1Overview
AC.L2-3.1.14 is the architectural requirement of the remote-access cluster: remote access must arrive through a small, managed set of entry points rather than through many scattered doors. It reduces the surface an organization has to defend and watch by funneling all remote connections through a limited number of controlled gateways.
The idea is straightforward and its benefit compounds across the other controls. If remote access can enter the environment at many points, each one has to be individually secured, monitored, and encrypted, and any that is overlooked becomes a way in. If remote access is instead routed through a few managed access control points, the organization can concentrate its defenses there: the monitoring of 3.1.12, the encryption of 3.1.13, and the inspection and enforcement that a managed gateway provides all apply at a small number of well-understood places. The control is satisfied when remote access is required to traverse those managed points and cannot bypass them.
Route remote access via managed access control points.
A managed access control point is a controlled gateway through which remote traffic must pass, such as a VPN concentrator or a remote access gateway that terminates and inspects the connection before it reaches the internal environment. "Managed" means the point is under the organization's control and oversight, and "route via" means remote access is constrained to travel through it, with no path that lets a remote connection reach the environment while avoiding the managed point.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.14 into two objectives: identify and control the managed access control points, and route remote access through them.
Managed access control points are identified and implemented. The organization has established the specific, limited set of controlled gateways through which remote access is to pass.
Remote access is routed through managed network access control points. Remote connections are constrained to travel through the managed points, with no bypass path into the environment.
The two objectives are an architecture and its enforcement: define the limited managed points, then require remote access to use them. The common gap is at objective [b], where an organization designates a proper gateway but leaves a direct path, an exposed remote-desktop port, a service published to the internet, that lets remote access reach the environment without passing through the managed point.
3Failure Patterns
The failures are about bypass paths and about remote entry points that multiplied without design, both of which defeat the consolidation the control depends on.
The exposed remote-desktop port
A remote-desktop service published directly to the internet, so a user or an attacker can reach an internal machine without passing through any managed gateway, is the classic failure of this control. It creates a remote entry point outside the managed set and is among the most commonly exploited exposures, defeating objective [b] regardless of how well the intended gateway is configured.
Services published individually to the internet
When individual applications or servers are each made directly reachable for remote use, the environment accumulates many uncoordinated entry points instead of a few managed ones. Objective [a] fails because there is no limited, defined set, and each published service is a door that must be separately defended.
The vendor path around the gateway
Outside support that connects through its own remote tool reaches the environment without traversing the managed access point, the same vendor-access gap seen across the cluster, here expressed as a bypass of the architectural control. The vendor connection has to enter through the managed point like any other remote access.
The split or unmanaged secondary gateway
A second remote access method stood up for a particular need, a cloud jump host, a legacy gateway left running, expands the set of entry points beyond what is actually managed and monitored. Every additional path that is not part of the controlled set undermines the concentration the requirement is meant to achieve.
4Ownership
This is an IT and network-owned architectural control, and its main demand is discipline about not opening remote entry points outside the managed set, which is as much a governance habit as a configuration.
| Role | Responsibility for this control |
|---|---|
| IT and network lead | Establishes the limited set of managed access control points, routes all remote access through them, and blocks direct remote paths and exposed services that would bypass them. Owns the architecture evidence. |
| Security or compliance lead | Confirms the managed points are the only remote entry into the environment and that no bypass path exists, and reviews for newly exposed services. |
| Vendor and contract managers | Ensure third-party remote access enters through the managed point rather than a vendor-controlled path around it. |
| Program lead | Includes external exposure in periodic review, checking for published services and new remote paths, and retains the record of the managed points. |
5Tooling
The control is delivered by the network architecture, the gateway, and the firewall rules that force remote access through it and close every bypass.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | VPN concentrator or remote access gateway, documented as the managed points | The limited, controlled set of entry points through which remote access is designed to pass. |
| [b] enforcement | Firewall rules, boundary configuration, no direct inbound remote paths | Permitting remote entry only through the managed points and blocking direct inbound access to internal services, so the architecture is enforced rather than merely intended. |
| [b] exposure control | External vulnerability and port scanning, attack-surface review | Finding and closing published services and exposed remote ports that would create entry points outside the managed set. |
| Vendor and cloud | Vendor access through the managed gateway, controlled cloud administration paths | Bringing third-party and cloud administrative access through the managed points rather than around them. |
The caveat is that the control is only as good as the absence of bypasses. A well-built gateway means nothing if a remote-desktop port is open beside it, so the work is as much about closing unmanaged paths as about building the managed one. The assessor tests objective [b] by looking for remote entry that avoids the managed points, often through an external scan of the organization's exposed surface, so the evidence has to show that the managed points are the only way in.
6Evidence
The satisfied version of 3.1.14 shows the limited managed points and demonstrates that remote access cannot bypass them.
| Evidence | What it demonstrates |
|---|---|
| Managed access point definition | Objective [a]. The documented, limited set of gateways through which remote access passes. |
| Network and boundary diagram | Objectives [a], [b]. The architecture showing remote access terminating at the managed points. |
| Firewall rule set | Objective [b]. Rules permitting remote entry only through the managed points and blocking direct paths. |
| External exposure scan | Objective [b]. Evidence that no remote-access service is exposed outside the managed points. |
| Vendor access path | Objectives [a], [b]. Confirmation that outside support enters through the managed point. |
The evidence should demonstrate the absence of bypass as much as the presence of the gateway, because the control turns on remote access having no other way in. An external view of the organization's exposed surface, showing only the managed points reachable for remote access, is the clearest single piece of evidence, paired with the firewall rules and architecture that enforce it.
The gateway is only as good as the ports beside it
Building a managed remote gateway is common; ensuring nothing reaches the environment around it, no exposed remote-desktop port, no individually published service, no vendor tool outside the path, takes an external look at the surface an attacker actually sees. Consolidating remote entry onto managed points and closing the bypasses is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.14. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.14[a] and 3.1.14[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov