIST SP 800-171 has specific requirements for remote access. These are not general best practices. They are assessed controls, and assessors specifically test whether remote access configurations implement them.

RequirementWhat It RequiresWhat Assessors Check
AC.L2-3.1.12
Control remote access sessions
Remote access to CUI systems must be controlled and monitored. Organizations must define which users are authorized for remote access, under what conditions, and with what restrictions.Remote access policy, list of authorized remote access users, VPN configuration, session timeout settings, monitoring evidence.
AC.L2-3.1.14
Route via managed access control points
Remote access must route through a controlled gateway, not directly from employee devices to CUI systems over the open internet. A properly configured VPN concentrator or similar managed access point is the standard implementation.Network diagram showing VPN architecture, firewall rules, confirmation that split tunneling forces CUI-bound traffic through the managed gateway.
IA.L2-3.5.3
Multi-factor authentication
MFA is required for all remote access to CUI systems, both for privileged and non-privileged accounts. A password alone does not satisfy this requirement under any configuration.Demonstration of MFA prompt on remote login, MFA enforcement policy in identity provider, confirmation that MFA cannot be bypassed.
SC.L2-3.13.8
Encrypt CUI in transit
CUI transmitted during remote access sessions must be encrypted. VPN with strong encryption satisfies this. Unencrypted RDP, plain HTTP, or weak cipher suites do not.VPN cipher configuration, TLS version enforcement, protocol configuration on remote desktop or application access services.
AU.L2-3.3.1 / 3.3.2
Audit logging
Remote access sessions must be logged. Logs must capture authentication events, session start and end, and actions taken during the session on CUI systems. Logs must be retained and protected from modification.Log evidence from VPN systems, SIEM integration, confirmation that remote access session activity is captured and reviewable.
The Practical Implication for Remote Teams
Every remote employee who accesses CUI must connect through company-controlled infrastructure, authenticate with MFA, operate over an encrypted session, and have their activity logged. This is achievable and routine for organizations using modern identity platforms and VPN solutions. The compliance burden is in documentation and configuration evidence, not in operational inconvenience for remote workers.

Offshore Teams: The Hard Stops

CMMC compliance does not explicitly prohibit hiring foreign nationals or using offshore teams. The framework focuses on where CUI is handled and what controls protect it, not on the citizenship or location of the people doing the work. That framing, however, obscures a more fundamental constraint that applies before CMMC is even relevant.

ITAR and EAR are export control laws that restrict the disclosure of defense-related technical data to foreign persons, including within the United States. Under these regulations, sharing controlled technical data with a foreign national can constitute an export requiring prior authorization from the State Department or Commerce Department.

Most CUI in the defense supply chain is also export-controlled. Controlled Technical Information, which accounts for the majority of CUI handled by defense contractors, is typically ITAR-controlled technical data. If your offshore developer has access to systems containing CTI, has access to source code incorporating protected technical approaches, or receives design documentation through any communication channel, the export control question is live and serious.

ITAR Applies to Foreign Nationals Inside the US Too
The term "deemed export" describes the disclosure of ITAR- or EAR-controlled technical data to a foreign national within the United States. Hiring a developer in your US office who is not a US citizen or permanent resident and giving them access to ITAR-controlled technical data may require an export license, just as sending that data overseas would. Physical location does not determine whether an export has occurred under these regulations.

The consequence is that for most defense contractors, offshore teams can be part of the organization but cannot touch the systems or data within the CUI boundary. The boundary is not just a cybersecurity concept. It is also an export control perimeter. Anything inside that boundary may only be accessible to authorized US persons unless the organization has obtained specific export licenses for the individuals involved.

This is not a CMMC-specific rule. It applies to your existing DFARS 252.204-7012 obligations, to your ITAR registration, and to your prime contract requirements. CMMC assessments do not conduct export control reviews, but the C3PAO will ask who has access to CUI systems. If offshore individuals are listed, the assessor will flag it. The more significant exposure, however, is the independent ITAR or EAR violation that may already exist.

