CMMC 3.1.1 (Access Control): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.1.1 · CMMC Practice: AC.L2-3.1.1 · Updated June 2026
Plain-English answer
3.1.1 says: limit system access to authorized users, to processes acting on their behalf, and to authorized devices (including other systems). It has two halves the assessor will separate — you must identify who/what is authorized, and you must enforce the limit.
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment. It's the front door of the access-control family — if it's weak, much of AC unravels.
Why it matters
This is the baseline that decides whether only the right people, services, and machines can reach CUI. It's weighted heavily — a 5-point requirement under the DoD Assessment Methodology.
Control lineage
- CMMC Practice: AC.L2-3.1.1
- NIST 800-171 Rev. 2: §3.1.1 — limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
- NIST 800-171A objectives: [a] authorized users identified; [b] processes acting on behalf of authorized users identified; [c] authorized devices/systems identified; [d] access limited to authorized users; [e] access limited to authorized processes; [f] access limited to authorized devices/systems.
What the assessor will EXAMINE
- Account inventory / authorized-user list and the process that approves and provisions access.
- Service / machine account inventory (the "processes acting on behalf of users").
- Authorized-device list and how unknown devices are blocked (NAC, device compliance, conditional access).
- Access-control policy and the SSP narrative for 3.1.1.
- Joiner/mover/leaver records showing access is granted and revoked through a controlled process.
What the assessor will INTERVIEW
- "How do you decide who is authorized, and who approves it?" — point to the documented request/approval workflow.
- "What stops an unmanaged laptop from reaching CUI?" — name the enforcement (device compliance / conditional access / NAC).
- "Show me a recently offboarded user." — demonstrate timely revocation across systems.
What the assessor will TEST
- Attempt access from an unauthorized account or device — confirm it's denied.
- Sample current accounts against the authorized-user list for orphans or unapproved access.
- Verify a sampled service account is inventoried and scoped.
Evidence examples (produce these)
- Current authorized-user list with role/approval, dated within your freshness window.
- Service/machine-account inventory with owner and purpose.
- Authorized-device list + the enforcement policy that blocks the rest.
- Access request/approval and offboarding tickets (samples).
- SSP section 3.1.1 referencing the above by name.
Platform-specific
- Google Workspace: Admin Directory users/groups, context-aware access rules (device + user conditions), and Admin audit log of access changes.
- Microsoft GCC High / Entra ID: Entra users/groups, Conditional Access requiring compliant/hybrid-joined devices, and access reviews.
Common failure patterns
- Users are listed but service/machine accounts aren't — objective [b] fails.
- Devices never inventoried, so "authorized device" can't be demonstrated.
- Offboarding is manual and inconsistent — orphaned accounts surface in sampling.
- Policy says "authorized only" but there's no enforcement that actually blocks the unauthorized.
SPRS impact & POA&M
SPRS: not meeting 3.1.1 is a 5-point deduction. POA&M: POA&M eligibility for individual requirements is restricted under CMMC — confirm 3.1.1's eligibility against current rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.1.1 when authorized users, processes, and devices are each formally identified; access is enforced and demonstrably denies the unauthorized; joiner/mover/leaver is controlled; and your evidence matches the SSP.
Map your 3.1.1 evidence the way an assessor reads it. Get an access-control evidence map →
Related: 3.5.3 MFA evidence · All control pages · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.