Example, read only. A sample account that shows what finished CMMC looks like.
Safeguard 3 of 15 · AC.L1-b.1.iii
AC.L1-3.1.20 · FAR 52.204-21 (b)(1)(iii) · NIST SP 800-171 3.1.20
Verify and control/limit connections to and use of external information systems
Control what outside systems (personal laptops, vendor tools, random cloud apps) can connect to yours.
For small contractors this usually means personal devices and SaaS tools touching contract info. A written list of external connections plus a short use policy is the control, not a zero-trust deployment.
Capture: Screenshot of external collaboration settings plus the guest-user list.
There are no public terminals or shared logins. The one shop floor estimating PC signs in with the same managed accounts and connects to the tenant over the company VPN only. No external system connects into the Federal Programs tenant.
You answer in plain English; Charlie writes the official narrative for your System Security Plan.
This is one of 15
Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.