Skip to content
ControlVerdict
AC.L2-3.1.14CMMC Level 2Level 2

Remote Access Routing

Practice statement

Route remote access via managed access control points.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.14.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    managed access control points are identified and implemented; and

    1 example covers this

  2. [b]

    remote access is routed through managed network access control points.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.14Remote Access Routing
    Route remote access via managed access control points.
    • [a]

      managed access control points are identified and implemented; and
    • [b]

      remote access is routed through managed network access control points.

    All remote paths land on managed VPN or IdP — no direct RDP to enclave

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Remote Access Routing objectives.

    Control points. Internet users reach CUI only via (1) IdP SSO to SaaS or (2) full-tunnel VPN into the lab VRF. Edge firewall denies inbound RDP/SMB from the Internet to enclave subnets.

    Routing. VPN terminates on managed concentrators; split tunnel disabled for CUI routes. Admin remote work uses the same VPN then a jump host — not a public jump IP.

    Maintenance. Quarterly firewall rule review for accidental publish. Continuous monitoring for new listeners on enclave VLANs.

    Accepted gap. A facilities vendor needs a temporary camera VPN. It uses a separate non-CUI VRF with no route to the enclave.

    What the evidence looks like

    • Firewall rules denying inbound RDP/SMB to enclave
    • VPN topology showing managed termination points
    • Route table / VRF diagram for CUI vs facilities

    Environment

    Hybrid lab + SaaS; remote staff.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.