CMMC 3.1.1 (Access Control): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.1.1 · CMMC Practice: AC.L2-3.1.1 · Updated June 2026

    Plain-English answer

    3.1.1 says: limit system access to authorized users, to processes acting on their behalf, and to authorized devices (including other systems). It has two halves the assessor will separate — you must identify who/what is authorized, and you must enforce the limit.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment. It's the front door of the access-control family — if it's weak, much of AC unravels.

    Why it matters

    This is the baseline that decides whether only the right people, services, and machines can reach CUI. It's weighted heavily — a 5-point requirement under the DoD Assessment Methodology.

    Control lineage

    • CMMC Practice: AC.L2-3.1.1
    • NIST 800-171 Rev. 2: §3.1.1 — limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
    • NIST 800-171A objectives: [a] authorized users identified; [b] processes acting on behalf of authorized users identified; [c] authorized devices/systems identified; [d] access limited to authorized users; [e] access limited to authorized processes; [f] access limited to authorized devices/systems.

    What the assessor will EXAMINE

    • Account inventory / authorized-user list and the process that approves and provisions access.
    • Service / machine account inventory (the "processes acting on behalf of users").
    • Authorized-device list and how unknown devices are blocked (NAC, device compliance, conditional access).
    • Access-control policy and the SSP narrative for 3.1.1.
    • Joiner/mover/leaver records showing access is granted and revoked through a controlled process.

    What the assessor will INTERVIEW

    • "How do you decide who is authorized, and who approves it?" — point to the documented request/approval workflow.
    • "What stops an unmanaged laptop from reaching CUI?" — name the enforcement (device compliance / conditional access / NAC).
    • "Show me a recently offboarded user." — demonstrate timely revocation across systems.

    What the assessor will TEST

    • Attempt access from an unauthorized account or device — confirm it's denied.
    • Sample current accounts against the authorized-user list for orphans or unapproved access.
    • Verify a sampled service account is inventoried and scoped.

    Evidence examples (produce these)

    • Current authorized-user list with role/approval, dated within your freshness window.
    • Service/machine-account inventory with owner and purpose.
    • Authorized-device list + the enforcement policy that blocks the rest.
    • Access request/approval and offboarding tickets (samples).
    • SSP section 3.1.1 referencing the above by name.

    Platform-specific

    • Google Workspace: Admin Directory users/groups, context-aware access rules (device + user conditions), and Admin audit log of access changes.
    • Microsoft GCC High / Entra ID: Entra users/groups, Conditional Access requiring compliant/hybrid-joined devices, and access reviews.

    Common failure patterns

    • Users are listed but service/machine accounts aren't — objective [b] fails.
    • Devices never inventoried, so "authorized device" can't be demonstrated.
    • Offboarding is manual and inconsistent — orphaned accounts surface in sampling.
    • Policy says "authorized only" but there's no enforcement that actually blocks the unauthorized.

    SPRS impact & POA&M

    SPRS: not meeting 3.1.1 is a 5-point deduction. POA&M: POA&M eligibility for individual requirements is restricted under CMMC — confirm 3.1.1's eligibility against current rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.1.1 when authorized users, processes, and devices are each formally identified; access is enforced and demonstrably denies the unauthorized; joiner/mover/leaver is controlled; and your evidence matches the SSP.

    Map your 3.1.1 evidence the way an assessor reads it. Get an access-control evidence map →

    Related: 3.5.3 MFA evidence · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.