3.1 Access Control5 pts

3.1.13 — Encrypt remote access sessions

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

All remote access is protected with strong cryptography.

What it actually means

Whatever path remote users take in, the session has to be encrypted end to end — TLS 1.2+ or an IPsec VPN. This pairs with 3.1.12: 3.1.12 says monitor and control the session; 3.1.13 says encrypt it.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Not Applicable only if there is genuinely no remote access (document it, same as 3.1.12).

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Access Control (3.1)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.