Subcontractor CMMC Tracker

Access Control (AC): the 22 CMMC Level 2 requirements a subcontractor self-assesses

The Access Control family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

22
CMMC L2 AC.L2-3.1.1Authorized Access Control 5 points in the score

Restrict system access so only identified, authorized users, the processes running on their behalf, and approved devices including other connected systems can connect.

What an assessor asks to see: Account inventory listing authorized users, service/process accounts and approved devices; Account provisioning and approval records showing authorization before access; System configuration showing device and system-to-system connection allow lists; Periodic account recertification results
Where subcontractors usually fall short: Service and machine accounts never authorized or reviewed; Device-level access unrestricted while user access is controlled; Stale accounts retained after staff depart
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.10Session Lock 1 point in the score

Lock the user session after a defined period of inactivity and conceal previously displayed content behind a pattern hiding display until the user reauthenticates.

What an assessor asks to see: Configured inactivity timeout and session lock settings; Evidence the lock hides screen content, for example screensaver policy; Deployment coverage across workstations and servers
Where subcontractors usually fall short: Timeout configured but pattern hiding not enforced; Users permitted to disable the lock locally; Servers and shared terminals excluded
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.11Session Termination 1 point in the score

Automatically end a user session once a defined condition, such as an inactivity period or maximum session duration, is met.

What an assessor asks to see: Defined session termination conditions in policy; System and application configuration implementing automatic termination; Evidence of sessions terminated in logs
Where subcontractors usually fall short: Session lock mistaken for session termination; Conditions undefined so nothing terminates; Application sessions persist after operating system termination
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.12Control Remote Access 5 points in the score

Monitor and control remote access sessions so each remote connection is authorized, visible to the organization and subject to enforcement.

What an assessor asks to see: Remote access policy defining permitted methods and approval; VPN or remote gateway configuration and connection logs; Records of remote session monitoring and review
Where subcontractors usually fall short: Remote access permitted through unmanaged tools; Connections logged but never reviewed; Third party remote support paths outside the control
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.13Remote Access Confidentiality 5 points in the score

Apply cryptographic protection to remote access sessions so session confidentiality is preserved in transit.

What an assessor asks to see: Remote access encryption configuration showing protocol and cipher settings; Evidence that weak or plaintext remote protocols are disabled; Certificate or key management records for the remote access service
Where subcontractors usually fall short: Legacy plaintext protocols still enabled as fallback; Encryption terminated at an intermediary leaving segments in clear; Cipher suites unreviewed and outdated
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.14Remote Access Routing 1 point in the score

Force remote access traffic through a limited set of managed access control points rather than allowing arbitrary entry paths into the network.

What an assessor asks to see: Network architecture identifying the managed remote access points; Firewall rules restricting remote entry to those points; Evidence that alternative ingress paths are blocked
Where subcontractors usually fall short: Multiple undocumented remote entry points; Vendor appliances providing side channel access; Split of remote traffic across unmanaged cloud services
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.15Privileged Remote Access 1 point in the score

Require explicit authorization before privileged commands may be executed remotely or security relevant information accessed remotely.

What an assessor asks to see: Documented authorization for remote privileged operations; Configuration restricting remote privileged command execution; Logs of remote privileged sessions and the approvals behind them
Where subcontractors usually fall short: Remote administration allowed to anyone holding admin rights; Authorization implied by role rather than explicitly granted; No record tying remote privileged activity to an approval
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.16Wireless Access Authorization 5 points in the score

Authorize each wireless connection before it is permitted to attach to the system.

What an assessor asks to see: Wireless access authorization records and approved device list; Wireless network configuration showing authorization enforcement; Rogue access point detection results
Where subcontractors usually fall short: Wireless access granted by shared passphrase with no authorization step; Guest wireless bridged to internal networks; Unauthorized access points undetected
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.17Wireless Access Protection 5 points in the score

Protect wireless connections using authentication and encryption so wireless traffic and access are not open to nearby parties.

What an assessor asks to see: Wireless security configuration showing authentication method and encryption; Evidence that deprecated wireless protocols are disabled; Wireless credential or certificate management records
Where subcontractors usually fall short: Pre shared keys shared widely and never rotated; Legacy encryption retained for older devices; Authentication not tied to individual identity
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.18Mobile Device Connection 5 points in the score

Control which mobile devices may connect to organizational systems, and manage those connections.

What an assessor asks to see: Mobile device policy and approved device inventory; Mobile device management enrolment and compliance records; Configuration restricting connection to managed devices
Where subcontractors usually fall short: Personal devices connect without enrolment; Inventory maintained but connection not technically restricted; No removal process when a device is lost or retired
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.19Encrypt CUI on Mobile 3 points in the score

Encrypt CUI held on mobile devices and mobile computing platforms so the data stays protected if a device is lost or stolen.

