Uniqcli

CMMC control families

CMMC Access Control (3.1 AC): 22 requirements and what sits behind them

Access control is the largest family in NIST SP 800-171 Rev 2 — 22 of the 110 Level 2 requirements. The account model and the policy stay yours. What a supplier puts behind them is the network that holds a CUI enclave apart, the remote-access and segmentation licensing that rides on it, and the configuration work that makes both live.

Family
3.1 — Access Control
Requirements
22 of the 110 Level 2 requirements
Level 1
In scope — basic requirements from this family
Boundary
The capability behind the control — never a certification we hold
Overview

The family that decides who reaches CUI, from where, and over which wire

Access control is the largest family in NIST SP 800-171 Rev 2: 22 of the 110 requirements a Level 2 assessment looks at. It governs who holds an account, what that account may do, which flows of CUI are permitted between systems, and how remote access, wireless and portable storage are handled at the edge of your boundary. The written policy and the account model are yours, and no purchase produces either. What a supplier can put behind them runs the whole way down: the physical separation the design assumes — managed switches that keep a CUI enclave apart, firewalls at the zone edges, and, where one operator works across two separated networks, a NIAP-approved secure KVM — the remote-access and segmentation licensing that turns those boxes into an enforced boundary, and the imaging, staging and configuration work that puts them in service against your build sheet. That is the capability behind the control, never a certification we hold.

Levels

What each level asks of this family

Access control is one of the six families Level 1 touches. Level 1 covers Federal Contract Information and carries 15 requirements drawn from FAR 52.204-21; the basic ones in this family limit system access to authorized users and to the transactions and functions those users are permitted to execute, and control what gets published to publicly accessible systems.

Level 2 is where the full 22 land. They run from the basics at 3.1.1 and 3.1.2 through information-flow control at 3.1.3, separation of duties at 3.1.4 and least privilege at 3.1.5, and out to the edges most contractors under-plan: monitoring and controlling remote access sessions (3.1.12), protecting the confidentiality of those sessions with cryptography (3.1.13), authorizing and protecting wireless access (3.1.16 and 3.1.17), encrypting CUI on mobile devices (3.1.19), and controlling connections to — and portable storage on — external systems (3.1.20 and 3.1.21).

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Separating the enclave (3.1.3)

Information-flow control is the requirement most enclave designs answer with VLANs and separate switching. Managed switches are one of the deepest genuinely stocked lines we carry — Netgear, Ubiquiti, Black Box and Eaton's industrial DIN range move regularly. Allied Telesis, D-Link and TRENDnet are priced across hundreds of rows but thin on the shelf, so those are quote-and-source rather than available now.

Zone edges and remote access (3.1.12, 3.1.13)

Remote access sessions have to be monitored, controlled and cryptographically protected, and the boundary between zones is where that gets enforced. SonicWall and WatchGuard appliances are genuinely stocked. Palo Alto Networks, Sophos, Check Point and Barracuda are priced and quotable but not stocked — treat those as lead-time lines, and expect subscriptions to be quoted against your renewal date.

One operator, two networks

Where a single desk works across separated networks, a NIAP Peripheral Sharing Device secure KVM is the ordinary answer, and several rows we carry state PSD PP v4.0 compliance in the title — some with a CAC reader in the console. ATEN, Vertiv's Cybex line, Black Box, StarTech.com, Belkin and IOGEAR all appear; availability varies model by model, so the quote confirms it before you commit.

Wireless access (3.1.16, 3.1.17)

Wireless has to be authorized before it is allowed to connect, then protected by authentication and encryption. Access points are quoted with the controller, licensing and mounting your design calls for. Ubiquiti is the hub line with the most depth we have verified here; much of the rest of the category is quote-and-source, and the quote says which is which.

Remote-access and segmentation licensing

The appliance is half the answer; the subscription term is the other half. Sophos Zero Trust Network Access, Citrix NetScaler and its SD-WAN line, and the SonicWall, WatchGuard, Check Point and Barracuda subscription families are all priced in our licensing catalog and quoted per seat or per appliance against your renewal date. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. We do not carry a privileged-access-management or network-access-control product line, and we will say so rather than relabel something adjacent.

Configured before it ships

Switching and edge gear that arrives factory-default is a project, not a delivery. Through our OEM-integration lane the same order can carry rack integration, imaging, firmware baselining, kitting and asset tagging, so each site receives a labeled, configured kit rather than a pallet of parts. Scoped per order alongside the hardware it applies to.

Limits

What stays yours to run

Least privilege (3.1.5), separation of duties (3.1.4), account management and session lock are decisions and administration. A switch does not enforce least privilege, a firewall does not decide who is authorized, and a ZTNA subscription does not write your access model. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Access control questions

What are the CMMC access control requirements at Level 2?

Twenty-two of them — 3.1.1 through 3.1.22 in NIST SP 800-171 Rev 2, the largest single family in the standard. They cover authorized access and permitted transactions, CUI flow control, separation of duties and least privilege, remote access, wireless, mobile-device encryption, external systems and portable storage, and publicly accessible content. Level 2 assesses all 110 requirements against 320 objectives.

Does CMMC Level 1 include access control?

Yes. Access control is one of the six families Level 1 touches, alongside identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. Level 1 carries 15 requirements in total, drawn from FAR 52.204-21 — not a per-family subset you can shop for. The other eight families appear only at Level 2 and above.

How many access control requirements are in NIST SP 800-171?

Twenty-two, numbered 3.1.1 to 3.1.22 in Rev 2 — the revision still pinned for DoD work by Class Deviation 2024-O0013. That is one fifth of the 110 requirements a Level 2 assessment covers, which is why access control tends to consume the largest share of an SSP.

Do I need a secure KVM switch for a CUI workstation?

No requirement names one. A secure KVM is what many programs use when one operator has to work across two separated networks from a single desk without introducing a path between them — NIAP Peripheral Sharing Device protection profile compliance is the fact worth asking about, and several rows we carry state PSD PP v4.0 in the title. Whether your design needs one is a scoping decision for your program, not a purchase we can make for you.

Get a CMMC estimate — CMMC Access Control (3.1 AC)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Access Control (3.1 AC)

Talk to us about the access-control build

Send the enclave design, the SSP section or the bill of materials you are buying against. A Uniqcli specialist replies with an estimate covering the hardware, the licensing terms and any staging or configuration work the rollout needs — TAA and §889 screening performed before it goes out, availability stated honestly line by line, and nothing claimed about certification that a purchase cannot deliver.