Network Access Control
Network Access Control (NAC) is a security approach that decides which users and devices are allowed to connect to a network and what they can reach once connected. It checks credentials and, in many cases, the security condition of a device before granting access, helping to keep untrusted or unauthorized devices out. NAC is intended to increase visibility into what is on a network and to reduce the risk of unauthorized access, though it is one control among many rather than a complete defense.
Network Access Control (NAC), also referred to as network admission control, is a set of policies and enforcement mechanisms that restrict access to a network based on the identity of the requesting user or device and, where implemented, the results of endpoint health or posture checks. Some firewalls provide NAC as a feature that grants access according to a user's credentials and the outcome of health checks. As a security solution, NAC enforces policy on devices seeking network access to improve network visibility and reduce risk by admitting only devices and users that satisfy defined trust and security criteria. NAC helps mitigate exposure to unauthorized access and related threats, but its effectiveness depends on policy configuration, coverage, and integration with other controls, and it should be evaluated within the applicable environment rather than treated as a standalone safeguard.
Why it matters
Payment environments depend on knowing exactly which devices and users can reach systems that store, process, or transmit cardholder data. Network Access Control helps address a persistent gap: unmanaged, misconfigured, or unauthorized devices connecting to a network and expanding the attack surface. By admitting only devices and users that satisfy defined trust and security criteria, NAC is intended to improve network visibility and reduce the risk of unauthorized access, which supports segmentation goals and the broader objective of limiting who can touch sensitive systems.
NAC also contributes to the discipline of maintaining an accurate inventory of what is actually on the network. Improved visibility into connected devices helps security and compliance teams identify rogue or non-compliant endpoints before they interact with in-scope systems. This matters for organizations working to keep their cardholder data environment tightly scoped, since undetected devices can undermine assumptions about network boundaries and segmentation.
NAC should be understood as one control among many rather than a complete defense. Its effectiveness depends on how policies are configured, how much of the environment it covers, and how well it integrates with other controls. NAC does not eliminate the risk of compromise on its own, and it should be evaluated within the applicable environment alongside other technical and administrative safeguards.
Who it's relevant to
Inside NAC
Common questions
Answers to the questions practitioners most commonly ask about NAC.