Every Tunnel Is Evaluated Twice

A VPN protects the confidentiality and integrity of traffic in transit. It prevents a party positioned on the path from reading or altering what passes, and that is the whole of it. What a VPN does not do is restrict what travels through it. To an intruder who has compromised a machine on one end, the tunnel is simply a road, and an encrypted road is still a road. Ransomware propagating from a remote laptop into the plant network does not care that its traffic was beautifully encrypted on the way in.

The paper therefore evaluates every tunnel twice, once for the quality of its cryptography and once for the discipline of its flows, because an assessment does the same, and because an adversary only cares about the second. That framing runs through the three tunnels most contractors actually operate: the workforce remote access tunnel, the site to site tunnel between facilities, and the third party and vendor tunnels that rarely appear on any diagram.

The FIPS Question and the September Transition

When cryptography is used to protect the confidentiality of CUI, requirement 3.13.11 makes FIPS validation the gating issue, and three details decide the outcome. The cryptographic module must map to a certificate in the NIST Cryptographic Module Validation Program, and the certificate is specific to a module, a model family, and a firmware or software version. The device must be operating in its FIPS approved mode, a deliberate configuration state that must be enabled and that restricts the available algorithms. And private transport does not waive the obligation, because a leased line or carrier circuit is not under the contractor's physical protection between its endpoints.

The calendar item. FIPS 140-2 certificates remain valid through September 21, 2026. After that date, the Cryptographic Module Validation Program places every remaining 140-2 certificate on its Historical list. On November 10, 2026, Phase 2 of the CMMC program begins. Seven weeks separate the two dates, and a large share of the firewalls and VPN appliances deployed across the Defense Industrial Base hold FIPS 140-2 certificates today.

Historical is not Revoked. Nothing is revoked at the transition. NIST's guidance directs new procurements to FIPS 140-3 modules while permitting continued use of 140-2 modules in existing systems. What changes is what the certificate lookup returns on assessment day, and the difference between a documented posture and a discovered one is a paragraph in the SSP written before anyone asks.

Three Tunnels, Three Sets of Obligations

The workforce tunnel carries the largest population and the longest list of requirements: multifactor authentication for every user, monitored and controlled sessions, managed access control points as the only entry, split tunneling prevented, connections and sessions that terminate rather than idle overnight, and remote users placed in segments scoped to their roles rather than on the flat internal network. The endpoint on the far end is in scope, which means it must be a contractor managed device, and the technical controls need a written counterpart, a remote access policy defining what may and may not be done during a session, acknowledged by every user, because a rule nobody signed is a rule the assessor cannot credit.

The site to site tunnel between facilities is a scoping decision wearing an engineering disguise. If the tunnel carries all traffic without restriction, the two facilities are one environment and every asset in both buildings falls inside the assessment boundary. The paper works the problem on concrete equipment: two commodity carriers, a SonicWall firewall at each end, and the trap specific to that build, where the platform by default creates access rules permitting all traffic between the tunneled networks and quietly rebuilds the flat network inside the encryption. The assessor evaluating flow control does not read the tunnel status page. The assessor reads the access rules, and those rules either name the flows or they do not.

The third category is the one that damages assessments: the persistent tunnel to a sister company, the machine tool vendor's standing remote access, the managed service provider's management plane, the legacy link nobody tore down. Each is an external system connection that must be identified, restricted, or removed before the assessment is scheduled, and there is no documentation strategy that substitutes for any of the three.

If It Is Not Logged, It Did Not Happen

Every claim about a tunnel is a claim about events, and under CMMC the only acceptable proof of an event is a log record. The paper's logging section covers what must be captured for each tunnel, authentication successes and failures with per user traceability, the traffic the rule set denied, vendor session terminations, and every administrative change to the appliances themselves, along with where the records must live, since an appliance buffer that overwrites itself in hours is not retention. Logs are the one control that cannot be remediated retroactively, and an assessor sampling the review period will ask for records spanning months, which means the organization that turns on comprehensive VPN logging today is buying evidence it cannot purchase at any price the week before the assessment.

The Five Question Tunnel Audit

For an executive who wants to know where the organization stands, the audit takes one meeting and five questions. How many tunnels do we have, counting the vendor and provider connections nobody drew. For each one, can we produce the CMVP certificate number and show FIPS mode enabled. Does every remote user pass multifactor authentication through a managed gateway on a company managed device with split tunneling prevented. For the site to site links, can we name every flow the rule set permits and show the deny beneath them. And who controls each termination point, us or a provider, and where is that written down. An organization that answers all five cleanly has done the work. An organization that answers with the word VPN has found its remediation plan.

Download the Full White Paper

The full twelve page paper covers the FIPS validation mechanics and the September 2026 transition, the complete requirements for workforce, facility, and third party tunnels, the SonicWall worked example across two commodity carriers, the VDI and External Service Provider scoping nuances, the logging and review obligations, and an evidence table mapping each artifact to its NIST SP 800-171 Revision 2 requirements. Every control number in the paper links directly to its control page in the CMMC Controls library.

Download PDF →
Related

The CMMC Decision, Second Edition

Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.

Read More →