CMMC enduring exception is a documented acknowledgment that a specific asset cannot natively implement a required security control because of hardware or firmware limits. It does not waive the requirement. It commits the contractor to a compensating control that addresses the residual risk, and it stays in place for the life of the device because the limitation is permanent.
What is a CMMC enduring exception?
CMMC Level 2 requires 110 security controls drawn from NIST SP 800-171. Many OT assets cannot meet some of them. PLCs, RTUs, embedded controllers, and older HMIs run purpose-built firmware with no way to install an agent, enforce multi-factor authentication, encrypt their own traffic, or write an audit log.
The enduring exception records that gap in the System Security Plan (SSP). Each entry names the specific asset, the specific control it cannot implement, the technical reason, and the compensating control that covers the risk. It is "enduring" because the limitation is baked into the device and will not change, which is what separates it from a Plan of Action and Milestones that tracks a gap you intend to close.
How does an enduring exception work?
The scope is narrow, and getting it wrong is the common mistake. An enduring exception covers the asset's inability to implement the control natively. It does not cover the risk that inability creates. You still have to show the compensating control reduces that risk to an acceptable level.
Take a PLC that cannot authenticate users. The exception documents the incapacity. The compensating control puts the PLC inside a segment where every access path is verified at the network layer, so identity is enforced around the device even though the device cannot enforce it itself.
The Affirming Official who signs the assessment personally attests that every documented exception has a valid compensating control. Under the False Claims Act, signing without one creates real legal liability, and the Department of Justice has signaled that CMMC attestations will get the same scrutiny as any other federal contract certification.
Who needs enduring exceptions in OT?
Defense manufacturers who run old iron. CNC machines, welding robots, and test equipment with embedded controllers 10 to 20 years old routinely process controlled technical drawings, which puts them inside the CUI assessment boundary. Replacing them can cost more than the contract and often forces re-qualification of the whole production process.
A typical case: a CNC controller receives G-code files containing CUI over unencrypted FTP, and its firmware supports no SFTP or TLS. The enduring exception records the limit. The compensating control drops the controller into an overlay-enforced enclave where only an authenticated, authorized file server can reach the FTP port, and traffic inside the enclave is encrypted at the network layer even though the application protocol is not.
How is an enduring exception different from a POA&M?
A POA&M is temporary. It describes a control gap you are actively remediating with a deadline. An enduring exception is permanent. It describes a gap that will never close because the device physically cannot do the thing. You do not remediate an enduring exception; you compensate for it and keep the compensating control running for the asset's operational life.
Compliance relevance
CMMC enduring exceptions are governed by 32 CFR Part 170 and must live in the SSP next to their compensating controls. NIST SP 800-171A provides the assessment procedures a C3PAO uses to judge whether a compensating control actually covers the risk. The mechanism lines up conceptually with IEC 62443 Security Level targeting, where devices with limited capability are protected by the controls of the zone around them.
How Access Gate helps
Access Gate supplies the compensating control for exempt OT assets by wrapping them in identity-enforced, encrypted overlay segments at the network layer, no agent on the device and no recabling. The PLC that cannot authenticate sits behind enforced identity; the CNC controller stuck on plaintext FTP sits inside an encrypted enclave. See CMMC enduring exceptions for OT.

