top of page

CMMC Access Control: Where Physical Meets Cyber

Writer: kate frese
kate frese
Sep 13
2 min read

Under the Cybersecurity Maturity Model Certification (CMMC) framework, the Access Control (AC) family doesn't stop at the network boundary. When someone walks through a controlled door into a space housing Controlled Unclassified Information (CUI), cyber access boundaries move with them — no firewall changes that. For federal facilities, that makes the Physical Access Control System (PACS) part of the access control posture, not a facilities afterthought.


The AC Family Beyond the Digital Boundary

NIST SP 800-53 ties the AC family directly to physical protections — PE-2, PE-3, and AC-3 all depend on the physical perimeter doing its job. Door controllers, card readers, intrusion detection, and video surveillance generate real-time telemetry that validates identity before anyone reaches a server room, SCIF, or CUI storage area. When physical controls fail to enforce least privilege at the door, every downstream cyber safeguard inherits that exposure.


Badges Are Identity Infrastructure

PIV and CAC credentials built to FIPS 201-2 and HSPD-12 are high-assurance identity documents — but only if the PACS actually validates them. A modern reader checks the certificate on the badge against federal revocation lists in real time; a swipe then generates an authenticated audit record, not just a door latch. Feed those records into a SIEM and the badge becomes a cyber-physical signal: an employee badging into the facility while their account logs in from offsite is an anomaly worth flagging.


Tailgating Is a Control Failure, Not a Policy Problem

Under CMMC assessment, tailgating is a failure of the AC and PE control families — user-awareness training doesn't close it. Engineering controls do: optical turnstiles, anti-passback rules, dual-custody portals, and video analytics that detect tailgating events. Done right, a tailgating violation triggers alerts, visual alarms, and can temporarily suspend the involved credential's logical access until security clears it.


Map Clearances, Automate Revocation

Access rights must track personnel status in real time. A static access matrix leaves orphaned credentials on doors and in systems after a contract ends or a clearance expires. Rule-based policies aligned with NIST SP 800-53 let the PACS revoke badge and logical access together, automatically, the moment a clearance or tasking changes — closing the manual-lag gap that assessors look for.


The Bottom Line

CMMC access control is one boundary with two faces, and it holds only when physical and cyber are engineered together. Blue Violet Security, LLC is an SBA-Certified Veteran-Owned Small Business (VOSB) specializing in physical security integration. Schedule a Consultation at bluevioletsecurity.com.


This content is provided for general informational purposes only and does not constitute legal or regulatory advice. Compliance requirements and regulations are subject to change. Blue Violet Security, LLC recommends consulting with appropriate legal and regulatory counsel before making compliance determinations.

Comments


bottom of page