CMMCpedia Download

Requirements / Access Control (AC)

AC.L2-3.1.14

Remote Access Routing

Official Source Material

Route remote access via managed access control points.

Determine if:

  1. [a] managed access control points are identified and implemented; and
  2. [b] remote access is routed through managed network access control points.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Funnel every remote path through a small number of points you manage.

Objective [a] asks you to identify and implement the control points. [b] asks you to show that all remote access actually routes through them. A VPN concentrator, the device that terminates every VPN connection, behind the firewall is the classic answer: one auditable door instead of a dozen ad hoc paths. That simplifies both monitoring under AC.L2-3.1.12 and this requirement's evidence.

Cloud-only environments already have the control point.

Conditional access in Microsoft Entra ID is a gate every session passes through: it decides who connects, from which devices, under which conditions, and it logs the decision. Document it as your managed access control point. You do not need to bolt a VPN onto a cloud-native architecture to satisfy this requirement.

A network diagram is the cleanest evidence.

Mark each access control point and show that no remote path bypasses them. For a hybrid shop that is the VPN gateway for network access and the conditional access layer for cloud services, on one page.

A managed point does more than pass traffic.

Managed means the point enforces policy and leaves a record: it authenticates against your identity provider, logs connections into your log tooling, and applies inspection or health checks where feasible. A port forward on an unmanaged router is a hole, not an access control point.

Edge cases

  • A managed service provider (MSP) remotely managing individual endpoints with an agent-based tool is administering specific machines, not entering your network through a path you route. Document the tool and its controls under AC.L2-3.1.12 and AC.L2-3.1.15, and keep this requirement's evidence focused on the paths into your system.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.