DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.15
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.15  Protect Communications Session Authenticity

Protect the authenticity of communications sessions.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
OnePer NIST SP 800-171A

1Overview

SC.L2-3.13.15 protects communications sessions from being hijacked or forged. It requires that the authenticity of communications sessions be protected, so that a session between systems or users cannot be impersonated, injected into, or taken over by an attacker. It is a five-point requirement that cannot be deferred on a plan of action.

Encrypting a session protects its confidentiality, but authenticity is a distinct property: the assurance that the session is genuinely with the intended party and has not been hijacked or tampered with mid-stream. Attacks such as session hijacking and man-in-the-middle exploit weak session authenticity. This control requires protecting that authenticity, typically through mechanisms that establish and verify the identity of session endpoints and protect the integrity of the session, so a session cannot be forged or taken over. Its five-point weight reflects that a hijacked session can bypass the protections around it. The single assessment objective is that the authenticity of communications sessions is protected.

The requirement · NIST SP 800-171 Rev 2, 3.13.15

Protect the authenticity of communications sessions.

The requirement is to protect the authenticity of communications sessions. In practice this is achieved through session authentication and integrity mechanisms, such as authenticated and integrity-protected protocols like TLS with proper certificate validation, that ensure a session is with the genuine party and cannot be hijacked or injected into. The single assessment objective is that this authenticity is protected.

2The Assessment Objective

NIST SP 800-171A frames 3.13.15 as a single objective: protect the authenticity of communications sessions.

The authenticity of communications sessions is protected. Sessions cannot be forged, hijacked, or injected into.

MeetsSession authenticity is protected through authentication and integrity mechanisms.
FailsSessions can be hijacked, impersonated, or tampered with.

The single objective is protecting session authenticity. The common gap is reliance on protocols or configurations that encrypt but do not adequately authenticate the session or protect its integrity. The assessor looks for mechanisms that protect the authenticity of sessions, not just their confidentiality.

3Failure Patterns

The failures are about sessions that can be forged or taken over.

No session authentication

Sessions without endpoint authentication can be impersonated. Authenticating the session parties protects its authenticity.

Weak certificate validation

Encrypted sessions that do not properly validate certificates are open to man-in-the-middle attacks. Proper validation protects authenticity.

Session integrity not protected

Sessions whose integrity is not protected can be injected into mid-stream. Integrity protection keeps the session genuine throughout.

The common root
This control fails when confidentiality is mistaken for authenticity. Encrypting a session hides its contents but does not by itself prove who is on the other end or keep the session from being hijacked, so a session can be private yet forged. Protecting authenticity, through authentication and integrity, is what makes the session genuinely trustworthy.

4Ownership

This is an IT and network-owned technical control.

RoleResponsibility for this control
IT and networkImplements session authentication and integrity protection. Owns the configuration evidence.
System architectsSelect protocols and configurations that protect session authenticity.
Security or compliance leadConfirms session authenticity is protected across communications.
See also: This control complements the transit encryption of SC.L2-3.13.8 and the boundary protection of SC.L2-3.13.1.

5Tooling

The control is delivered by authenticated, integrity-protected session protocols.

ObjectiveToolingWhat it provides
authenticateTLS with certificate validation, mutual authenticationVerified session endpoints.
protect integrityIntegrity-protected session protocolsSessions that cannot be injected into or hijacked.

The caveat is that the mechanisms have to protect authenticity, not merely confidentiality. Encrypted sessions with weak authentication or certificate validation remain open to hijacking. The assessor examines whether session authenticity is protected, so the authentication and integrity mechanisms have to hold.

6Evidence

The satisfied version of 3.13.15 shows protected session authenticity.

EvidenceWhat it demonstrates
Session protocol configurationThe objective. Sessions authenticated and integrity-protected.
Certificate validation settingsThe objective. Session endpoints verified.

The evidence should show communications sessions protected through authentication and integrity mechanisms. The session protocol configuration together with certificate validation settings is the clearest demonstration, and because this control cannot sit on a plan of action, the protection has to be real at the time of assessment.

A private session can still be a forged one

Encryption hides a session's contents but does not prove who is on the other end, so this five-point control asks that session authenticity be protected against hijacking and impersonation. Implementing authenticated, integrity-protected sessions is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.15. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.15. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SC.L2-3.13.15 among the five-point derived security requirements. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.14 · Control and Monitor VoIP
Next in System and Communications Protection →
SC.L2-3.13.16 · Protect CUI at Rest
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.15 · Edition 2026.1 · Last reviewed July 12, 2026