Network Access Control (NAC) is a security mechanism that decides which devices get onto a network and what they can do once they are on it. When a device tries to connect, NAC checks who or what it is, whether it meets policy, and only then grants access, often a specific level of access rather than the whole network. It is the gate at the door of the LAN.
What is Network Access Control?
NAC enforces admission policy at the moment of connection. It authenticates the device or user, assesses the endpoint's health, and assigns access based on the result. The best-known mechanism is 802.1X, an IEEE standard that authenticates a device before its switch port or Wi-Fi association is opened. Non-compliant devices get blocked, quarantined, or dropped into a restricted segment where they can remediate.
How does Network Access Control work?
Most NAC deployments run through four steps:
- Authentication. The device proves its identity, typically via 802.1X with a certificate or credentials, before any traffic is allowed.
- Posture assessment. NAC checks the endpoint against policy: patch level, antivirus status, configuration.
- Authorization. Based on identity and posture, the device is granted a specific level of access, mapped to a VLAN or policy.
- Remediation. A device that fails is confined to a limited segment where it can update and try again.
Why does NAC matter for OT?
OT networks are full of devices that were never meant to authenticate anything: PLCs, SCADA nodes, sensors, and legacy controllers that will happily talk to whatever appears on the wire. As these converge with IT, controlling what plugs in becomes essential. NAC stops an unknown laptop, a rogue device, or an unmanaged contractor machine from silently joining the network next to systems that move physical mass. That maps directly onto the access-control requirements in NIST SP 800-171, CMMC, NIS2, and IEC 62443, all of which treat controlling network access as a foundational control.
But classic 802.1X NAC struggles in OT. Many industrial devices cannot run a supplicant, cannot present a certificate, and cannot be taken offline to onboard. That gap is why identity-based access enforced at the network layer, rather than at the device, has become the practical path for plants.
How is NAC different from a firewall?
A firewall filters traffic between networks based on rules about addresses, ports, and protocols. NAC governs admission: it decides whether a device belongs on the network at all and what it may reach once admitted. A firewall watches the boundary between zones; NAC watches the front door of a single network. In a Zero Trust design the two work together, but they answer different questions.
How does Access Gate help?
Access Gate delivers access control the way OT actually needs it: agent-free, identity-based, and enforced in the network rather than on devices that cannot run a supplicant. It discovers every asset on the LAN, applies least-privilege microsegmentation so an admitted device reaches only what it should, proxies remote and vendor sessions, and forwards traffic to your SIEM. No 802.1X rollout, no re-cabling. See Zero-trust access control.

