SKIP TO CONTENT

PROGRAM-BUILD DOMAIN 03 OF 05

Access control

Account lifecycle and least privilege; separation of duties; multi-factor authentication; remote and session controls; physical and visitor controls for CUI areas; foreign-national gating.

PRIMARY PUBLIC REFERENCES

NIST SP 800-171 Rev.2 AC, IA, and PE families; contract-specific U.S.-person requirements.

STANDING BOUNDARY
Implemented and evidenced only. No claim without an operating control behind it.
CURRENT CMMC POSTURE
CMMC Phase II (Level 2 and Level 3 third-party assessments) has been suspended since 2026-07-13 pending the Department of War reform review, and contracting officers were directed on 2026-09-03 to remove Phase II requirements from solicitations and contracts. Level 1 and Level 2 self-assessments, baseline NIST SP 800-171 Revision 2 compliance, SPRS, and the DFARS 252.204-7012 safeguarding obligation remain in force. CMMC work is quoted only after the current-posture check.

SCOPE THE DOMAIN

Does this pursuit need access control?

Domains fire only when the route, the target contract, or an evidence gap justifies the spend. We will tell you if it does not.

A 30-minute introductory call. Bring the target solicitation and what you already know about your gaps.

VOSB + SDVOSB CERTIFIED (SBA VETCERT) · UEI VU2HV8458J93 · CAGE 21BA0