Frameworks / CMMC 2.0 / SC.L2-3.13.1 CMMC 2.0
System and Communications Protection
CMMC 2.0 SC.L2-3.13.1: Boundary Protection Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 64 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy ASBv3-GS-4 Define and implement network security strategy ASBv3-NS-6 Deploy web application firewall LT-4 Enable network logging for security investigation NS-1 Establish network segmentation boundaries NS-2 Secure cloud services with network controls NS-3 Deploy firewall at the edge of enterprise network ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-13.10 Perform Application Layer Filtering CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-13.9 Deploy Port-Level Access Control CIS-4.4 Implement and Manage a Firewall on Servers ASD37-07 Web content filtering (Excellent) ASD37-08 Deny direct internet connectivity (Excellent) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-32 Network-based IDS/IPS (Limited) SC-7 Boundary Protection SC-7(3) Access Points SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SC-7 Boundary Protection SC-7(3) Access Points SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers 1.3.1 1.3.1 Inbound CDE traffic restricted 1.3.2 1.3.2 Outbound CDE traffic restricted 1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside C5-COS-01 Technical safeguards C5-COS-02 Security requirements for connections in the Cloud Service Provider's network C5-COS-04 Cross-network access 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks CE-FW.1 Boundary Firewalls Deployed CE-FW.4 Approve and Document Inbound Rules AUCDR-IS-2 Secure the network and systems within the data environment 6.10.1 Network security management NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in System and Communications Protection You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 SC.L2-3.13.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.