CMMC 3.1.20 (External Systems): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.1.20 · CMMC Practice: AC.L2-3.1.20 · Updated June 2026

    Plain-English answer

    3.1.20 requires you to verify and control/limit connections to — and use of — external systems: personal/unmanaged devices, home networks, partner systems, and external cloud/SaaS that touch your environment. Identify them, verify they're authorized, and limit the connection and use (often by prohibiting CUI on them or routing through a managed enclave).

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment — especially anyone with remote work, BYOD, or contractor/partner access.

    Why it matters

    External systems are where CUI quietly leaks out of your boundary. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: AC.L2-3.1.20
    • NIST 800-171 Rev. 2: §3.1.20 — verify and control/limit connections to and use of external systems.
    • NIST 800-171A objectives: [a] connections to external systems are identified; [b] the use of external systems is identified; [c] connections to external systems are verified; [d] the use of external systems is verified; [e] connections to external systems are controlled/limited; [f] the use of external systems is controlled/limited.

    What the assessor will EXAMINE

    • Your list of external systems (partner/cloud/SaaS, personal devices) that connect to or use your environment.
    • Policy on external systems / BYOD / remote access, and how it's enforced (conditional access, device compliance, VDI/enclave).
    • Agreements or terms governing external/partner connections where applicable.
    • SSP narrative for 3.1.20.

    What the assessor will INTERVIEW & TEST

    • Interview: "Can someone reach CUI from a personal laptop or a partner's system, and how is that controlled?" — name the enforcement (block, managed-device requirement, enclave).
    • Test: Attempt access from an unmanaged/external system — confirm it's limited or denied.
    • Test: Review the external-systems list against actual connections for unidentified ones.

    Evidence examples (produce these)

    • External-systems inventory (partner/cloud/SaaS + personal-device posture).
    • External-system / BYOD / remote-access policy.
    • Enforcement evidence — conditional access requiring managed/compliant devices, VDI/enclave config.
    • Partner/cloud agreements where connections exist.
    • SSP section 3.1.20 referencing the above.

    Common failure patterns

    • Personal devices can reach CUI with no control — objectives [e]/[f] fail.
    • External cloud/SaaS connections never identified.
    • A BYOD policy on paper that isn't technically enforced.
    • Partner connections with no agreement or verification.

    SPRS impact & POA&M

    SPRS: 3.1.20 carries a weighted deduction (verify the exact value). POA&M: confirm 3.1.20's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.1.20 when external systems (including personal devices and external cloud/SaaS) are identified and verified; access to CUI from them is controlled or denied with technical enforcement; agreements exist where connections do; and the SSP matches reality.

    Worried CUI can leak to a personal laptop or partner system? Get an external-connections evidence map →

    Related: 3.1.1 Access Control · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.