Requirements / Access Control (AC)
AC.L2-3.1.14
Remote Access Routing
Official Source Material
Route remote access via managed access control points.
Determine if:
- [a] managed access control points are identified and implemented; and
- [b] remote access is routed through managed network access control points.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Funnel every remote path through a small number of points you manage.
Objective [a] asks you to identify and implement the control points. [b] asks you to show that all remote access actually routes through them. A VPN concentrator, the device that terminates every VPN connection, behind the firewall is the classic answer: one auditable door instead of a dozen ad hoc paths. That simplifies both monitoring under AC.L2-3.1.12 and this requirement's evidence.
Cloud-only environments already have the control point.
Conditional access in Microsoft Entra ID is a gate every session passes through: it decides who connects, from which devices, under which conditions, and it logs the decision. Document it as your managed access control point. You do not need to bolt a VPN onto a cloud-native architecture to satisfy this requirement.
A network diagram is the cleanest evidence.
Mark each access control point and show that no remote path bypasses them. For a hybrid shop that is the VPN gateway for network access and the conditional access layer for cloud services, on one page.
A managed point does more than pass traffic.
Managed means the point enforces policy and leaves a record: it authenticates against your identity provider, logs connections into your log tooling, and applies inspection or health checks where feasible. A port forward on an unmanaged router is a hole, not an access control point.
Edge cases
- A managed service provider (MSP) remotely managing individual endpoints with an agent-based tool is administering specific machines, not entering your network through a path you route. Document the tool and its controls under AC.L2-3.1.12 and AC.L2-3.1.15, and keep this requirement's evidence focused on the paths into your system.