1Overview
AC.L2-3.1.16 opens the short wireless pair of the Access Control family. It requires that wireless access be authorized before a device is allowed to connect, treating the wireless network as a controlled entry into the environment rather than an open one that any device in range can join.
Wireless deserves its own requirement because it extends the network past the walls. A wired connection requires physical access to a port inside the building; a wireless signal reaches the parking lot, the neighboring unit, and the street, so a wireless network that any device can join is an entry point available to anyone within range. The control asks the organization to define who and what may use wireless, and to require that authorization before a connection is permitted, so that joining the wireless network is a controlled act rather than an automatic one. It pairs with 3.1.17, which governs how that wireless access is then protected.
Authorize wireless access prior to allowing such connections.
The phrase "prior to allowing such connections" is the heart of the control: authorization comes before connection, not after. This means the organization has established which wireless access is permitted and has arranged that a device cannot simply join the wireless network without meeting that authorization. It is the wireless counterpart to the general access authorization of the family, applied specifically to the medium that reaches beyond the building.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.16 into two objectives: identify the wireless access points, and authorize wireless access before allowing connections.
Wireless access points are identified. The organization knows what wireless access exists in its environment, the access points and the networks they provide.
Wireless access is authorized prior to allowing such connections. The organization has defined which wireless access is permitted and enforces that authorization before a device connects, so an unauthorized device cannot join the wireless network that reaches the environment.
The two objectives move from knowing the wireless footprint to requiring and enforcing authorization. The common gap is at objective [b], where a shared wireless password is treated as authorization; a password everyone knows does not distinguish authorized devices from unauthorized ones, and the assessor looks for authorization that actually identifies who or what is connecting.
3Failure Patterns
The failures are about wireless that anyone can join and about access points that exist outside the organization's knowledge or control.
The shared wireless password
A single wireless password, known across the shop and rarely changed, is the most common shortfall. It permits connection to anyone who has ever learned it, including former employees and any device they configure, which is not authorization prior to connection but a shared secret with no individual accountability. Objective [b] calls for authorization that identifies the connecting device or user, which a common password does not provide.
The internal network on open wireless
Where the wireless network that any nearby device can join reaches the internal environment and the systems handling CUI, the wireless signal becomes an entry point around the building's physical controls. The internal environment should be reachable only by authorized wireless access, with visitors and unauthorized devices confined to an isolated network.
The rogue or forgotten access point
A consumer wireless router plugged in for convenience, or a legacy access point left running, creates wireless access the organization does not manage and may not know exists. Objective [a] fails because the wireless footprint is not fully identified, and the unmanaged access point is an entry that no authorization governs.
Guest and internal wireless not separated
A guest wireless network that shares the internal network rather than being isolated lets visitor devices reach the environment, defeating the purpose of authorizing internal wireless access. Guest access belongs on a separate, isolated network that cannot reach the CUI environment.
4Ownership
This is an IT and network-owned control whose main demands are knowing the full wireless footprint and enforcing real authorization rather than a shared secret.
| Role | Responsibility for this control |
|---|---|
| IT and network lead | Inventories the wireless access points, enforces authorization before connection through device or user authentication, and separates guest wireless from the internal network. Owns the configuration evidence. |
| Security or compliance lead | Confirms that authorization actually identifies authorized devices or users and that no unmanaged access point provides an unauthorized path. |
| Facilities and operations | Help surface unmanaged access points, since a consumer router added to the floor for convenience is often installed outside IT's knowledge. |
| Program lead | Includes wireless in periodic review, checking for new and rogue access points, and retains the wireless inventory. |
5Tooling
The control is built with enterprise wireless authentication and network separation, replacing the shared password with authorization that identifies the connecting device or user.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Wireless controller inventory, rogue access point detection | A record of the managed access points and detection of unmanaged ones, so the wireless footprint is fully known. |
| [b] | WPA2 or WPA3 Enterprise with 802.1X, RADIUS or Network Policy Server tied to the directory | Authorization before connection through individual authentication against the directory, replacing a shared password so only authorized users or devices join the internal network. |
| [b] separation | Separate guest SSID and VLAN, isolated from the internal network | An isolated guest network for unauthorized and visitor devices that cannot reach the CUI environment. |
| Device authorization | Certificate-based authentication, Intune enrollment | Authorizing specific devices by certificate or enrollment, a stronger form of prior authorization than a user password alone. |
The caveat is that a shared password is not authorization. Enterprise wireless authentication tied to the directory is what turns wireless access into an authorized act, and the work is moving from a common secret to individual authentication and separating the internal network from guest access. The assessor tests objective [b] by checking whether an unauthorized device can join the internal wireless network, so the enforcement has to identify the connecting party rather than merely check a shared key.
6Evidence
The satisfied version of 3.1.16 shows the identified wireless footprint and authorization enforced before connection.
| Evidence | What it demonstrates |
|---|---|
| Wireless access point inventory | Objective [a]. The documented set of managed access points and networks. |
| Wireless authentication configuration | Objective [b]. Enterprise authentication tying wireless access to the directory, enforcing authorization before connection. |
| Guest network separation | Objective [b]. The isolated guest network configuration that keeps unauthorized devices from the internal environment. |
| Rogue access point detection | Objective [a]. Evidence that unmanaged access points are detected rather than able to exist unseen. |
The evidence should demonstrate that authorization identifies the connecting device or user, not merely that a password is required, and that the internal wireless network is reachable only by authorized access with guests isolated. Configuration showing directory-tied wireless authentication, paired with a wireless inventory and rogue detection, is the clearest demonstration of the control.
A shared Wi-Fi password is not authorization
Moving from a wireless password everyone knows to authentication that identifies each authorized device or user, and separating guest access from the internal network, is a common readiness gap on a shop floor. Standing up enterprise wireless authorization and finding any unmanaged access points is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.16. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.16[a] and 3.1.16[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov