DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.7
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.7  Prevent Split Tunneling

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

SC.L2-3.13.7 closes the split-tunneling gap for remote devices. It requires that remote devices be prevented from simultaneously establishing a non-remote connection with organizational systems and communicating via some other connection to external networks, so that a remote device cannot bridge the organization's network to the outside. It is a one-point requirement and may be deferred on a plan of action.

When a remote device is connected to the organization's network and at the same time to an external network, it can become a bridge between the two, letting external traffic reach the internal network through the device. This split-tunneling condition undermines the boundary protections the organization relies on. This control requires preventing that simultaneous configuration, so a device connected to organizational systems routes through the organization's protections rather than tunneling around them. The single assessment objective is that split tunneling is prevented.

The requirement · NIST SP 800-171 Rev 2, 3.13.7

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

The requirement is to prevent the split-tunneling condition: a remote device holding a connection into organizational systems while also communicating to external networks by another path. Preventing it means the remote connection is configured so that the device's traffic to external resources does not bypass the organization's network protections, typically by forcing all traffic through the organization's controlled path while the remote connection is active.

2The Assessment Objective

NIST SP 800-171A frames 3.13.7 as a single objective: prevent split tunneling.

Remote devices are prevented from simultaneously establishing a non-remote connection with the system and communicating via some other connection to external networks (split tunneling). Remote devices cannot bridge internal and external networks.

MeetsSplit tunneling is prevented, so remote devices route through the organization's protections.
FailsRemote devices can hold an internal connection while communicating externally by another path.

The single objective is preventing split tunneling. The common gap is remote-access configurations that permit local internet access while connected, leaving the bridge open. The assessor looks for configuration that prevents the simultaneous condition.

3Failure Patterns

The failures are about remote devices bridging networks.

Split tunneling allowed by default

Remote-access configurations that let a connected device also use its local internet connection leave the split-tunnel path open. Forcing traffic through the organization's path prevents it.

Configuration not enforced on devices

A policy against split tunneling that devices do not actually enforce leaves the condition possible. The prevention has to be enforced in the remote-access configuration.

Inconsistent across remote access methods

Preventing split tunneling on one remote-access method but not others leaves gaps. The prevention has to cover the remote access in use.

The common root
This control fails when remote convenience is allowed to bypass the boundary. Split tunneling exists because letting a remote device use its local connection is convenient, but that convenience turns the device into a bridge around the organization's protections. Preventing the simultaneous condition keeps remote traffic inside the controlled path.

4Ownership

This is a network and IT-owned control tied to remote access configuration.

RoleResponsibility for this control
Network and ITConfigures remote access to prevent split tunneling. Owns the remote-access configuration.
Security or compliance leadConfirms the prevention is enforced across remote access methods.
Program leadDocuments the remote access configuration.
See also: This control protects the boundary of SC.L2-3.13.1 and works with the remote access controls of the access control family.

5Tooling

The control is delivered by remote-access configuration that forces traffic through the controlled path.

ObjectiveToolingWhat it provides
VPN full-tunnel configurationAll remote traffic routed through the organization's protections.
Endpoint remote-access policy enforcementThe split-tunnel condition prevented on the device.

The caveat is that the prevention has to be enforced in configuration, not just stated in policy, and cover the remote access in use. A device that can still split-tunnel despite policy leaves the bridge open. The assessor examines whether split tunneling is prevented, so the configuration has to enforce it.

6Evidence

The satisfied version of 3.13.7 shows remote access that prevents split tunneling.

EvidenceWhat it demonstrates
Remote access configurationThe objective. Split tunneling prevented.
Endpoint policy enforcementThe objective. The prevention enforced on devices.

The evidence should show remote-access configuration that prevents a device from bridging internal and external networks. The remote access configuration and endpoint enforcement are the clearest demonstration of the control.

A remote device should not bridge inside and outside

Split tunneling turns a connected remote device into a path around your boundary protections, so this control asks that the simultaneous condition be prevented. Configuring remote access to keep traffic inside the controlled path is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.7. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.13.7. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.6 · Deny by Default
Next in System and Communications Protection →
SC.L2-3.13.8 · Encrypt CUI in Transit
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.7 · Edition 2026.1 · Last reviewed July 12, 2026