What an assessor asks to see: Device encryption configuration and compliance reporting; Evidence of encryption status per enrolled device; Policy identifying which mobile platforms may hold CUI
Where subcontractors usually fall short: Encryption assumed by default without verification; Removable storage in mobile devices left unencrypted; Devices holding CUI outside the managed estate
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.2Transaction & Function Control 5 points in the score

Confine each authorized user to the specific transactions and functions their role permits, so privileges bound what can be executed and not merely whether access is granted.

What an assessor asks to see: Role definitions mapping roles to permitted transactions and functions; Application and system permission matrices as configured; Approval records for role assignment per user; Evidence of enforcement testing on a restricted role
Where subcontractors usually fall short: Access granted at system level with no function-level restriction; Roles defined on paper but not enforced in the application; Broad default roles assigned for convenience
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.20External Connections 1 point in the score

Verify, then control or limit, connections to and use of external systems that are outside organizational control.

What an assessor asks to see: Inventory of approved external systems and connection terms; Agreements or terms governing external system use; Technical controls limiting external system connections
Where subcontractors usually fall short: External cloud services used without review; Connections permitted with no verification of the external party; No limit on what CUI may be processed externally
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.21Portable Storage Use 1 point in the score

Restrict how organizational portable storage devices may be used when connected to systems outside organizational control.

What an assessor asks to see: Policy stating limits on portable storage use on external systems; Technical restriction or endpoint control evidence; Records of approved exceptions
Where subcontractors usually fall short: Policy silent on external system use specifically; Restriction applied internally but not to devices taken off site; No mechanism to detect violation
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.22Control Public Information 1 point in the score

Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.

What an assessor asks to see: Review and approval process for content published publicly; Designated reviewer authorizations and review records; Evidence of periodic scanning of public sites for CUI
Where subcontractors usually fall short: Publication approval informal or undocumented; No periodic check of already published content; Public facing systems not identified as in scope
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.3Control CUI Flow 1 point in the score

Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.

What an assessor asks to see: Documented CUI flow authorizations and approved flow paths; Firewall, proxy, DLP or gateway rules enforcing those flows; Data flow diagrams identifying CUI sources, stores and destinations; Records of blocked or exception-approved transfers
Where subcontractors usually fall short: CUI flows documented but not technically enforced; Egress to cloud and email paths unmonitored for CUI; No defined authorization for flows to external partners
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.4Separation of Duties 1 point in the score

Divide security relevant duties among different individuals so no single person can both carry out and conceal a harmful action without collusion.

What an assessor asks to see: Documented separation of duties matrix for security relevant tasks; Access assignments demonstrating conflicting duties are held by different people; Records of conflict analysis and any approved compensating controls
Where subcontractors usually fall short: Single administrator holds all privileged roles; Separation defined but not tested against actual entitlements; Small team treated as automatic exemption with no compensating control
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.5Least Privilege 3 points in the score

Grant users and processes only the privileges their assigned tasks require, applying this specifically to security functions and to privileged accounts.

What an assessor asks to see: Privileged account inventory with documented business justification; Entitlement review results showing removal of excess rights; Configuration showing security functions restricted to designated roles
Where subcontractors usually fall short: Standing administrative rights granted broadly; Privilege reviews performed but findings not actioned; Security functions accessible to general administrators
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.6Non-Privileged Account Use 1 point in the score

Require staff holding privileged accounts to use a non privileged account or role when performing work that does not need elevated rights.

What an assessor asks to see: Policy requiring separate privileged and non privileged accounts; Evidence that administrators hold distinct day-to-day accounts; Logs showing routine activity performed under non privileged accounts
Where subcontractors usually fall short: Administrators use privileged accounts for email and browsing; Dual accounts issued but daily use not enforced or monitored; No detection of privileged account use for nonsecurity tasks
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.7Privileged Functions 1 point in the score

Block non privileged users from executing privileged functions, and capture every execution of such functions in the audit log.

What an assessor asks to see: Configuration preventing privileged function execution by standard users; Audit log samples showing captured privileged function execution; Test results of an attempted privileged action by a non privileged account
Where subcontractors usually fall short: Privileged functions blocked but execution not logged; Logging enabled without covering privileged function use; Local administrator rights on endpoints bypass the restriction
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.8Unsuccessful Logon Attempts 1 point in the score

Cap the number of consecutive failed logon attempts allowed and take a defined action, such as account lockout, once that limit is reached.

What an assessor asks to see: Configured lockout threshold, duration and reset settings; Policy stating the failed attempt limit and resulting action; Evidence of enforcement across all authentication paths including remote
Where subcontractors usually fall short: Limit set in policy but not configured on all systems; Remote and application logons exempt from lockout; Lockout thresholds so high they never trigger
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AC.L2-3.1.9Privacy & Security Notices 1 point in the score

Display privacy and security notices to users at logon that reflect the CUI rules applicable to the system.

What an assessor asks to see: Approved notice or banner text consistent with applicable CUI rules; Screenshots showing the notice presented at logon; Coverage list of systems where the banner is deployed
Where subcontractors usually fall short: Banner present on some systems only; Generic notice not reflecting CUI requirements; Notice bypassed on remote or application logon paths
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)