DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.16
The CMMC Guide · Access Control Family

AC.L2-3.1.16  Authorize Wireless Access

Authorize wireless access prior to allowing such connections.

Family
Access ControlAC, 22 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

AC.L2-3.1.16 opens the short wireless pair of the Access Control family. It requires that wireless access be authorized before a device is allowed to connect, treating the wireless network as a controlled entry into the environment rather than an open one that any device in range can join.

Wireless deserves its own requirement because it extends the network past the walls. A wired connection requires physical access to a port inside the building; a wireless signal reaches the parking lot, the neighboring unit, and the street, so a wireless network that any device can join is an entry point available to anyone within range. The control asks the organization to define who and what may use wireless, and to require that authorization before a connection is permitted, so that joining the wireless network is a controlled act rather than an automatic one. It pairs with 3.1.17, which governs how that wireless access is then protected.

The requirement · NIST SP 800-171 Rev 2, 3.1.16

Authorize wireless access prior to allowing such connections.

The phrase "prior to allowing such connections" is the heart of the control: authorization comes before connection, not after. This means the organization has established which wireless access is permitted and has arranged that a device cannot simply join the wireless network without meeting that authorization. It is the wireless counterpart to the general access authorization of the family, applied specifically to the medium that reaches beyond the building.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.16 into two objectives: identify the wireless access points, and authorize wireless access before allowing connections.

[a]

Wireless access points are identified. The organization knows what wireless access exists in its environment, the access points and the networks they provide.

MeetsA documented inventory of wireless access points and the networks they broadcast, including any guest and separate networks.
FailsWireless has grown without inventory, and unknown or rogue access points may exist unrecorded.
[b]

Wireless access is authorized prior to allowing such connections. The organization has defined which wireless access is permitted and enforces that authorization before a device connects, so an unauthorized device cannot join the wireless network that reaches the environment.

MeetsWireless authentication ties to the directory, so only enrolled or authenticated devices and users reach the internal network, and others land on an isolated guest network.
FailsThe internal wireless network uses a shared password known throughout the shop, so any device with it connects.

The two objectives move from knowing the wireless footprint to requiring and enforcing authorization. The common gap is at objective [b], where a shared wireless password is treated as authorization; a password everyone knows does not distinguish authorized devices from unauthorized ones, and the assessor looks for authorization that actually identifies who or what is connecting.

3Failure Patterns

The failures are about wireless that anyone can join and about access points that exist outside the organization's knowledge or control.

The shared wireless password

A single wireless password, known across the shop and rarely changed, is the most common shortfall. It permits connection to anyone who has ever learned it, including former employees and any device they configure, which is not authorization prior to connection but a shared secret with no individual accountability. Objective [b] calls for authorization that identifies the connecting device or user, which a common password does not provide.

The internal network on open wireless

Where the wireless network that any nearby device can join reaches the internal environment and the systems handling CUI, the wireless signal becomes an entry point around the building's physical controls. The internal environment should be reachable only by authorized wireless access, with visitors and unauthorized devices confined to an isolated network.

The rogue or forgotten access point

A consumer wireless router plugged in for convenience, or a legacy access point left running, creates wireless access the organization does not manage and may not know exists. Objective [a] fails because the wireless footprint is not fully identified, and the unmanaged access point is an entry that no authorization governs.

Guest and internal wireless not separated

A guest wireless network that shares the internal network rather than being isolated lets visitor devices reach the environment, defeating the purpose of authorizing internal wireless access. Guest access belongs on a separate, isolated network that cannot reach the CUI environment.

The common root
Wireless access fails when a shared password is mistaken for authorization. The requirement is that the organization know who and what is permitted and enforce that before connection, which a secret passed around the shop cannot do.

4Ownership

This is an IT and network-owned control whose main demands are knowing the full wireless footprint and enforcing real authorization rather than a shared secret.

RoleResponsibility for this control
IT and network leadInventories the wireless access points, enforces authorization before connection through device or user authentication, and separates guest wireless from the internal network. Owns the configuration evidence.
Security or compliance leadConfirms that authorization actually identifies authorized devices or users and that no unmanaged access point provides an unauthorized path.
Facilities and operationsHelp surface unmanaged access points, since a consumer router added to the floor for convenience is often installed outside IT's knowledge.
Program leadIncludes wireless in periodic review, checking for new and rogue access points, and retains the wireless inventory.
See also: This control pairs with the preceding remote-access controls as another path into the environment, and directly with 3.1.17, which governs the protection of the authorized wireless access.

5Tooling

The control is built with enterprise wireless authentication and network separation, replacing the shared password with authorization that identifies the connecting device or user.

ObjectivesToolingWhat it provides
[a]Wireless controller inventory, rogue access point detectionA record of the managed access points and detection of unmanaged ones, so the wireless footprint is fully known.
[b]WPA2 or WPA3 Enterprise with 802.1X, RADIUS or Network Policy Server tied to the directoryAuthorization before connection through individual authentication against the directory, replacing a shared password so only authorized users or devices join the internal network.
[b] separationSeparate guest SSID and VLAN, isolated from the internal networkAn isolated guest network for unauthorized and visitor devices that cannot reach the CUI environment.
Device authorizationCertificate-based authentication, Intune enrollmentAuthorizing specific devices by certificate or enrollment, a stronger form of prior authorization than a user password alone.

The caveat is that a shared password is not authorization. Enterprise wireless authentication tied to the directory is what turns wireless access into an authorized act, and the work is moving from a common secret to individual authentication and separating the internal network from guest access. The assessor tests objective [b] by checking whether an unauthorized device can join the internal wireless network, so the enforcement has to identify the connecting party rather than merely check a shared key.

6Evidence

The satisfied version of 3.1.16 shows the identified wireless footprint and authorization enforced before connection.

EvidenceWhat it demonstrates
Wireless access point inventoryObjective [a]. The documented set of managed access points and networks.
Wireless authentication configurationObjective [b]. Enterprise authentication tying wireless access to the directory, enforcing authorization before connection.
Guest network separationObjective [b]. The isolated guest network configuration that keeps unauthorized devices from the internal environment.
Rogue access point detectionObjective [a]. Evidence that unmanaged access points are detected rather than able to exist unseen.

The evidence should demonstrate that authorization identifies the connecting device or user, not merely that a password is required, and that the internal wireless network is reachable only by authorized access with guests isolated. Configuration showing directory-tied wireless authentication, paired with a wireless inventory and rogue detection, is the clearest demonstration of the control.

A shared Wi-Fi password is not authorization

Moving from a wireless password everyone knows to authentication that identifies each authorized device or user, and separating guest access from the internal network, is a common readiness gap on a shop floor. Standing up enterprise wireless authorization and finding any unmanaged access points is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.16. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.16[a] and 3.1.16[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.15 · Authorize Remote Privileged Commands
Next in Access Control →
AC.L2-3.1.17 · Protect Wireless Access
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.16 · Edition 2026.1 · Last reviewed July 12, 2026