3.1 Access Control5 ptsAlso Level 1

3.1.1 — Limit who (and what) can get in

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Only approved people, processes, and devices can access your CUI systems.

What it actually means

This is the front door. Every account, service, and device that can reach your CUI environment must be one you deliberately approved — and you must be able to show the list. In practice that means a central identity provider, a documented request-and-approval step before access is granted, and only managed/enrolled devices allowed to connect.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.