Quick Answer: In today's interconnected global landscape, securing Controlled Unclassified Information (CUI) is paramount for defense contractors, DoD subcontractors, and any organization collaborating with government agencies worldwide. Jun Cyber specializes in guiding businesses across the US, UK, Australia, and Europe through the complexities of CMMC Level 2 compliance, particularly addressing the critical control SC.L2-3.13.7 concerning split tunneling. We provide expert strategies and solutions to prevent unauthorized data exposure, maintain the integrity of your secure networks, and safeguard your eligibility for crucial government contracts.
⚡ TL;DR — Key Takeaways
- CMMC SC.L2-3.13.7 (NIST 800-171 3.13.7) mandates strict control over split tunneling to protect CUI.
- Uncontrolled split tunneling poses a significant risk of CUI exposure and can lead to CMMC audit failures.
- Jun Cyber provides expert, globally-aware solutions for implementing compliant remote access and VPN configurations.
- Achieving compliance often involves enforcing full tunneling or tightly managing exceptions, balancing security with operational needs.
- Proactive SC.L2-3.13.7 compliance is critical for securing defense contracts and maintaining data integrity for organizations worldwide.
The Challenge
For organizations handling Controlled Unclassified Information (CUI), compliance with CMMC Level 2 is not just a regulatory hurdle—it's a foundational pillar of trust and operational security. The NIST SP 800-171 control 3.13.7, directly translated into CMMC Level 2's SC.L2-3.13.7, specifically mandates the prevention of unauthorized circumvention of network security controls through split tunneling. This seemingly technical detail often becomes a significant compliance roadblock, leading to substantial risks and operational inefficiencies across diverse global environments.
- Lack of Clear Documentation: Demonstrating compliance requires not just technical implementation but also robust policies, procedures, and evidence that can withstand rigorous audits.
The Solution
Jun Cyber provides a comprehensive, globally-aware solution designed to demystify and implement robust controls for SC.L2-3.13.7, ensuring your organization achieves and maintains CMMC Level 2 compliance. Our expert team understands the intricate balance between security imperatives and operational realities, delivering tailored strategies that are effective and sustainable. We begin with a meticulous assessment of your current remote access infrastructure, identifying specific vulnerabilities related to split tunneling and providing clear, actionable recommendations. Our approach moves beyond merely disabling split tunneling; we help you architect a secure remote access environment that fully encapsulates CUI within your trusted network boundaries. This includes developing and implementing policies that govern VPN usage, configuring network devices and endpoint security solutions to enforce full tunneling, or establishing strictly controlled and monitored exceptions where absolutely necessary and compliant. Our deep expertise in NIST SP 800-171 and CMMC allows us to translate complex requirements into practical, implementable solutions. With Jun Cyber, you gain a trusted partner equipped to navigate the global landscape of cybersecurity regulations. We provide end-to-end support, from initial gap analysis and policy development to technical configuration, staff training, and continuous monitoring. Our goal is to empower your organization to confidently handle CUI, secure critical contracts, and demonstrate unwavering commitment to cybersecurity integrity, no matter where your operations are located. Get started with a free AI-powered consultation at ChatCMMC or schedule an assessment to solidify your compliance posture.
See how we can solve this for your organization
Secure Your CMMC Assessment TodayHow It Works
1. Comprehensive Discovery & Gap Analysis
Our process begins with a thorough assessment of your existing network architecture, remote access solutions, and current VPN configurations. We identify all instances where split tunneling might be present or inadvertently enabled, mapping these against the precise requirements of NIST SP 800-171 3.13.7 and CMMC SC.L2-3.13.7. This initial phase helps us understand your unique operational context and pinpoint specific areas requiring remediation.
2. Policy Development & Strategic Planning
Based on the discovery phase, we collaborate with your team to develop or refine organizational policies and procedures explicitly addressing split tunneling. This includes defining clear rules for remote access, VPN usage, and data routing, ensuring alignment with CMMC Level 2. We then craft a strategic implementation plan that minimizes operational disruption while maximizing security effectiveness, tailored to your global workforce and infrastructure.
3. Technical Implementation & Configuration Management
Our experts provide hands-on guidance and support for the technical implementation of controls. This involves configuring your VPN clients and servers to enforce full tunneling by default, or establishing highly controlled and monitored exceptions in accordance with CMMC guidelines. We assist with network segmentation, firewall rules, and endpoint security measures to ensure all CUI traffic remains within the secure tunnel, regardless of user location.
4. Validation, Documentation & Continuous Readiness
Once technical controls are in place, we rigorously validate their effectiveness through testing and verification. Crucially, we help you develop the comprehensive documentation required for CMMC audits, including system security plans (SSPs), policies, procedures, and evidence of implementation. Jun Cyber also provides ongoing support and guidance to maintain continuous compliance, adapting to evolving threats and regulatory updates, ensuring you are always audit-ready.
Key Statistics
Key Features of Jun Cyber's Split Tunneling Compliance Solution
✓ NIST & CMMC Control SC.L2-3.13.7 Expertise
Benefit from our deep understanding of NIST SP 800-171 control 3.13.7 and its CMMC Level 2 manifestation. We translate complex requirements into clear, actionable steps, ensuring your remote access policies and technologies fully align with the highest standards for CUI protection.
✓ Global Remote Access Security Architecture
Whether your team operates in the US, UK, Australia, Europe, or beyond, we design and implement secure remote access architectures that centralize CUI traffic, enforce full tunneling, and prevent unauthorized bypasses, ensuring consistent security posture across all geographical boundaries.
✓ Tailored VPN Configuration & Hardening
Receive expert assistance in configuring and hardening your VPN infrastructure (e.g., OpenVPN, IPsec, SSL VPNs) to strictly control or eliminate split tunneling. Our engineers optimize your VPN setup for both security and performance, ensuring CUI never leaves the protected tunnel.
✓ Comprehensive Policy & Documentation Support
We help you develop robust, audit-ready policies and procedures specifically for remote access, VPN usage, and split tunneling. This includes creating System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and evidentiary documentation vital for CMMC assessments.
✓ Endpoint Security & Device Compliance Integration
Integrate split tunneling controls with your broader endpoint security strategy. We ensure that devices accessing CUI environments are compliant, secure, and configured to respect tunneling requirements, adding another layer of defense against data exfiltration.
✓ Continuous Monitoring & Audit Readiness
Beyond initial implementation, we offer solutions for ongoing monitoring of network traffic and VPN logs to detect and respond to any attempts at split tunneling or unauthorized access. We help you maintain a state of continuous compliance, keeping you prepared for future audits and evolving threats.
Ready to put these capabilities to work?
Secure Your CMMC Assessment TodayKey Terms
- Controlled Unclassified Information (CUI)
- Information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy, but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended. This includes a wide range of sensitive government information.
- Split Tunneling
- A VPN feature that allows a device to simultaneously access resources on the private network through the VPN tunnel and other resources (e.g., the public internet) directly, bypassing the VPN for some traffic. This is generally considered a security risk for CUI.
- Full Tunneling
- A VPN configuration where all network traffic from the connected device, whether destined for the private network or the public internet, is routed through the secure VPN tunnel. This ensures all traffic is subject to the organization's security controls, offering a higher level of security.
Who Benefits from Robust Split Tunneling Controls?
- Defense Contractors & DoD Supply Chain Members — Organizations directly or indirectly supporting the US Department of Defense and other national defense agencies globally, requiring CMMC Level 2 certification to secure new contracts or retain existing ones. Robust SC.L2-3.13.7 compliance is non-negotiable for CUI handlers.
- International Organizations Handling CUI — Any firm, regardless of its primary location (US, UK, Australia, Europe), that handles or processes Controlled Unclassified Information in collaboration with government entities, needing to demonstrate a consistent and high level of cybersecurity maturity.
- Remote-First & Hybrid Workforces — Companies with a significant portion of their employees working remotely or in hybrid models, where VPN and secure remote access are critical. Ensuring CUI is protected from the vulnerabilities of uncontrolled split tunneling is vital for distributed teams.
- Organizations Seeking Enhanced Network Security — Beyond compliance, any organization committed to strengthening its overall network security posture, reducing data exfiltration risks, and improving control over outbound traffic, particularly when sensitive information is involved.
Frequently Asked Questions
What is 'split tunneling' in the context of CMMC SC.L2-3.13.7?
