CMMCpedia Download

Requirements / System and Communications Protection (SC)

SC.L2-3.13.14

Voice over Internet Protocol

Official Source Material

Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

Determine if:

  1. [a] use of Voice over Internet Protocol (VoIP) technologies is controlled; and
  2. [b] use of Voice over Internet Protocol (VoIP) technologies is monitored.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

This covers voice as network traffic, not the copper phone line.

Plain telephone service is outside this requirement. VoIP is data on a network and gets treated like any other protocol. A true no-VoIP environment can assess this requirement as not applicable. But Teams, Zoom, and softphones are VoIP technologies, so no VoIP at all is rarely true. State what you run and how it is controlled.

Control is naming the approved service. Monitoring is watching its traffic.

Authorize the VoIP solution in policy and configuration, and restrict use to the approved product [a]. Monitor through its logs, and watch your network monitoring for voice traffic that is not the approved service [b]. Patching the VoIP software with the rest of the fleet under SI.L2-3.14.1 is part of controlling it.

Keep CUI out of the phone system rather than pulling the phone system into scope.

Segment VoIP from the environment holding CUI (Controlled Unclassified Information), and prohibit CUI discussion over it in policy and training. When a voice conversation about CUI must happen, use a service authorized to carry CUI, such as Teams in GCC High. State compliance through separation in your system security plan, the document that describes how your system meets each requirement, instead of arguing the requirement away.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.