Skip to content
ControlVerdict
AC.L2-3.1.20CMMC Level 2Level 2

External Connections [CUI Data]

Practice statement

Verify and control/limit connections to and use of external systems.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.20.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(6)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    connections to external systems are identified;

    1 example covers this

  2. [b]

    the use of external systems is identified;

    1 example covers this

  3. [c]

    connections to external systems are verified;

    1 example covers this

  4. [d]

    the use of external systems is verified;

    1 example covers this

  5. [e]

    connections to external systems are controlled/limited; and

    1 example covers this

  6. [f]

    the use of external systems is controlled/limited.

    No example covers this objective yet. Submit your own example.

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AC.L2-3.1.20External Connections [CUI Data]
    Verify and control/limit connections to and use of external systems.
    • [a]

      connections to external systems are identified;
    • [b]

      the use of external systems is identified;
    • [c]

      connections to external systems are verified;
    • [d]

      the use of external systems is verified;
    • [e]

      connections to external systems are controlled/limited; and

    External system connections via CASB allow-list and reviewed integrations

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Claims objectives [a]–[e] for verifying and limiting connections to external systems that handle CUI. Objective [f] (limit use of portable storage on external systems) is covered under the portable-storage practice example (AC.L2-3.1.21), not duplicated here.

    Inventory. Every external system that can receive CUI (partners, ESP tools, subcontractors) is listed with owner, data types, and connection method (API, sync, human upload).

    Control. IdP blocks unsanctioned OAuth apps. CASB/DLP blocks upload of labeled CUI to unsanctioned personal cloud. New integrations require security review before client secrets are issued.

    Maintenance. Quarterly integration inventory review. Alert on new OAuth grants to enclave users.

    Accepted gap. Email to authorized partner domains remains a human path; DLP + encryption mandatory, and partner domain list is contract-owned.

    What the evidence looks like

    • External system / integration inventory
    • IdP OAuth app restrictions
    • CASB/DLP policy for unsanctioned cloud
    • Sample approved integration security review

    Environment

    SaaS-heavy OSC; Microsoft Purview / CASB-class controls.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.