Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · SC

System & Communications Protection

How CUI is protected in motion and where the boundary sits — segmentation, cryptography, and denial-of-service protection.

16
requirements in this family
What it requires

The 16 requirements, in plain language.

3.13.1 Boundary Protection [CUI Data]

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems

3.13.2 Security Engineering

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems

3.13.3 Role Separation

Separate user functionality from system management functionality

3.13.4 Shared Resource Control

Prevent unauthorized and unintended information transfer via shared system resources

3.13.5 Public-Access System Separation [CUI Data]

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks

3.13.6 Network Communication by Exception

Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)

3.13.7 Split Tunneling

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling)

3.13.8 Data in Transit

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards

3.13.9 Connections Termination

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity

3.13.10 Key Management

Establish and manage cryptographic keys for cryptography employed in organizational systems

3.13.11 CUI Encryption

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI

3.13.12 Collaborative Device Control

Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device

3.13.13 Mobile Code

Control and monitor the use of mobile code

3.13.14 Voice over Internet Protocol

Control and monitor the use of Voice over Internet Protocol (VoIP) technologies

3.13.15 Communications Authenticity

Protect the authenticity of communications sessions

3.13.16 Data at Rest

Protect the confidentiality of CUI at rest

NIST SP 800-171 Rev 2 — Family SC. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.