CMMC 3.1.20 (External Systems): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.1.20 · CMMC Practice: AC.L2-3.1.20 · Updated June 2026
Plain-English answer
3.1.20 requires you to verify and control/limit connections to — and use of — external systems: personal/unmanaged devices, home networks, partner systems, and external cloud/SaaS that touch your environment. Identify them, verify they're authorized, and limit the connection and use (often by prohibiting CUI on them or routing through a managed enclave).
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment — especially anyone with remote work, BYOD, or contractor/partner access.
Why it matters
External systems are where CUI quietly leaks out of your boundary. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).
Control lineage
- CMMC Practice: AC.L2-3.1.20
- NIST 800-171 Rev. 2: §3.1.20 — verify and control/limit connections to and use of external systems.
- NIST 800-171A objectives: [a] connections to external systems are identified; [b] the use of external systems is identified; [c] connections to external systems are verified; [d] the use of external systems is verified; [e] connections to external systems are controlled/limited; [f] the use of external systems is controlled/limited.
What the assessor will EXAMINE
- Your list of external systems (partner/cloud/SaaS, personal devices) that connect to or use your environment.
- Policy on external systems / BYOD / remote access, and how it's enforced (conditional access, device compliance, VDI/enclave).
- Agreements or terms governing external/partner connections where applicable.
- SSP narrative for 3.1.20.
What the assessor will INTERVIEW & TEST
- Interview: "Can someone reach CUI from a personal laptop or a partner's system, and how is that controlled?" — name the enforcement (block, managed-device requirement, enclave).
- Test: Attempt access from an unmanaged/external system — confirm it's limited or denied.
- Test: Review the external-systems list against actual connections for unidentified ones.
Evidence examples (produce these)
- External-systems inventory (partner/cloud/SaaS + personal-device posture).
- External-system / BYOD / remote-access policy.
- Enforcement evidence — conditional access requiring managed/compliant devices, VDI/enclave config.
- Partner/cloud agreements where connections exist.
- SSP section 3.1.20 referencing the above.
Common failure patterns
- Personal devices can reach CUI with no control — objectives [e]/[f] fail.
- External cloud/SaaS connections never identified.
- A BYOD policy on paper that isn't technically enforced.
- Partner connections with no agreement or verification.
SPRS impact & POA&M
SPRS: 3.1.20 carries a weighted deduction (verify the exact value). POA&M: confirm 3.1.20's POA&M eligibility against current CMMC rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.1.20 when external systems (including personal devices and external cloud/SaaS) are identified and verified; access to CUI from them is controlled or denied with technical enforcement; agreements exist where connections do; and the SSP matches reality.
Worried CUI can leak to a personal laptop or partner system? Get an external-connections evidence map →
Related: 3.1.1 Access Control · All control pages · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.