CMMCpedia Download

Requirements / System and Communications Protection (SC)

SC.L2-3.13.7

Split Tunneling

Official Source Material

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

Determine if:

  1. [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling).

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

With a VPN, this is one setting plus proof users cannot change it.

Disable split tunneling on the VPN (virtual private network) concentrator or client profile, so every packet from a connected device rides the tunnel. Lock the client configuration so users cannot re-enable it. Test one device, then keep the configuration export and the test note as evidence for [a].

Expect the printer problem and solve it deliberately.

Full tunneling breaks printing to home printers, because the local subnet disappears. Decide the answer up front: block device redirection, allow USB-attached printers, or accept no remote printing. Quietly re-enabling split tunneling to stop the complaints defeats the objective.

A cloud-only environment answers this at the endpoint.

With no on-premises system to tunnel into, the requirement does not vanish. The remote device itself becomes the boundary to defend. A host firewall denying unsolicited inbound connections, endpoint detection and response, and DNS or web filtering give the endpoint the controls a perimeter would. Each connection to your cloud tenant is then an individually secured TLS session rather than a bridge between networks. Write that architecture into your system security plan, the document that describes how your system meets each requirement, rather than claiming the requirement is not applicable.

Edge cases

  • No remote access to on-premises resources at all is a complete answer. Prohibit it technically, state the prohibition, and document how you would meet the requirement if remote access were ever introduced.
  • A VPN that tunnels everything except traffic to your own Microsoft 365 tenant sends trusted cloud traffic direct while the tunnel carries the rest. It is split tunneling by the literal definition, so it needs a written rationale explaining that the exempted traffic is TLS to a service you control.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.