3.13 System & Communications Protection5 ptsAlso Level 1

3.13.5 — Wall off your public-facing systems

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

Put anything the public can reach — web servers, mail relays, guest Wi-Fi — on a separated subnetwork, not your internal network.

What it actually means

Publicly accessible components — a public web server, a guest network, a mail gateway — must sit in a separate subnetwork, a DMZ, that is physically or logically isolated from the internal network where CUI lives. If a public box gets compromised, the attacker lands in the DMZ, not next to your CUI.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

Also a Level 1 (FCI) requirement and a 5-point control. If you host nothing publicly accessible, document that — but guest Wi-Fi and any internet-reachable service still count.

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.