DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.5
The CMMC Guide · Maintenance Family

MA.L2-3.7.5  Nonlocal Maintenance MFA

Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

Family
MaintenanceMA, 6 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

MA.L2-3.7.5 is the family's second five-point requirement and it secures remote maintenance. It requires multifactor authentication to establish nonlocal maintenance sessions over external network connections, and the termination of those sessions when the work is done, so that remote maintenance access is both strongly authenticated and closed promptly. It is a five-point requirement that cannot be deferred on a plan of action.

Nonlocal maintenance, servicing systems over an external network, is powerful and remote, which makes it an attractive target: an attacker who compromises a maintenance session gains privileged remote access. This control addresses two risks. First, it requires MFA to establish the session, so a stolen password alone cannot open a maintenance connection. Second, it requires that the session be terminated when maintenance is complete, so an open connection does not linger as a standing entry point. Its five-point weight reflects the depth of access remote maintenance grants.

The requirement · NIST SP 800-171 Rev 2, 3.7.5

Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

The requirement has two parts, both tied to nonlocal maintenance over external connections. Establishing the session requires MFA, adding a second factor to the strong authentication such privileged remote access demands. Completing the maintenance requires terminating the session, so the connection does not remain open afterward. Together they ensure remote maintenance access is hard to obtain and does not persist beyond its need.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.7.5 into two objectives: require MFA to establish the session and terminate it when complete.

[a]

Multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. Remote maintenance sessions require MFA to open.

MeetsNonlocal maintenance sessions over external connections require MFA to establish.
FailsRemote maintenance sessions open with only a password.
[b]

Nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. The session is closed when the work is done.

MeetsMaintenance sessions are terminated when the work is complete, so no connection lingers.
FailsRemote maintenance sessions remain open after the work is finished.

The two objectives are MFA to open and termination to close. The common gap is at objective [b], where sessions are established with MFA but left open afterward, so a maintenance connection persists as a standing access path. The assessor looks for both strong authentication and prompt termination.

3Failure Patterns

The failures are about weakly authenticated or lingering maintenance sessions.

Remote maintenance without MFA

A nonlocal maintenance session that opens on a password alone is vulnerable to credential theft, giving an attacker privileged remote access. Requiring MFA to establish the session closes this.

Sessions left open

A maintenance session left connected after the work is done is a standing entry point that no one is using but an attacker could. Terminating the session when maintenance completes removes it.

No defined end to the session

Where there is no process to close maintenance connections, they accumulate as forgotten open paths. A defined termination step keeps them from lingering.

The common root
This control fails at the two ends of the session. Remote maintenance is privileged access from outside, so it has to be hard to open, through MFA, and it must not stay open, through termination. A session that opens weakly or never closes is a remote door into the environment.

4Ownership

This is an IT-owned technical control tied to how remote maintenance is conducted.

RoleResponsibility for this control
IT and system administratorRequires MFA for nonlocal maintenance sessions and terminates them when complete. Owns the technical evidence.
Security or compliance leadConfirms remote maintenance requires MFA and that sessions are closed promptly.
Program leadIncludes remote maintenance in periodic review and retains the evidence.
See also: This control applies the multifactor authentication of IA.L2-3.5.3 to maintenance and works with the maintenance controls of MA.L2-3.7.2.

5Tooling

The control is delivered by MFA on remote maintenance access and by session termination.

ObjectivesToolingWhat it provides
[a]MFA on remote maintenance connectionsStrong authentication to establish a nonlocal maintenance session.
[b]Session termination process, timeoutsClosing of the maintenance connection when the work is done.

The caveat is that both ends have to hold: MFA to open and termination to close. A session protected by MFA but left open still leaves a standing path, and a session closed promptly but opened on a password alone is weakly defended. The assessor examines both, so MFA and termination both have to be present.

6Evidence

The satisfied version of 3.7.5 shows MFA-protected maintenance sessions that terminate when complete.

EvidenceWhat it demonstrates
Remote maintenance MFA configurationObjective [a]. Sessions require MFA to establish.
Session termination processObjective [b]. Sessions are closed when maintenance completes.

The evidence should show nonlocal maintenance sessions requiring MFA to open and terminated when complete. The MFA configuration and the termination process are the clearest demonstration, and because this control cannot sit on a plan of action, both have to be real at the time of assessment.

Remote maintenance should be hard to open and quick to close

Nonlocal maintenance is privileged access from outside the environment, so this five-point control requires MFA to establish it and termination when it is done. Configuring MFA on remote maintenance and closing sessions promptly is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.7.5[a] and 3.7.5[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.5 among the five-point derived security requirements. ecfr.gov
← Previous in Maintenance
MA.L2-3.7.4 · Check Media for Malicious Code
Next in Maintenance →
MA.L2-3.7.6 · Supervise Maintenance Personnel
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.5 · Edition 2026.1 · Last reviewed July 12, 2026