Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
REMOTE ACCESS

Remote Workers and CMMC: Laptops, Home Offices, and CUI

What remote work changes in a CMMC environment: endpoints, local storage, printing, networking, support, physical exposure, and evidence.

Remote work does not change the sensitivity of CUI; it changes the environment around the user. A managed laptop may be part of an approved CMMC architecture while the home router, printer, family members, local storage, browser behavior, and remote-support tools create paths that do not exist in the office.

The most reliable design minimizes dependence on the employee's home environment. Use managed endpoints, strong identity, protected connections, controlled local storage, and clear physical rules so the security outcome does not rely on a consumer router or a perfect home-office setup.

Write down whether CUI may be cached locally, downloaded for offline work, stored in synchronized folders, copied to removable media, or captured in screenshots. If the answer is no, enforce that technically where possible. If the answer is yes, the endpoint controls and evidence need to support that choice.

Decide where CUI is allowed to exist on the endpoint

Managed laptops are easier to defend because the organization can control patching, encryption, endpoint protection, local administration, configuration, and remote wipe. Personal computers or unmanaged tablets introduce additional uncertainty and should be analyzed separately rather than being treated as equivalent because both can open a browser.

Design remote access so the home router is not the control

A home router is usually outside enterprise management. Do not make its firewall settings, firmware, or family Wi-Fi password the foundation of CUI protection. Instead, use device-based controls, encrypted communications, strong authentication, host firewalls, endpoint monitoring, and application or network access policies that continue to operate on an untrusted network.

Document the architecture in those terms. An assessor should be able to understand why the endpoint remains protected at a hotel, airport, or home office without assuming that every local network meets a corporate standard.

Physical protection becomes a household problem

Remote-work procedures should address screens, conversations, paper, removable media, visitors, storage, and disposal. A private room is not always realistic, but employees need a clear rule for preventing unauthorized viewing and for securing the device when they step away. Privacy screens and automatic screen lock can support the procedure.

Paper is especially easy to forget. If home printing is not necessary, prohibit it and disable or restrict printing from the CUI environment. If it is necessary, define approved printers, secure storage, shredding or return procedures, and how the paper is tracked. A vague 'use judgment' instruction creates inconsistent handling.

Control the convenience features that create copies

Browser downloads, clipboard use, personal cloud sync, local backups, screenshots, USB devices, and consumer collaboration apps can create new CUI locations. Review the remote-work configuration for each. The correct answer depends on the architecture, but every permitted path should have an owner and protection method.

Test with a normal user account. Try to download, print, copy, share, and sync representative non-sensitive test content in the same way an employee would handle CUI. Configuration documents can say a feature is disabled while a browser extension or local permission leaves it available.

Include remote support in the scope analysis

An MSP or internal help desk may have privileged remote access to the managed endpoint. That support tooling, the identities used to administer devices, session logging, and the provider's responsibilities can become part of the security-protection story. Do not consider only the employee's login path.

Define how support is authorized, whether sessions are recorded or logged, what data the technician can see, and how credentials are protected. When a provider changes, revoke old access, remove agents, and update the SSP and responsibility matrix.

Audit the remote workflow, not the employee's home

The objective is not to inspect private residences. Audit the company-controlled workflow: managed-device posture, identity events, access logs, configuration compliance, approved data paths, training acknowledgments, and exceptions. Use those records to show the security process is operating without collecting unnecessary personal information.

Tie each remote-work evidence item to an owner and a failure response. Endpoint compliance can belong to IT operations, conditional-access exceptions to identity administration, and home-print approvals to the CUI program owner. The useful test is not merely whether a dashboard exists, but whether someone reviews the result, investigates noncompliant devices, and can show what happened when an exception appeared. That turns remote-work evidence from a one-time assessment screenshot into an operating process.

Run a short remote-work scenario every six months. Ask an employee to receive a test file, work on it, contact support, and return the deliverable. Observe where copies appear and which systems participate. The exercise gives you evidence and, more importantly, reveals scope drift before it becomes normal behavior.

Evidence should focus on company-controlled systems rather than on photographs of an employee's home. Use managed-device compliance reports, encryption status, endpoint-protection health, conditional-access logs, VPN or secure-access configuration, training records, exception approvals, and samples of remote-support authorization.

For physical safeguards, document the rule and employee acknowledgment, then test the workflow through interview or scenario rather than collecting intrusive household details. The organization needs to show that workers know how to protect screens, paper, and devices; it does not need to create a surveillance program inside private residences.

If home printing is prohibited, gather evidence from application or endpoint configuration where possible and include the rule in remote-work training. If it is allowed for a small group, maintain explicit approvals, approved device and disposal procedures, and periodic review of whether the exception is still necessary.

Use incident records and exercises as operating evidence. A lost-laptop or suspicious-login tabletop can demonstrate that identity revocation, remote wipe, log retrieval, contract escalation, and employee reporting paths work for staff outside the office.

Include travel in the remote-work design. Hotels, customer sites, airports, and temporary workspaces create the same unmanaged-network problem plus greater physical exposure. Define when users may work with CUI in public locations, whether privacy screens are required, how devices are secured during transit, and what to do if a laptop or paper record is lost. One remote policy should cover the situations employees actually encounter.

Define what happens when the managed laptop cannot be used. A broken device, travel delay, or urgent customer request can tempt staff to use a personal computer or forward files to ordinary email. Give employees an approved contingency, such as a replacement-device process or controlled remote session, so business continuity does not create an unplanned CUI path.

Keep the remote-work review focused on company-controlled safeguards, not the employee's household. Evidence should show the managed device, approved access path, local-storage restrictions, screen and paper-handling rules, support method, and incident-reporting process. Photographs of a home or details about other household members usually add privacy risk without proving the controls the company is actually responsible for.

WORKING CHECKLIST

Before you call the boundary done

  • Use managed endpoints for CUI work
  • Control local download and removable media
  • Define approved remote connection paths
  • Address home printing and paper handling
  • Review remote support privileges
  • Collect evidence from the remote configuration
  • Test one normal remote CUI workflow end to end

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.