1Overview
MA.L2-3.7.5 is the family's second five-point requirement and it secures remote maintenance. It requires multifactor authentication to establish nonlocal maintenance sessions over external network connections, and the termination of those sessions when the work is done, so that remote maintenance access is both strongly authenticated and closed promptly. It is a five-point requirement that cannot be deferred on a plan of action.
Nonlocal maintenance, servicing systems over an external network, is powerful and remote, which makes it an attractive target: an attacker who compromises a maintenance session gains privileged remote access. This control addresses two risks. First, it requires MFA to establish the session, so a stolen password alone cannot open a maintenance connection. Second, it requires that the session be terminated when maintenance is complete, so an open connection does not linger as a standing entry point. Its five-point weight reflects the depth of access remote maintenance grants.
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.
The requirement has two parts, both tied to nonlocal maintenance over external connections. Establishing the session requires MFA, adding a second factor to the strong authentication such privileged remote access demands. Completing the maintenance requires terminating the session, so the connection does not remain open afterward. Together they ensure remote maintenance access is hard to obtain and does not persist beyond its need.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.7.5 into two objectives: require MFA to establish the session and terminate it when complete.
Multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. Remote maintenance sessions require MFA to open.
Nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. The session is closed when the work is done.
The two objectives are MFA to open and termination to close. The common gap is at objective [b], where sessions are established with MFA but left open afterward, so a maintenance connection persists as a standing access path. The assessor looks for both strong authentication and prompt termination.
3Failure Patterns
The failures are about weakly authenticated or lingering maintenance sessions.
Remote maintenance without MFA
A nonlocal maintenance session that opens on a password alone is vulnerable to credential theft, giving an attacker privileged remote access. Requiring MFA to establish the session closes this.
Sessions left open
A maintenance session left connected after the work is done is a standing entry point that no one is using but an attacker could. Terminating the session when maintenance completes removes it.
No defined end to the session
Where there is no process to close maintenance connections, they accumulate as forgotten open paths. A defined termination step keeps them from lingering.
4Ownership
This is an IT-owned technical control tied to how remote maintenance is conducted.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Requires MFA for nonlocal maintenance sessions and terminates them when complete. Owns the technical evidence. |
| Security or compliance lead | Confirms remote maintenance requires MFA and that sessions are closed promptly. |
| Program lead | Includes remote maintenance in periodic review and retains the evidence. |
5Tooling
The control is delivered by MFA on remote maintenance access and by session termination.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | MFA on remote maintenance connections | Strong authentication to establish a nonlocal maintenance session. |
| [b] | Session termination process, timeouts | Closing of the maintenance connection when the work is done. |
The caveat is that both ends have to hold: MFA to open and termination to close. A session protected by MFA but left open still leaves a standing path, and a session closed promptly but opened on a password alone is weakly defended. The assessor examines both, so MFA and termination both have to be present.
6Evidence
The satisfied version of 3.7.5 shows MFA-protected maintenance sessions that terminate when complete.
| Evidence | What it demonstrates |
|---|---|
| Remote maintenance MFA configuration | Objective [a]. Sessions require MFA to establish. |
| Session termination process | Objective [b]. Sessions are closed when maintenance completes. |
The evidence should show nonlocal maintenance sessions requiring MFA to open and terminated when complete. The MFA configuration and the termination process are the clearest demonstration, and because this control cannot sit on a plan of action, both have to be real at the time of assessment.
Remote maintenance should be hard to open and quick to close
Nonlocal maintenance is privileged access from outside the environment, so this five-point control requires MFA to establish it and termination when it is done. Configuring MFA on remote maintenance and closing sessions promptly is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.7.5[a] and 3.7.5[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.5 among the five-point derived security requirements. ecfr.gov