← Custodia
Practice 3 of 15·FAR 52.204-21(b)(1)(iii)·ACAccess Control

AC.L1-b.1.iii

Control connections to external systems

If your users connect from outside systems — personal laptops, home computers, a contractor's machine, a public Wi-Fi network — you have to know about it and control it. Don't let arbitrary external systems pull FCI out of your environment.

Official text

Verify and control/limit connections to and use of external information systems.

FAR 52.204-21(b)(1)(iii), CMMC Level 1 v2.13 Assessment Guide

What evidence satisfies this

Any one of these, by itself, won't satisfy the practice — but showing a few of them together is what an assessor or a prime contractor expects to see:

  • A short policy that says "only company-managed devices may access FCI; personal devices must use the approved web portal only."
  • Conditional Access in M365 / Context-Aware Access in Google blocking unknown devices from reaching the FCI folder.
  • VPN configuration if remote workers connect to an on-prem file server.
  • A list of external SaaS systems that have your FCI (e.g. an accounting tool that processes invoices) and their security agreements.
  • Disabling email forwarding to external addresses in M365 / Workspace.

Common ways small shops fail this

  • Founders / owners working out of personal Macs that have never been enrolled in any management.
  • Auto-forwarding of project emails to a personal Gmail "so I can read on the road."
  • USB drives moving between the shop PC and someone's home machine.
  • Free / unmanaged cloud storage (personal Dropbox, iCloud) syncing FCI folders to non-company devices.
  • Subcontractors uploading FCI to their own SaaS tools without an agreement.

How to fix it in a weekend

  1. 1Disable email auto-forwarding to external domains in your tenant settings.
  2. 2Block personal-device access to the FCI folder via Conditional Access (M365 P1) or Context-Aware Access (Workspace).
  3. 3Issue or designate a specific company device for every person who works with FCI — even if it's their main laptop, just register it.
  4. 4Inventory every external SaaS tool that touches FCI; either get a written security agreement or stop using it.
  5. 5Add a two-sentence "no personal devices" line to your one-page boundary description.

FAQ

Does this mean I can't work from home?+

No. It means the device you work from has to be managed (a company laptop or a personal device you've enrolled) and the connection has to be controlled (VPN if you're hitting on-prem, or a managed cloud tenant if you're using SaaS). Working from a coffee shop on a managed laptop with MFA is fine.

Related references

Doing all 15 yourself? Use the checklist.

Custodia's free CMMC Level 1 checklist walks the same 15 requirements with a self-assessment workflow, generates your SSP and affirmation memo, and posts your SPRS score for you.

Open the checklist →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)