Skip to content
ControlVerdict
AC.L2-3.1.17CMMC Level 2Level 2

Wireless Access Protection

Practice statement

Protect wireless access using authentication and encryption.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.17.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    wireless access to the system is protected using authentication; and

    1 example covers this

  2. [b]

    wireless access to the system is protected using encryption.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.17Wireless Access Protection
    Protect wireless access using authentication and encryption.
    • [a]

      wireless access to the system is protected using authentication; and
    • [b]

      wireless access to the system is protected using encryption.

    WPA2/3-Enterprise with certs; no PSK on CUI-capable SSIDs

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Wireless Access Protection objectives.

    Authentication + encryption. Corp SSID uses WPA2/3-Enterprise with RADIUS. PSK SSIDs are forbidden for any VLAN that can reach CUI. Management frames protected where hardware supports it.

    Maintenance. Annual wireless security assessment; disable legacy protocols (WEP/TKIP) if reintroduced by defaults after upgrades.

    Accepted gap. IoT sensors use a PSK SSID on an air-gapped building VLAN with no route to CUI systems.

    What the evidence looks like

    • WLC SSID security settings export
    • RADIUS auth success logs sample
    • IoT PSK SSID isolation evidence

    Environment

    Same wireless plant as 3.1.16.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.