DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.20
The CMMC Guide · Access Control Family

AC.L2-3.1.20  External Systems

Verify and control or limit connections to and use of external systems.

Family
Access ControlAC, 22 requirements
Point Value
1Low weight, but a named POA&M exclusion
POA&M Eligible
NoNamed exclusion under 32 CFR 170.21
Objectives
SixPer NIST SP 800-171A

1Overview

AC.L2-3.1.20 governs the seam between the organization's environment and the systems it does not control. It requires that connections to and use of external systems be verified and either controlled or limited, so that the boundary of the CUI environment is not quietly extended through every outside system an employee happens to use. It is one of the controls that cannot remain open on a plan of action at a Level 2 assessment.

An external system is one outside the organization's authorization boundary: a home computer, a partner's network, a personal cloud account, a kiosk, a device the organization neither owns nor manages. The risk is that CUI flows to or through these systems, or that these systems connect into the environment, without any assurance about how they are secured. The control asks the organization to know where its environment connects to the outside, to verify that those external systems meet its requirements or to limit what they can do, and specifically to govern the use of the organization's own cloud and external services and the portable storage that moves between inside and outside. It is a boundary control as much as an access control, and it interacts closely with the scoping that defines the environment in the first place.

The requirement · NIST SP 800-171 Rev 2, 3.1.20

Verify and control or limit connections to and use of external systems.

The requirement pairs "verify" with "control or limit." To verify is to have assurance that an external system meets the organization's security requirements before it connects or is used for CUI. To control or limit is either to permit the connection under conditions the organization enforces, or, where that assurance is not possible, to limit or prohibit the use. The requirement also reaches the organization's use of external systems, including cloud services, and the connection of portable storage to external systems, drawing those specific cases into the control.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.20 into six objectives: identify the external connections and their use, verify each, and control or limit each.

[a]

Connections to external systems are identified. The organization knows where its environment connects to systems outside its boundary.

MeetsA documented set of external connections and services: the cloud platforms, partner connections, and remote endpoints that touch the environment.
FailsExternal connections have grown unrecorded, and no one can list where the environment reaches outside.
[b]

The use of external systems is identified. The organization knows how external systems are used in relation to CUI, including its own cloud services and staff use of outside systems.

MeetsA defined understanding of which external systems and services are used for CUI and how, including sanctioned cloud services.
FailsStaff use personal cloud and outside systems for work with no record of what handles CUI.
[c]

Connections to external systems are verified. The organization has assurance that the external systems it connects to meet its security requirements.

MeetsExternal connections are permitted only where the external system is verified to meet requirements, such as an authorized cloud service.
FailsExternal systems connect with no verification of how they are secured.
[d]

The use of external systems is verified. The organization has assurance that the external services used for CUI meet its requirements, including its own cloud services.

MeetsCUI is handled only on verified external services whose security posture has been confirmed.
FailsCUI is worked on unverified personal systems and consumer cloud with no assurance.
[e]

Connections to external systems are controlled/limited. Connections that cannot be assured are limited or prohibited.

MeetsConnections to unverified external systems are blocked, and only assured connections are permitted.
FailsAny external system may connect regardless of assurance.
[f]

The use of external systems is controlled/limited. Use of external systems for CUI that cannot be assured is limited or prohibited, and the limit is enforced.

MeetsUse of unverified personal systems and consumer cloud for CUI is prohibited and enforced.
FailsCUI is worked on personal home computers and consumer cloud with no limit.

The six objectives pair identification, verification, and control across both connection and use. The common gap is at objectives [c] through [f], where an organization identifies its external systems but neither verifies the important ones nor limits the ones it cannot verify, so external systems of unknown security posture continue to touch CUI. The assessor looks for verification of the trusted external systems and a real limit on the rest.

3Failure Patterns

The failures are about CUI leaving onto systems the organization does not control and about external services adopted without verification.

Work on personal home computers

Staff working on CUI from personal home computers place controlled data on systems the organization has no assurance about, which fails objectives [c] and [d] directly. The resolution is either to bring that work onto managed devices or a verified virtual environment, or to prohibit and prevent it, since a personal home computer of unknown security cannot be verified.

Consumer cloud and personal accounts

Personal cloud storage, personal email, and consumer file-sharing used for work move CUI onto external systems outside any organizational control. The control requires that use of external systems for CUI be verified or limited, and consumer services used ad hoc are neither, so they have to be replaced with sanctioned services or blocked.

