Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · AC

Access Control

Who and what can reach CUI, and under which conditions — accounts, privileges, sessions, remote and wireless access. The largest family.

22
requirements in this family
What it requires

The 22 requirements, in plain language.

3.1.1 Authorized Access Control [CUI Data]

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems)

3.1.2 Transaction & Function Control

Limit system access to the types of transactions and functions that authorized users are permitted to execute

3.1.3 Control CUI Flow

Control the flow of CUI in accordance with approved authorizations

3.1.4 Separation of Duties

Separate the duties of individuals to reduce the risk of malevolent activity without collusion

3.1.5 Least Privilege

Employ the principle of least privilege, including for specific security functions and privileged accounts

3.1.6 Non-Privileged Account Use

Use non-privileged accounts or roles when accessing nonsecurity functions

3.1.7 Privileged Functions

Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs

3.1.8 Unsuccessful Logon Attempts

Limit unsuccessful logon attempts

3.1.9 Privacy & Security Notices

Provide privacy and security notices consistent with applicable CUI rules

3.1.10 Session Lock

Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity

3.1.11 Session Termination

Terminate (automatically) a user session after a defined condition

3.1.12 Control Remote Access

Monitor and control remote access sessions

3.1.13 Remote Access Confidentiality

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions

3.1.14 Remote Access Routing

Route remote access via managed access control points

3.1.15 Privileged Remote Access

Authorize remote execution of privileged commands and remote access to security-relevant information

3.1.16 Wireless Access Authorization

Authorize wireless access prior to allowing such connections

3.1.17 Wireless Access Protection

Protect wireless access using authentication and encryption

3.1.18 Mobile Device Connection

Control connection of mobile devices

3.1.19 Encrypt CUI on Mobile

Encrypt CUI on mobile devices and mobile computing platforms

3.1.20 External Connections [CUI Data]

Verify and control/limit connections to and use of external systems

3.1.21 Portable Storage Use

Limit use of portable storage devices on external systems

3.1.22 Control Public Information [CUI Data]

Control CUI posted or processed on publicly accessible systems

NIST SP 800-171 Rev 2 — Family AC. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.