Requirements / Access Control (AC)
AC.L2-3.1.20
External Connections
Official Source Material
Verify and control/limit connections to and use of external systems.
Determine if:
- [a] connections to external systems are identified;
- [b] the use of external systems is identified;
- [c] connections to external systems are verified;
- [d] the use of external systems is verified;
- [e] connections to external systems are controlled/limited; and
- [f] the use of external systems is controlled/limited.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
This requirement can never sit on a POA&M.
A POA&M is the plan of action that buys time for unfinished requirements, and 32 CFR 170.21(a)(2)(iii) excludes AC.L2-3.1.20 from Level 2 plans of action. A Not Met here blocks even a Conditional CMMC Status, regardless of your overall score. Treat it as day-one work, not cleanup.
Scope the list to systems that matter, not the whole internet.
Read literally, [a] could mean every connection from every system. Do not take the bait. The list that answers [a] and [b] has two parts. The first is the external services that receive your CUI or FCI. CUI is the controlled unclassified information your contract requires you to protect. FCI is the non-public information the government provides, or you generate for it, under your contract. The second is the connections that allow access back into your environment. Your cloud suite, file transfer services, a managed service provider's (MSP) tooling, and government portals are the usual entries. A dozen well-described entries is a normal answer. Hundreds of websites is a wrong turn that makes every later objective unmanageable.
Verification is recorded trust, per connection.
For [c] and [d], record why each listed system is fit for what you use it for. FedRAMP is the federal cloud authorization program. A cloud service's FedRAMP authorization and package identifier, the contract terms for a partner connection, or the configuration showing only expected devices connect all serve. A policy stating which systems are approved for FCI and CUI, paired against the list, is the verification of use.
Control and limit with the firewall and the policy together.
Objectives [e] and [f] split along the same line: firewall rules and content filtering control the connections, and a policy naming the approved systems and prohibiting all others limits the use. Remote laptops are the leak in this design, because their traffic can bypass the firewall. An always-on VPN or enforced endpoint firewall rules brings them back inside the controls.
Personal devices are external systems.
A personal phone or home computer touching company services is exactly what this requirement governs. Either block them or bring them under defined terms and verification. Conditional access that refuses unmanaged devices is the cleanest enforcement, because it makes the limit self-executing.
External can mean your own other network.
A lab, a commercial business unit, or any system outside the assessment scope is an external system from the enclave's perspective, even though your company owns it. Connections between the enclave and those environments belong on the list with the same verify-and-limit treatment as any vendor.
What falls short
- A multifactor authentication product offered as evidence of external connection control. It authenticates access to your own systems and says nothing about connections to external ones, so it answers none of [a] through [f].
- Open egress plus unmanaged personal-device use with no external system list and no policy. Nothing is identified under [a] and [b], so nothing downstream can be verified, controlled, or limited.
Edge cases
- Routine business websites such as banks are not the focus, because nothing there reaches back into your system and no CUI flows to them. Note the reasoning once rather than inventorying the web.
- Government-operated destinations can be grouped: a single entry covering .mil and .gov services such as DoD SAFE keeps the list honest without itemizing every portal.