October 07, 2026
What Evidence Satisfies Access Control Requirement 3.1.1?
Your assessor wants proof that only authorized users, processes, and devices can reach your systems.
What requirement 3.1.1 asks for
Requirement 3.1.1 comes from the National Institute of Standards and Technology (NIST) Special Publication 800-171 Rev 2. NIST SP 800-171 Rev 2
Limit system access to authorized users, processes acting on behalf of authorized users, or devices (including other systems).
The requirement protects Controlled Unclassified Information (CUI) in nonfederal systems and organizations. That makes it foundational for contractors handling CUI under the Cybersecurity Maturity Model Certification (CMMC) program. It treats users and their processes as active subjects, while devices, files, and domains are passive objects. The focus is account management for systems and applications. Finer questions about which transactions a user may execute belong to requirement 3.1.2, not this one.
How assessors check it
The companion guide, NIST SP 800-171A, defines how each requirement is assessed. Its full title is Assessing Security Requirements for Controlled Unclassified Information. NIST SP 800-171A
It splits 3.1.1 into six assessment objectives, labeled 3.1.1[a] through 3.1.1[f]. The first three check that authorized users, their processes, and authorized devices are identified. The last three check that system access is limited to those same users, processes, and devices.
Assessors use three methods: Examine, Interview, and Test. Examine means reviewing documents, records, and configurations. Interview means questioning the people who manage accounts. Test means exercising the account management processes and mechanisms. Plan to produce evidence for all three methods.
Gathering evidence for the Examine method
Start with these records, because they form the core of your evidence package. Each item below is one of the assessment objects named for 3.1.1 in NIST SP 800-171A.
- Access control policy
- Account management procedures
- System security plan
- System design documentation
- System configuration settings and associated documentation
- List of active accounts, each tied to a named individual
- Records of transferred, separated, or terminated employees
- List of conditions for group and role membership
- List of recently disabled accounts, each tied to a named individual
- Access authorization records
- Account management compliance reviews
- System monitoring records
- System audit logs and records
- List of devices and systems authorized to connect
Pull the account list from your identity system and match every entry to a person. Flag service accounts and note the owner or process each one supports. Save the human resources records that show access ended when employment ended. Export the configuration settings that enforce access limits, with screenshots or reports. Keep the audit logs that show logon decisions, both allowed and denied.
Preparing for the Interview method
Assessors will talk with account management staff, system or network administrators, and information security personnel. These are the interview objects named for 3.1.1. NIST SP 800-171A
Make sure each person can describe the account lifecycle from request to removal. They should explain how approvals are recorded and who may approve access. Keep their answers consistent with the written procedures. If the procedure says accounts are reviewed quarterly, the reviewers should be able to describe the last review.
Preparing for the Test method
The test objects for 3.1.1 are your account management processes and the mechanisms that implement them. Assessors may exercise them directly. NIST SP 800-171A
They might watch a test account move through your approval steps. They might attempt access with a disabled account and expect a denial. Document your own tests of these processes before the assessment arrives. Record each test date, the steps taken, and the result.
Building the package in order
Follow this order when assembling evidence for 3.1.1.
- Write or update the access control policy and account management procedures.
- Export the active account list with the person tied to each account.
- Collect termination and transfer records with matching account disable dates.
- Gather the approvals behind each account, group, and role.
- Document the configuration settings that enforce the limits.
- Assemble audit logs and monitoring records that show the limits working.
- Build the authorized device and connected system list.
- Brief the people the assessor will interview, then run your own tests.
Name every file with the requirement number and the assessment method it supports.
Practical next steps
This week, export your active account list and match each account to a person. Next, confirm that every separated employee has a disabled account with a recorded date. Then document the approval behind each privileged account. Close the loop by testing one account creation and one account removal yourself.
For continuous, automated evidence collection evaluated against NIST 800-53 and NIST 800-171, see PolicyCortex at https://policycortex.com.
Sources
- NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-171r2
- NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171a.pdf