AC.L1-b.1.iii
Control connections to external systems
If your users connect from outside systems — personal laptops, home computers, a contractor's machine, a public Wi-Fi network — you have to know about it and control it. Don't let arbitrary external systems pull FCI out of your environment.
Official text
“Verify and control/limit connections to and use of external information systems.”
— FAR 52.204-21(b)(1)(iii), CMMC Level 1 v2.13 Assessment Guide
What evidence satisfies this
Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:
- ✓A short policy that says "only company-managed devices may access FCI; personal devices must use the approved web portal only."
- ✓Conditional Access in M365 / Context-Aware Access in Google blocking unknown devices from reaching the FCI folder.
- ✓VPN configuration if remote workers connect to an on-prem file server.
- ✓A list of external SaaS systems that have your FCI (e.g. an accounting tool that processes invoices) and their security agreements.
- ✓Disabling email forwarding to external addresses in M365 / Workspace.
Common ways small shops fail this
- ✗Founders / owners working out of personal Macs that have never been enrolled in any management.
- ✗Auto-forwarding of project emails to a personal Gmail "so I can read on the road."
- ✗USB drives moving between the shop PC and someone's home machine.
- ✗Free / unmanaged cloud storage (personal Dropbox, iCloud) syncing FCI folders to non-company devices.
- ✗Subcontractors uploading FCI to their own SaaS tools without an agreement.
How to fix it in a weekend
- 1Disable email auto-forwarding to external domains in your tenant settings.
- 2Block personal-device access to the FCI folder via Conditional Access (M365 P1) or Context-Aware Access (Workspace).
- 3Issue or designate a specific company device for every person who works with FCI — even if it's their main laptop, just register it.
- 4Inventory every external SaaS tool that touches FCI; either get a written security agreement or stop using it.
- 5Add a two-sentence "no personal devices" line to your one-page boundary description.
FAQ
Does this mean I can't work from home?+
No. It means the device you work from has to be managed (a company laptop or a personal device you've enrolled) and the connection has to be controlled (VPN if you're hitting on-prem, or a managed cloud tenant if you're using SaaS). Working from a coffee shop on a managed laptop with MFA is fine.
Related references
Doing all 15 yourself? Use the checklist.
Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.
Open the checklist →