Protect CUI on every machine in your plant.
Trout Access Gate protects the OT on your shop floor for CMMC Level 2: CNCs, PLCs, CMMs and the legacy machines CMMC calls specialized assets. It connects to your existing network, with nothing to install on machines. It enforces 87 of the 110 NIST 800-171 controls. Installed in a day.
Last updated:
Trusted by defense manufacturers and partners
Drawings go to printers. Toolpaths go to CNCs. Results come back from CMMs. Many are legacy OT machines, too old to patch. Your IT team or MSP cannot install anything on them.
CMMC Phase II third-party assessments are suspended. The NIST 800-171 obligation stands: the self-assessment and the SPRS affirmation still apply.
One appliance does four jobs.
Access Gate connects to your existing network, beside your machines. Nothing is installed on the machines themselves.
See every machine.
List every machine that handles CUI in the asset inventory, as NIST 800-171 3.4.1 asks, and see who reached it and when.
Control who reaches what.
MFA and per-machine rules, even on machines too old to support them.
Reach any machine, securely.
Vendors get scoped, time-limited sessions with MFA. Every session is recorded.
Prove every audit.
Evidence for 87 of the 110 NIST 800-171 controls, ready for your assessor.
What Access Gate covers for CMMC Level 2.
What Access Gate takes off your plate for a CMMC Level 2 assessment, on the machines your IT team cannot touch.
- Access control (AC)
- Named people only, per machine
- Authentication (IA)
- MFA, even on old machines
- Audit (AU)
- Every session logged
- Network protection (SC)
- CUI machines kept apart
- Assessment scope
- Only the enclave is in scope
- Deployment
- In a day, enclave done in a week

Access Gate Essential
1/2U appliance · Up to 200 assets

Trout + CUI Vault
One CMMC solution from cloud to machine.
- CUI Vault enclave
- FIPS 140-3 tunnel
- Access Gate
- Authorized machines
CUI Vault by NtelSec keeps your CUI in a managed Microsoft GCC High enclave. Access Gate carries it to the machines on your floor. Each part has a fixed price, decided up front. The full setup, from cloud enclave to machine, is up in a week.
Elna Magnetics secured 100% of its CUI flows.
of on-site CUI flows secured and documented for CMMC Level 2. Deployed without downtime.
Read the case studyof the 110 NIST 800-171 controls enforced at the network layer. The remaining 23 are customer-owned process controls, listed in the Shared Responsibility Matrix.
See the coverage matrix“CUI was flowing everywhere (engineering, shop floor, file servers) with no access control and no audit trail. The Access Gate gave us enclave isolation and full logging.”
IT Director
Defense Manufacturer · Elna Magnetics
Common questions about CMMC compliance.
to be up and running on your shop floor. The full CUI enclave is complete in a week.
It works either way. For CUI that stays on site, Access Gate covers the controls on premises, and whether you also need GCC High depends on your contract. If you run GCC High or CUI Vault, the two are complementary. The enclave holds CUI in the cloud. Access Gate protects it where it reaches your plant and its machines, which is where the enclave's boundary ends.
CMMC Level 2 requires all 110 controls of NIST SP 800-171 for contractors that handle CUI. Third-party C3PAO assessments have been suspended since 13 July 2026. The controls, the self-assessment and the SPRS affirmation still apply. Access Gate covers the technical network controls on site: access, audit, identification and encryption.
A CMMC Level 2 checklist maps to the 110 NIST 800-171 controls across 14 families. They include access control, audit, identification and authentication, configuration management and communications protection. Access Gate enforces 87 of the 110 at the network layer and produces the evidence for each. The remaining 23 are customer-owned process controls, tracked in a Shared Responsibility Matrix.
Access Gate is installed in a day. It connects to your existing network, with no re-cabling and no IP changes. A single-plant CUI enclave is complete in a week, including scope, policies and evidence. With CUI Vault, the full setup from cloud enclave to machine is up in a week.
Access Gate provides enforcement evidence for 87 of the 110 NIST 800-171 controls. Coverage is strongest in access control, audit, configuration management, identification and authentication, and communications protection. The other 23, such as physical security and personnel screening, are customer-owned. The Shared Responsibility Matrix shows which controls Access Gate enforces, which it supports and which stay with you. Assessors can review access logs, policies and session recordings on demand.
Yes. Vendors log in with MFA and reach only the machines you allow, for a limited time. Every session is recorded. The link runs over the VPN built into Access Gate CMMC Edition, which uses a FIPS 140-3 validated cryptographic module.
A CUI enclave is an isolated part of your network that holds every system touching CUI: file servers, engineering workstations, printers and the shop-floor machines that receive drawings and toolpaths. Only the enclave is in scope for a CMMC Level 2 assessment. It can run on premise or extend a GCC High enclave such as CUI Vault down to your plant. See the CUI enclave architecture.
The gate is the first service you run, not the last.
Protect CUI from cloud to machine.
Tell us about your plant. We show you the path from your enclave to your machines, with a fixed price up front.