DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.9
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.9  Terminate Network Connections

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

SC.L2-3.13.9 requires that idle and ended network connections be closed. It requires that network connections associated with communications sessions be terminated at the end of the sessions or after a defined period of inactivity, so that connections do not remain open and available for misuse after their use has ended. It is a one-point requirement and may be deferred on a plan of action.

An open network connection that outlives its purpose is a standing opportunity: an abandoned session that is still connected can be resumed by someone else, and idle connections consume the boundary's attention. This control requires terminating connections at the end of their sessions or after a defined period of inactivity, so that connections close when done rather than lingering. The three assessment objectives are defining the inactivity period, terminating connections at session end, and terminating them after the defined period of inactivity.

The requirement · NIST SP 800-171 Rev 2, 3.13.9

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

The requirement pairs an event trigger with a time trigger: connections terminate at the end of a session, and also after a defined period of inactivity. The assessment objectives make explicit that the inactivity period is defined and that connections are terminated on either trigger. This ensures a connection does not persist indefinitely, whether the session ended cleanly or simply went idle.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.9 into three objectives: define the inactivity period, terminate connections at session end, and terminate connections after the defined period of inactivity.

[a]

A period of inactivity to terminate network connections associated with communications sessions is defined. The idle timeout is set.

MeetsA period of inactivity for terminating connections is defined.
FailsNo inactivity period is defined.
[b]

Network connections associated with communications sessions are terminated at the end of the sessions. Connections close when the session ends.

MeetsConnections are terminated at session end.
FailsConnections remain open after sessions end.
[c]

Network connections associated with communications sessions are terminated after the defined period of inactivity. Connections close on idle timeout.

MeetsConnections are terminated after the defined inactivity period.
FailsIdle connections persist past the defined period.

The three objectives are the defined period and the two termination triggers. The common gap is at objective [c], where connections are not actually closed on inactivity, so idle sessions persist. The assessor looks for a defined inactivity period and connections terminated on both triggers.

3Failure Patterns

The failures are about connections that linger.

No idle timeout

Connections that never time out on inactivity remain open indefinitely. A defined inactivity period and enforced timeout close them.

Sessions not terminated at end

Connections left open after a session ends remain available for resumption. Terminating at session end closes them.

Period defined but not enforced

An inactivity period on paper that the system does not enforce leaves connections open. The termination has to actually occur.

The common root
This control fails when connections are allowed to outlive their use. A session that ended or went idle but stays connected is a standing entry point that no one is watching, so leaving connections open trades a small convenience for a persistent exposure. Terminating on session end and inactivity closes that window.

4Ownership

This is an IT and network-owned control.

RoleResponsibility for this control
IT and networkConfigures session and connection termination on end and inactivity. Owns the configuration evidence.
Security or compliance leadDefines the inactivity period and confirms termination is enforced.
Program leadDocuments the defined inactivity period.
See also: This control complements the session controls of the access control family and the boundary protection of SC.L2-3.13.1.

5Tooling

The control is delivered by session and connection timeout configuration.

ObjectivesToolingWhat it provides
[a]Defined inactivity periodThe idle timeout value.
[b], [c]Session and connection timeout enforcementTermination at session end and after inactivity.

The caveat is that termination has to be enforced on both triggers. A defined period that the system ignores, or termination at session end without an idle timeout, leaves connections open. The assessor examines the defined period and enforced termination, so both objectives have to hold.

6Evidence

The satisfied version of 3.13.9 shows connections terminated on end and inactivity.

EvidenceWhat it demonstrates
Defined inactivity periodObjective [a]. The idle timeout.
Timeout configurationObjectives [b], [c]. Connections terminated on end and inactivity.

The evidence should show a defined inactivity period and connections terminated at session end or after that period. The defined period together with the timeout configuration is the clearest demonstration of the control.

A connection should close when its use ends

An open connection that outlives its session is a standing entry point, so this control asks that connections terminate at session end or after a defined inactivity period. Configuring that termination is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.9. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.9[a] through 3.13.9[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.8 · Encrypt CUI in Transit
Next in System and Communications Protection →
SC.L2-3.13.10 · Manage Cryptographic Keys
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.9 · Edition 2026.1 · Last reviewed July 12, 2026