Cloud services adopted without verification

Even sanctioned cloud services are external systems, and adopting one to handle CUI without verifying it meets the requirements, including the specific assurance expected for cloud handling CUI, fails the verification element. The organization has to confirm that an external service is adequate before entrusting CUI to it, not merely that it is convenient or widely used.

Portable storage across the boundary

The requirement specifically reaches the connection of portable storage to external systems, so a thumb drive that carries CUI and is then plugged into a home computer or an external system crosses the boundary in a way this control governs. Portable storage used without limits is a path for CUI onto unverified external systems, and it connects to the media protection family.

The common root
This control fails when the boundary leaks through convenience. The home computer, the personal cloud account, the unverified service, and the traveling thumb drive each extend the environment to systems the organization cannot vouch for, and the control asks it to either vouch for them or stop the flow.

4Ownership

This control spans IT enforcement, a leadership decision about remote and personal-system use, and the verification of external services, so its ownership is broader than a single technical setting.

RoleResponsibility for this control
IT and system administratorIdentifies external connections and use, enforces the limits on personal systems and consumer services, and controls portable storage crossing the boundary. Owns the technical evidence.
Security or compliance leadVerifies that trusted external systems and cloud services meet the requirements before CUI is entrusted to them, and defines what use is prohibited.
Executive sponsorDecides the posture on personal systems and remote work, since prohibiting work on personal home computers is a business decision that leadership has to make and support.
Program leadIncludes external systems and services in periodic review, since new cloud services and connections appear continually, and retains the verification records.
See also: This control connects to the flow-of-CUI requirement at AC.L2-3.1.3, to the portable-storage requirement at 3.1.21, and to the scoping decisions that determine what counts as external in the first place.

5Tooling

The control is built with the boundary and cloud controls that limit external connections and use, plus the verification records that assure the trusted external systems.

ObjectivesToolingWhat it provides
[a], [b]Connection and service inventory, cloud discoveryIdentification of where the environment connects externally and which external services are used for CUI, including discovery of unsanctioned cloud use.
[e], [f] controlConditional Access, firewall and DLP egress controls, web filteringConfining CUI to verified external systems, blocking consumer cloud and personal accounts, and limiting connections to those that are assured.
[c], [d] verificationCloud service assessment, FedRAMP or equivalent assurance for cloud handling CUIConfirming that external services entrusted with CUI meet the required security posture before use.
Portable storage and personal systemsRemovable-media controls, virtual desktop or managed access for remote workLimiting portable storage across the boundary and providing a verified path for remote work instead of personal home computers.

The caveat is that verification and limitation are alternatives the organization must actually choose between for each external system, not a box to check. Where an external system can be verified to meet requirements, it may be used under control; where it cannot, its use must be limited or prohibited and that limit enforced. The assessor tests objectives [c] and [d] by examining whether CUI can reach an unverified external system, such as a personal cloud account or home computer, so the enforcement has to close those paths while permitting the verified ones.

6Evidence

The satisfied version of 3.1.20 shows the identified external systems, the verification of the trusted ones, and the enforced limits on the rest.

EvidenceWhat it demonstrates
External connection and service inventoryObjectives [a], [b]. The identified external connections and the external systems used for CUI.
External system verification recordsObjectives [c], [d]. Evidence that trusted external systems and cloud services meet the requirements before CUI is entrusted to them.
External access control configurationObjectives [e], [f]. The controls confining CUI to verified systems and blocking consumer and personal external systems.
Remote work and personal-system policyObjective [f]. The enforced posture on personal home computers and the verified alternative provided.
Portable storage controlsObjective [e]. Limits on portable storage crossing to external systems.

The evidence should show both that trusted external systems are verified and that unverified ones are limited or blocked, since the control turns on that pairing. Demonstrating that CUI cannot reach a personal cloud account or home computer, while the sanctioned external services are documented as verified, is the clearest demonstration, and because this control cannot sit on a plan of action, the enforcement has to be real at the time of assessment.

The boundary is only real if the outside is closed

External systems are where a carefully drawn boundary quietly leaks, through the home computer, the personal cloud account, the unverified service, the traveling thumb drive. Deciding the posture on personal systems, verifying the external services that handle CUI, and closing the rest is part of the onsite readiness work this practice does, and it is one of the controls that must be closed rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.20. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.20[a] through 3.1.20[f]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.19 · Encrypt CUI on Mobile Devices
Next in Access Control →
AC.L2-3.1.21 · Limit Use of Portable Storage
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.20 · Edition 2026.1 · Last reviewed July 12, 2026