What Offshore Teams Can Do

An offshore or distributed international development team is not categorically incompatible with CMMC compliance, provided the work structure keeps those team members entirely outside the CUI boundary. This requires architectural discipline and deliberate process design, but it is operationally achievable.

Non-CUI product developmentIf your offshore team works exclusively on commercial product lines, internal tooling, or other work that does not involve defense technical data, they are outside the CMMC scope entirely. Work that never touches CUI is simply out of scope for the assessment. Document this boundary explicitly in your SSP.
Isolated development environmentsOffshore developers can work in a completely separate network and repository environment with no access, direct or indirect, to the CUI boundary. The key is that the CUI environment and the non-CUI environment must be technically segregated, not just policy-segregated. Code, files, and communications must not cross the boundary without review and authorization.
Administrative and business functionsBilling, customer support, marketing, human resources, and other business functions that are not operationally connected to CUI systems are outside the scope of CMMC. Offshore staff in these roles do not trigger access control or export control concerns as long as no CUI flows through their work.
Code that contains no controlled technical informationSource code that does not incorporate controlled algorithms, restricted design approaches, or technical data from a DoD program may not be CUI even in a defense contractor context. Whether code is CUI depends on its content and the context in which it was developed. If your RP or legal counsel has confirmed specific code repositories are not CUI, offshore access to those repositories may be permissible.

The critical variable in all of these scenarios is clear boundary definition. Your SSP must explicitly identify which systems are in and out of scope, what separates them technically, and why offshore team members have no path to access in-scope systems. Assessors will test this. Vague statements that offshore developers "don't work on CUI projects" are not sufficient. The technical and procedural controls that enforce the separation must be documented and demonstrable.

Personnel Screening Requirements

NIST SP 800-171 includes two Personnel Security requirements under the PS domain. Both are simple in statement, but contractors with distributed and offshore teams frequently underinvest in them.

PS.L2-3.9.1
Screen individuals prior to access
Everyone who receives access to CUI systems must be screened before that access is granted. Screening standards are not defined prescriptively, but assessors expect to see documented criteria and evidence of completion. For US-based employees handling standard CUI, a background check is the common implementation. For more sensitive categories, or any situation involving foreign nationals with cleared access, screening requirements may be more extensive.
PS.L2-3.9.2
Protect CUI during personnel actions
This requirement governs what happens when someone who had CUI access leaves the organization or changes roles. Access must be revoked promptly. Any CUI in their possession must be returned or destroyed. Audit logs must be reviewed for anomalous activity in the period leading up to departure. For contractors with offshore staff or frequent turnover, this is a process discipline gap that surfaces regularly in assessments.

One practical implication for remote and offshore teams: your offboarding procedure must be just as rigorous for geographically distant employees as for in-office staff. Terminating a remote employee's VPN credentials, revoking their SSO access, disabling their accounts on all CUI systems, and logging the completion of those steps is a required and auditable process. Assessors will ask to see offboarding records and compare them against your user account lists to confirm disabled accounts match departed personnel.

Structuring Your Team for Assessment

The practical goal for any defense contractor with a distributed team is to reach assessment day with a clear, documented answer to one question: who has access to your CUI boundary, and what controls govern that access? The following structure makes that answer defensible.

Workforce SegmentCUI Access PositionWhat Your SSP Must Document
US-based employees with CUI accessIn scope. Subject to all 110 controls for user-facing access requirements.Unique accounts, MFA enrollment, remote access via VPN, training completion, background screening, access reviews.
US-based employees without CUI accessOut of scope if technical controls prevent CUI from reaching their systems.Access control policy confirming exclusion, technical enforcement method, no CUI repositories accessible from their accounts.
Remote US employees with CUI accessIn scope. Endpoint device in scope depending on access method.VPN configuration, MFA, endpoint management, physical environment policy, audit logging, remote access authorization records.
Offshore or foreign national employees without CUI accessOut of scope if isolation is technically enforced and documented.Network and system separation architecture, access control rules confirming no path to CUI systems, SSP boundary statement explicitly excluding offshore environment.
Offshore or foreign national employees with CUI accessNot permissible for most CUI without export authorization.If pursued: export license documentation, RP legal review of specific CUI categories, ITAR/EAR compliance program documentation. This configuration requires legal counsel before proceeding.
Contractors and vendors with system accessIn scope if they have access to CUI systems, regardless of employment type.Vendor agreements including security requirements, background screening records, access limited to minimum necessary, accounts disabled upon contract end.
The Boundary Statement Is the Document That Matters
Your System Security Plan's CUI boundary description is the anchor document for every access control and workforce-related finding in your assessment. It needs to explicitly state which personnel categories have access, which systems they access, how access is controlled, and why offshore or non-CUI personnel cannot reach in-scope systems. A vague boundary description forces the assessor to ask, and the answer almost always reveals gaps. Write it precisely, and update it every time your team structure changes.

For contractors using 1TEN, the Access Control and Personnel Security modules produce the SSP sections and user access records that document this structure. The platform tracks which accounts are active, which users have completed training, and when access was provisioned or revoked. Those records become the evidence package your C3PAO reviews when they examine your workforce controls.

Frequently Asked Questions

Can I get CMMC certification with remote employees?

Yes. Remote employees are not a barrier to CMMC certification. What matters is whether your remote workers access CUI, what systems they use to do it, and whether those systems implement the required controls. Remote access to CUI systems must use encrypted VPN connections with multi-factor authentication. Depending on how access is structured, the remote employee's endpoint device may be in scope for the assessment. Proper documentation of your remote access architecture in your SSP is essential.

Can offshore developers work on a CMMC-certified contract?

It depends entirely on whether those developers touch CUI. Offshore developers who never access CUI and work only on systems entirely outside your CUI boundary can be part of your organization without triggering compliance issues. However, if they have any access to systems within your CUI boundary, the analysis becomes complicated quickly. Most defense contractor CUI is also ITAR- or EAR-controlled, which means access by foreign nationals may constitute a deemed export requiring prior government authorization. This is a legal question your RP or legal counsel should evaluate before you make architectural decisions.

Does CMMC apply to foreign nationals working for a US defense contractor?

CMMC itself does not distinguish between US citizens and foreign nationals within your workforce. The framework is about protecting CUI on your systems, not about who your employees are. However, ITAR and EAR apply independently, and they do draw that distinction. Sharing ITAR-controlled technical data with a foreign national inside the United States is a deemed export under those regulations and may require a license. Since most defense contractor CUI is also ITAR technical data, this is a real constraint for foreign national employees who would otherwise need access to CUI systems.

What controls does NIST SP 800-171 require for remote access?

The core remote access controls are: AC.L2-3.1.12 (control and monitor remote access sessions), AC.L2-3.1.14 (route remote access through managed access control points), IA.L2-3.5.3 (multi-factor authentication for remote access), SC.L2-3.13.8 (encrypt CUI in transit), and AU.L2-3.3.1 (audit log remote access activity). These are assessed requirements with evidence expectations. A VPN, MFA, and logging are the minimum technical implementations for most environments.

Are remote employee home offices in scope for a CMMC assessment?

Potentially, but in a limited way. C3PAO assessors do not physically inspect home offices. However, your SSP must address how Physical and Environmental Protection requirements are met in remote work locations. This means your policies need to cover how CUI is protected from unauthorized physical access when accessed from a home environment. The endpoint device used at that location is in scope for assessment depending on access configuration. If you use VDI so that CUI never leaves your servers, the physical location issue is substantially simplified.

Can I use BYOD devices for remote access to CUI systems?

NIST SP 800-171 does not prohibit BYOD, but it does require that personal devices accessing CUI comply with all applicable controls if they are in scope. A personal laptop that receives, displays, or stores CUI is in scope for your assessment. You either must manage that device to the same standard as a company-issued device, or you must implement technical controls that prevent CUI from reaching it. VDI is the most common approach for organizations that want to allow BYOD without bringing personal devices into their CUI boundary. Your SSP must explicitly address how personal device access is handled.

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo