Access Control (AC) — 3.1.3

FutureFeed CMMC Education Series · Access Control

Access Control (AC): 3.1.3

The short version

If you’re responsible for CMMC compliance, here’s what this requirement comes down to. You need to:

  • Have the business decide where Controlled Unclassified Information (CUI) is allowed to move: between people, departments, systems, suppliers, and service providers
  • Have IT enforce those decisions with your network tools, so approved routes work and everything else is blocked
  • Stop CUI from leaving on unapproved routes, like personal email or consumer cloud storage
  • Keep dated records of the approved flows and proof they’re enforced

If you already have those things and can prove them, you’re well on your way. Now let’s talk about what each one actually looks like.

Access Control (AC): CMMC requirement 3.1.3, control the flow of CUI in accordance with approved authorizations

Applies to: Organizations pursuing CMMC Level 2 or 3 · Anyone who stores, processes, or transmits CUI · Business and data owners, IT and network administrators, and whoever approves where CUI is allowed to move.

Last reviewed: September 2026. Covers NIST SP 800-171 Rev 2 Access Control (3.1.3), which sits at CMMC Level 2.

01

In plain English

IT doesn’t decide where CUI is allowed to travel. The business does, and it decides first. Before a firewall blocks anything or an email gateway allows anything, someone has to answer questions like these:

  • Should engineering be able to send CUI to manufacturing?
  • Can purchasing share CUI with a supplier?
  • Can employees work with CUI from home?
  • Can an outside IT provider (an MSP) reach CUI?
  • Is a tool like Dropbox allowed? Is a USB drive?

Only after the business answers those questions can IT configure the technology to enforce them. This control is about making those decisions on purpose, and then making the network hold the line.

The business decides where CUI is allowed to go. IT makes sure it can’t go anywhere else. That’s the control.

Example

Before IT configured anything, engineering, operations, and leadership decided that CUI could move between the engineering system, the document repository, and the approved backup service, and nowhere else. Once those approved paths were written down, IT set up the email gateway and firewall to enforce them. Later, when an engineer tried to email a drawing to a personal account, the message was blocked, because that path had never been approved. The business made the decision; the technology simply held the line.

02

What you need to have in place

To be compliant, each of those boxes needs to be real and repeatable:

  • A documented business decision identifying where CUI is allowed to move: between people, departments, systems, suppliers, partners, and service providers.
  • IT enforcement of those decisions in your boundary devices (firewall, gateway, web proxy, VPN or other encrypted tunnels) that permit the approved paths and block the rest.
  • Guardrails on everyday exits, so CUI can’t slip out through personal email, consumer cloud storage, or removable media where those aren’t allowed.
  • Records of the approved flows, plus configuration that shows they’re actually enforced.

Name the routes CUI is allowed to take, then make your network turn away everything else. The decision belongs to the business; the enforcement belongs to IT.

The Road to CMMC

A new stop every Tuesday and Thursday.

Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.

03

What you need to prove it

Think in three buckets. An assessor will want all three, so it helps to build them at the same time.

People

  • Business and data owners who decide where CUI needs to flow (engineering, operations, program management, purchasing and contracts)
  • Security and compliance leaders who review those decisions
  • IT and network administrators who configure the systems to enforce them

Tools

  • Firewalls, gateways, a web proxy, and email security
  • VPN or encryption for approved transfers
  • Somewhere configurations and logs are kept

Documents

  • A written information flow policy naming the approved sources and destinations
  • Firewall, proxy, or gateway rule exports showing the flows are enforced
  • Records that the decisions and rules are reviewed, with dates
  • A note in your System Security Plan (SSP) describing your flows and how they’re enforced

You don’t need exotic tooling. You need a clear business decision about the approved paths, and proof your network enforces it.

04

When should I work on this

Work on this after you’ve identified where CUI lives and how your business actually uses it. Until you understand how information supports engineering, purchasing, manufacturing, suppliers, and service providers, you can’t decide where it should be allowed to flow. Those business decisions come first; the technology comes second. It does overlap with System and Communications Protection, the family where the enforcement lives, but don’t let that turn this into a purely networking task. The hard part is the decision, not the firewall rule.

05

Common challenges

1

IT is told to “lock down CUI” before the business has decided where it should go.

Why it happens: It gets handed to IT as a technical task, so the firewall rules end up guessing at flows no one actually defined.

Recommendation: Have the business and data owners define the approved flows first, then let IT enforce them.

2

CUI leaks out through everyday tools.

Why it happens: Personal email, consumer cloud storage, and messaging apps are easy, familiar, and usually wide open.

Recommendation: Use your email and web controls to stop CUI from leaving on routes you never approved.

3

The rule exists on paper but nothing enforces it.

Why it happens: A policy says “don’t send CUI externally,” but no device actually blocks it and there’s no evidence either way.

Recommendation: Enforce the approved flows in your boundary devices, and keep the configuration as proof it’s working.

06

What good looks like

A compliant contractor can usually answer yes to all of these:

  • Has the business, not just IT, decided where CUI is allowed to move?
  • Do your network tools actually block unapproved paths, not just a policy on paper?
  • Is CUI kept from leaving through personal email or consumer cloud storage?
  • Can you show the configuration that enforces those decisions?

If any answer is no, that’s your next place to start.

Watch out

Flow control is about where the information can go, not who can see it. It’s easy to confuse with 3.1.1 and 3.1.2, but those govern people and permissions, while this one governs the data’s path between systems and networks. A user can be fully authorized and still not be allowed to move CUI down a particular route.

How this connects to other controls

This control doesn’t stand alone. A few close relationships:

  • Scoping and asset inventory: you can’t decide where CUI should flow until you know where it lives and how the business uses it, so this control builds directly on that work.
  • System & Communications Protection: boundary protection and encryption are where the approved flows are actually enforced, so these two families overlap heavily.
  • Media Protection: controlling CUI on removable media is another way of controlling where it’s allowed to go.

The requirement, word for word

For your reference, here’s the exact language so you’re working from the source and not a paraphrase:

3.1.3

Control the flow of CUI in accordance with approved authorizations.

Every organization implements these controls a little differently. If you’re not sure whether your approach would satisfy an assessor, join one of our upcoming webinars or schedule a 15 Minutes with FutureFeed session. We’d rather answer your questions now than have you discover them during an assessment.

CMMC: Everything You Need to Know to Get Started, 6th Edition guide cover

CMMC: Everything You Need to Know to Get Started (6th Edition)

Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.

Sources

  • NIST SP 800-171 Rev 2, Access Control (3.1)
  • Related standards: NIST SP 800-53 Rev 5 (AC-4 Information Flow Enforcement) · DFARS 252.204-7012