Network Access Control (NAC) is a security solution that decides which users and devices can join a network. It also controls what they can do once connected.
So what is network access control in practice? NAC verifies identity, checks whether a device meets security policy, and then grants, limits, quarantines, or blocks access.
Organizations now absorb a flood of personal devices, IoT hardware, and remote connections. NAC has become the enforcement layer that keeps unknown and non-compliant devices from quietly joining the network. Knowing what network access control is, and how it works, is the first step to closing those gaps.
Key takeaways
NAC decides who and what may connect to your network, then enforces that decision continuously.
- NAC authenticates users and devices, checks device posture, and enforces an access decision before and after they connect.
- It relies on standards such as IEEE 802.1X and RADIUS for port-based authentication.
- It comes in several forms, pre- or post-admission, agent-based or agentless, and on-premises or cloud-native.
- It acts as a policy enforcement point in Zero Trust, complementing ZTNA and firewalls rather than replacing them.
- It supports compliance frameworks such as HIPAA, PCI DSS, and ISO 27001 by controlling and logging access.
How does network access control work?
NAC checks every device and user against security policy the moment they try to connect. It then allows, restricts, or blocks them based on the result.
Most wired and wireless NAC is built on the IEEE 802.1X standard. That standard defines a three-party model of supplicant, authenticator, and authentication server.
The supplicant is the connecting device. The authenticator is the switch, access point, or VPN gateway that controls the port. The authentication server is typically a RADIUS server.
Until the supplicant's identity is validated and authorized, the authenticator keeps the door closed.
Behind the authenticator sits RADIUS. It is the protocol from IETF RFC 2865 that carries authentication and authorization data between the access device and the authentication server. One reason it has endured is security by design: its shared secret is never transmitted across the network.
The process itself breaks into three steps:

Step 1: Authentication (identity verification)
First, the user and device must prove who they are.
Depending on the environment, that can mean 802.1X with a digital certificate or a username and password checked against a directory. It can also mean a RADIUS exchange or multi-factor authentication for extra assurance.
Not every device can run an 802.1X supplicant. Printers, cameras, and industrial sensors often can't, so NAC uses MAC Authentication Bypass (MAB) and profiling to admit them safely.
Step 2: Posture assessment (device compliance)
Once identity is established, NAC evaluates the device's security posture.
This typically includes operating system patch level, antivirus status, firewall configuration, disk encryption, and device type. A device that falls short of policy isn't trusted just because someone logged in correctly. It can be flagged, sent to a remediation network, or given restricted access until it complies.
Step 3: Authorization and enforcement
Policy determines what the authenticated, compliant device is actually allowed to reach.
Options range from full access to a single segment, guest-only access, or quarantine for anything suspicious. Enforcement happens at the network's control points, the switches, wireless controllers, and VPN gateways. Good NAC keeps watching after admission, ready to change a device's access if its posture or behavior shifts.
Why is network access control important?
NAC matters because devices are connecting far faster than teams can track by hand. Attackers are exploiting the gaps.
IoT Analytics counted 18.5 billion connected IoT devices worldwide in 2024. It projects roughly 21.1 billion by the end of 2025. Every one of those endpoints is a potential entry point.
The breach data tells the same story. In Verizon's 2025 Data Breach Investigations Report, credential abuse was the most common initial access vector. Stolen credentials featured in roughly 31% of the breaches analyzed for 2024.
The same report found that 46% of infostealer-compromised systems holding corporate logins were non-managed devices. These are the personal, unmanaged devices that BYOD policies invite onto the network. NAC addresses that risk by refusing to treat a valid login on an unknown device as free rein.
The payoff is twofold. It means fewer unauthorized and unmanaged devices on the network, and less room for an intruder to move laterally. That containment matters as ransomware now appears in 44% of breaches, up from 32% a year earlier, according to the same Verizon report.
Types of network access control
NAC is not a single product shape. It differs along three axes.
Pre-admission versus post-admission: Pre-admission NAC evaluates a device before it joins and admits only those that meet policy. Post-admission NAC keeps monitoring connected devices, adjusting or revoking access if conditions change. Most mature deployments use both.
Agent-based versus agentless: Agent-based NAC installs software on the endpoint for detailed posture checks. Agentless NAC instead evaluates devices using network-based methods such as DHCP options, traffic patterns, and device fingerprints.
Contrary to a common myth, modern NAC does not require an agent on every device. Agentless profiling is often preferred for IoT, OT, and other unmanaged hardware.
On-premises versus cloud-native: Traditional NAC ran on on-premises appliances with their own hardware, licensing, and maintenance overhead. NAC is no longer limited to that model.
Cloud-native and SaaS options now extend the same policy enforcement across distributed and hybrid environments. That retires another myth, that NAC is only for campus networks.
Common network access control use cases
NAC applies wherever unknown or unmanaged devices need to be controlled.
- BYOD and remote work: NAC checks that employee-owned and off-network devices meet policy before they connect.
- IoT and OT visibility: NAC profiles and segments cameras, sensors, and industrial systems that can't defend themselves.
- Guest and third-party access: Contractors, partners, and visitors get time-limited, restricted access through self-service portals.
- Incident response: NAC can automatically quarantine a compromised device and share context with other security tools.
- Regulated industries: Healthcare, finance, education, and government use NAC to authenticate devices and produce audit logs.
NAC vs. ZTNA vs. firewalls
These three technologies are often confused. Each controls something different, and they work best together.

A firewall decides which traffic may pass. NAC decides whether a device may join the network at all. ZTNA decides whether a verified identity may reach a specific application, wherever the user is.
They are complementary. NIST's Zero Trust Architecture guidance (SP 800-207) treats NAC, firewalls, and segmentation all as policy enforcement points. ZTNA does not make NAC obsolete, the two solve different problems.
How NAC supports Zero Trust
Zero Trust starts from a simple principle. Don't grant trust just because a device sits inside the network.
NIST SP 800-207 states a basic tenet plainly: "remove the implicit trust in users, services, and devices" based on network location alone. Under that model, authentication and authorization of both the subject and the device happen before a session is established.
That is exactly what NAC does at the network layer. It verifies device identity and posture at the moment of connection.
It does not assume a device is safe simply because it reached a network port. In turn, NAC becomes the enforcement point that makes Zero Trust actionable for on-premises, wireless, and IoT environments.
NAC and compliance
NAC helps meet access-control obligations across major frameworks. It supports compliance rather than guaranteeing it.
- HIPAA: NAC supports the access-control safeguard at 45 CFR §164.312(a)(1), limiting system access to authorized persons and software.
- PCI DSS v4.0: NAC helps enforce multi-factor authentication for cardholder-data-environment access (Requirement 8.4.2).
- ISO/IEC 27001:2022: NAC supports the standard's access-control and network-access controls by enforcing who and what may connect.
Because NAC records every admission decision, it produces the audit trail regulators expect.
How to choose and implement a NAC solution
Evaluating NAC comes down to a few practical factors. Look at how well it discovers and profiles devices, especially agentless discovery for IoT and OT. Check how cleanly it integrates with your firewall, SIEM, identity provider, and MFA. Confirm it scales to your endpoint count and fits your deployment model. