CMMC Practice Requirement:

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

CMMC Requirement Explanation:

By terminating inactive sessions you reduce the risk of attackers taking advantage of them.

Example CMMC Implementation:

Establish a policy specifying the period of inactivity before a network connection is terminated. An example is 60 minutes. This can be implemented on your firewall by setting the idle time out settings (e.g., in seconds: UDP = 5, TCP = 1800, ICMP = 5, Other = 180). The same can be applied to your VPN connections.


- Scenario 1:

You have a VPN appliance allowing users to connect to your network. You configure the idle time out on the VPN to meet your policy which is 60 minutes.

Discover Our NIST SP 800-171 Solutions:


Compliance Accelerator

For contractors seeking compliance

Quantum Assessor

For IT service providers

Supply Chain Verifier

For contractors seeking to verify partner compliance