Split tunneling refers to a network configuration where a user connected to a Virtual Private Network (VPN) can simultaneously access resources on the VPN's private network (e.g., corporate servers) and the public internet directly, bypassing the VPN tunnel for internet-bound traffic. For CMMC Level 2 (NIST SP 800-171 3.13.7), this is a critical security concern. The control mandates preventing the unauthorized disclosure of CUI via split tunneling by ensuring that all network traffic, especially that related to CUI, flows through the secured VPN tunnel and is subject to organizational security controls.
Why is CMMC SC.L2-3.13.7 so important for organizations handling CUI?
SC.L2-3.13.7 is crucial because uncontrolled split tunneling creates a significant vulnerability for Controlled Unclassified Information (CUI). When some traffic bypasses the secure VPN tunnel, it also bypasses corporate firewalls, intrusion detection systems, and other security measures designed to protect CUI. This opens a direct path for data exfiltration, malware introduction, or unauthorized access to sensitive information. For defense contractors and their supply chain, non-compliance means a direct failure to protect CUI, risking contracts and national security interests.
Does CMMC Level 2 require me to disable split tunneling entirely?
While the strictest interpretation and best practice for CMMC Level 2 (NIST SP 800-171 3.13.7) often lean towards disabling split tunneling entirely (enforcing 'full tunneling'), the control itself states 'Prevent remote devices from simultaneously communicating with non-organizational systems using split tunneling.' This implies that any split tunneling must be strictly controlled and authorized, ensuring no CUI leaves the secure environment. In practice, achieving this level of control is challenging, making full tunneling the most straightforward and secure path to compliance for most organizations. Jun Cyber can help you determine the most appropriate and compliant strategy for your specific operational needs.
How can Jun Cyber help my global organization comply with SC.L2-3.13.7?
Jun Cyber provides comprehensive, globally-aware solutions for SC.L2-3.13.7. Our experts assess your international network infrastructure, identify split tunneling risks, and develop tailored strategies for your unique operational footprint across the US, UK, Australia, and Europe. We assist with VPN configuration, policy development, employee training, and documentation, ensuring your remote access solutions meet CMMC Level 2 requirements consistently, regardless of your team's geographic distribution. We focus on practical, sustainable solutions that balance security with global operational efficiency.
What are the risks of non-compliance with CMMC SC.L2-3.13.7?
The risks of non-compliance are severe and far-reaching. They include: failure to achieve CMMC Level 2 certification, leading to ineligibility for new and existing government contracts (especially DoD contracts); significant financial penalties; reputational damage; and, most critically, the unauthorized disclosure or compromise of CUI. This can result in intellectual property theft, national security vulnerabilities, and severe legal ramifications. Proactive compliance is essential to mitigate these risks.
Is it possible to maintain productivity while enforcing full tunneling?
Yes, absolutely. While initial concerns about productivity impacts with full tunneling are common, modern VPN solutions and network architectures are highly optimized to minimize latency and ensure efficient data transfer. Jun Cyber helps organizations design and implement VPN solutions that prioritize both robust security and user experience. This includes optimizing VPN server locations, bandwidth management, and deploying advanced networking solutions to ensure that full tunneling does not unduly impede productivity, even for global workforces.
Still have questions? Let's talk.
Secure Your CMMC Assessment TodayHave questions about this control?
Ask ChatCMMC — our free AI-powered CMMC compliance assistant. Get instant answers to your compliance questions.
Try ChatCMMC Free →DIB Cybersecurity Compliance Resources
What resources are available to assist companies in complying with Department cybersecurity requirements? The Department provides resources to help businesses who wish to enter the DIB reach cybersecurity compliance.
DoD DIB Cybersecurity-As-A-Service (CSaaS)
No-cost Cybersecurity-as-a-Service resources to reduce barriers to DIB community compliance and support contract cybersecurity efforts.
✅ Cyber ABCertified CMMC Assessors & Practitioners
Marketplace of certified CMMC assessors, professionals, and registered practitioner organizations to prepare for CMMC implementation.
📚 TrainingDefense Acquisition University CMMC Training
Free online CMMC and cybersecurity training from the Defense Acquisition University for defense contractors and businesses.
Related Articles
Read the latest insights on this topic
Don't leave without a plan
Ensure your remote access and VPN solutions meet stringent CMMC Level 2 requirements, eliminating critical vulnerabilities posed by uncontrolled split tunneling for global operations.
Secure Your CMMC Assessment Today