CMMC 3.13.1 (Boundary Protection): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.13.1 · CMMC Practice: SC.L2-3.13.1 · Updated June 2026
Plain-English answer
3.13.1 requires you to monitor, control, and protect communications at the external boundary of your system and at key internal boundaries. Three verbs, two places: you watch what crosses (monitor), you allow/deny traffic deliberately (control), and you safeguard it in transit (protect) — at the internet edge and at important internal segmentation points like a CUI enclave.
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment. It's foundational — boundary protection is what makes your CUI scope defensible in the first place.
Why it matters
Your boundary is your scope. A well-defined, monitored, controlled boundary is what lets you argue the rest of the network is out of scope; a fuzzy one drags everything in. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).
Control lineage
- CMMC Practice: SC.L2-3.13.1
- NIST 800-171 Rev. 2: §3.13.1 — monitor, control, and protect communications (information transmitted or received) at the external boundaries and key internal boundaries of organizational systems.
- NIST 800-171A objectives: [a] the external system boundary is defined; [b] key internal system boundaries are defined; [c] communications are monitored at the external boundary; [d] communications are monitored at key internal boundaries; [e] communications are controlled at the external boundary; [f] communications are controlled at key internal boundaries; [g] communications are protected at the external boundary; [h] communications are protected at key internal boundaries.
What the assessor will EXAMINE
- A network/boundary diagram showing the external boundary and key internal boundaries (CUI enclave, DMZ, management network).
- Firewall / gateway rule sets enforcing allowed traffic at each boundary (default-deny preferred).
- Monitoring at the boundary — IDS/IPS, firewall logging, NetFlow, or equivalent feeding your monitoring stack.
- Protection of communications crossing the boundary — TLS/VPN, content filtering, proxy.
- SSP narrative for 3.13.1 describing boundary definition and the controls at each.
What the assessor will INTERVIEW & TEST
- Interview: "Walk me through your boundary — where's the edge, what internal boundaries protect CUI, and how is each monitored and controlled?" — point to the diagram + rule sets + monitoring.
- Test: Review firewall rules for a default-deny posture and justified exceptions at both external and key internal boundaries.
- Test: Confirm boundary devices are actually logging/monitored (sample alerts or log flow), not just deployed.
Evidence examples (produce these)
- Current network diagram with the external boundary and key internal boundaries labeled.
- Firewall/gateway rule export (perimeter and internal segmentation) showing controlled traffic.
- Monitoring evidence at the boundary — IDS/IPS config and sample alerts, firewall log forwarding.
- Encryption/filtering config for communications crossing the boundary (VPN, TLS inspection, proxy).
- SSP section 3.13.1 referencing the above by name.
Common failure patterns
- Perimeter firewall exists, but no key internal boundary around the CUI enclave — objectives [b]/[d]/[f]/[h] fail.
- Boundary devices deployed but not monitored — control and protect without monitor.
- Permissive "any/any" rules that don't actually control communications.
- A network diagram that doesn't match the live configuration.
SPRS impact & POA&M
SPRS: 3.13.1 carries a weighted deduction (verify the exact value). POA&M: confirm 3.13.1's POA&M eligibility against current CMMC rules before assuming it can be deferred — boundary protection is foundational and is often expected to be in place.
Assessor-ready summary
You're good on 3.13.1 when the external boundary and key internal boundaries are defined and diagrammed; traffic is controlled at each with a default-deny posture; communications crossing are monitored and protected; and the SSP and diagram match the live configuration.
Is your CUI enclave really a boundary, or just a subnet? Get a boundary-protection evidence map →
Related: 3.13.11 FIPS Cryptography · 3.1.20 External Systems · All control pages
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.