DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.10
The CMMC Guide · Access Control Family

AC.L2-3.1.10  Session Lock

Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

Family
Access ControlAC, 22 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

AC.L2-3.1.10 requires that a workstation lock itself after a period of inactivity and that the lock screen hide whatever was on the display. It addresses the ordinary risk of a logged-in machine left unattended, which on a manufacturing floor is not an edge case but a daily reality, where an operator steps away from a terminal that still holds an open drawing.

The control has two parts that are easy to miss as one. The session must lock after inactivity, and the lock must conceal what was previously displayed rather than freezing the last screen in view. A lock that leaves a controlled drawing visible behind it has prevented interaction but not viewing, and the requirement names both. The threshold is not fixed by the requirement, but it must be short enough to be meaningful, and the same lock should be available for a user to invoke deliberately when stepping away. A defined inactivity period, an enforced lock, and a pattern-hiding display together satisfy the control.

The requirement · NIST SP 800-171 Rev 2, 3.1.10

Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

Two elements distinguish this from a simple screensaver. "Session lock" means the machine requires reauthentication to resume, not merely a moving image that clears on a keypress. "Pattern-hiding displays" means the lock screen obscures the prior content, so a passerby cannot read what was open. Both are required, and a screensaver that does not lock, or a lock that shows the underlying screen, satisfies only part of the control.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.10 into three objectives: define the inactivity period, enforce the lock after it, and hide the previous display.

[a]

The period of inactivity after which the system initiates a session lock is defined. The organization has set how long a machine may sit idle before it locks.

MeetsA defined inactivity period, short enough to be meaningful, recorded in the configuration policy.
FailsNo inactivity period is set, so machines never lock on their own.
[b]

Access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. The machine actually locks and requires reauthentication once the idle period passes.

MeetsAfter the defined idle time, the workstation locks and requires the user to sign in again to resume.
FailsA screensaver appears but the machine does not lock, so any keypress resumes the session without authentication.
[c]

Previously visible information is concealed via a pattern-hiding display when a session lock is initiated. The lock screen hides what was on the display rather than leaving it in view.

MeetsThe lock screen replaces the desktop, so an open drawing is no longer readable to anyone standing at the machine.
FailsThe lock overlays a small prompt while the CUI document remains visible behind it.

The three objectives are a threshold, a lock, and a concealment. The most frequently missed is the difference between [b] and a screensaver: a decorative timeout that does not require reauthentication satisfies neither the access nor the viewing element, and the assessor distinguishes the two directly.

3Failure Patterns

The failures gather on the shop floor, where locking behavior collides with how machines are actually used, and on the systems that central policy does not manage.

The shop-floor terminal that never locks

Locking is disabled on floor terminals because reauthenticating at a shared or awkward station interrupts the work, so the machine holding job files and drawings sits open all shift. This is the most common and most consequential failure of the control, and it usually cannot be fixed by the timeout alone; it needs a workable authentication approach for the floor, such as badge tap or fast user switching, so that locking does not stop production.

The screensaver mistaken for a lock

A machine set to show a screensaver after inactivity may not be set to lock, so the session resumes on any keypress with no authentication. The screensaver looks like compliance and is not, because objective [b] requires reauthentication and objective [c] requires the prior content to be hidden, neither of which a bare screensaver provides.

The timeout set too long to matter

An inactivity period measured in an hour or more technically satisfies objective [a] while defeating the purpose, because the unattended machine remains open through exactly the window in which someone would walk past it. The period has to be short enough to address the risk the control names.

The standalone and specialized machines left out

Session lock configured through Group Policy reaches domain-joined workstations and misses the workgroup machine, the standalone controller, and the specialized equipment interface, which are common on a shop floor and often display CUI. These systems need the lock applied directly or, where they cannot lock, a compensating physical control.

The common root
Session lock fails where locking fights the work. On the office desktop it is trivial; on the shared floor terminal it requires an authentication method that people will actually use, and the honest fix is to solve that rather than to switch the lock off.

4Ownership

This is an IT-owned technical control whose one complication is the shop floor, where the operations side has to be part of finding a locking approach that does not impede production.

RoleResponsibility for this control
IT lead or system administratorDefines the inactivity period and enforces the lock and pattern-hiding display across workstations, including standalone and specialized systems. Owns the configuration evidence.
Operations or floor supervisorPartners on a locking approach the floor will accept, such as badge-based reauthentication or fast switching, so that the control is sustained rather than disabled to keep the line moving.
Security or compliance leadConfirms the inactivity period is short enough to be meaningful and that the lock conceals prior content on the systems that handle CUI.
Program leadIncludes session-lock coverage in periodic review, particularly for new floor equipment, and retains the record.
See also: Session lock addresses the unattended-machine risk that also underlies the physical protection family, and it works with the session-termination requirement at 3.1.11.

5Tooling

The control is set with native lock and screensaver policy, and the meaningful work is applying it everywhere and solving the floor-authentication problem so the lock survives.

ObjectivesToolingWhat it provides
[a], [b], [c]Group Policy machine inactivity limit and screen-saver lock settingsThe inactivity timeout that triggers a locking, pattern-hiding screen requiring reauthentication on domain-joined systems.
[b], [c] standaloneLocal policy or configuration baselinesThe same lock and concealment on workgroup machines and local sign-ins outside Group Policy.
Floor practicalityBadge or smart-card reauthentication, fast user switching, proximity lockAn authentication method quick enough that locking does not impede floor work, which is what keeps the control from being disabled in practice.
Specialized equipmentEquipment-native lock settings or a compensating physical controlA lock on machines that support one, and where they do not, a documented physical measure such as positioning or enclosure to satisfy the concealment intent.

The caveat is that the office case and the floor case are different problems. On the office desktop the native settings satisfy the control outright; on the shared floor terminal the control is only sustainable if reauthentication is fast enough to accept, so the tooling that matters most is often the badge reader rather than the timeout. The assessor tests objectives [b] and [c] by letting a machine idle and observing whether it locks and hides its content, including on representative floor systems.

6Evidence

The satisfied version of 3.1.10 shows the defined period, the enforced lock, and the concealed display across the range of systems.

EvidenceWhat it demonstrates
Session-lock policy configurationObjectives [a], [b]. The defined inactivity period and the lock-on-timeout setting.
Pattern-hiding lock screenObjective [c]. The lock screen concealing prior content, shown by screenshot or observation.
Group Policy enforcement reportObjective [b]. The lock applied across domain-joined systems.
Standalone and specialized system configurationObjectives [b], [c]. The lock, or a documented compensating control, on machines outside Group Policy.
Floor reauthentication methodSupporting. The badge or switching approach that keeps the lock sustainable on shared terminals.

The evidence should demonstrate the lock on the systems most likely to display CUI, which on a manufacturing floor means the terminals and specialized interfaces rather than only the office desktops. Observation is the strongest evidence here, since letting a representative machine idle and watching it lock and conceal its content demonstrates all three objectives at once.

The floor terminal is the real question

Session lock is trivial on the office desktop and genuinely hard on the shared shop-floor terminal, where the honest answer is a fast reauthentication method rather than a disabled lock. Working out a locking approach the floor will actually keep, and covering the standalone and specialized machines, is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.10. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.10[a] through 3.1.10[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.9 · Privacy and Security Notices
Next in Access Control →
AC.L2-3.1.11 · Terminate Sessions
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.10 · Edition 2026.1 · Last reviewed July 12, 2026