Skip to content
ControlVerdict
AC.L2-3.1.16CMMC Level 2Level 2

Wireless Access Authorization

Practice statement

Authorize wireless access prior to allowing such connections.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.16.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    wireless access points are identified; and

    1 example covers this

  2. [b]

    wireless access is authorized prior to allowing such connections.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.16Wireless Access Authorization
    Authorize wireless access prior to allowing such connections.
    • [a]

      wireless access points are identified; and
    • [b]

      wireless access is authorized prior to allowing such connections.

    Corporate WLAN allow-list; guest SSID has no enclave route

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Wireless Access Authorization objectives.

    Authorize prior to connect. Corporate SSID requires device certificate or 802.1X user/machine auth via ISE. Unknown devices land on guest or quarantine with no enclave routes.

    Inventory. Authorized wireless clients are those with issued certs or approved BYOD profiles. Rogue AP detection enabled on the WLC.

    Maintenance. Quarterly purge of stale device certificates. After office moves, re-validate SSID → VLAN mapping.

    Accepted gap. Contractor day-pass Wi-Fi cannot use corp certs. Guests get internet-only VLAN; CUI laptops stay on corp SSID.

    What the evidence looks like

    • ISE/WLC policy showing auth required before corp VLAN
    • Guest VLAN route table (no enclave)
    • Certificate inventory / purge ticket

    Environment

    Office + lab Wi-Fi; Cisco ISE-class NAC optional.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.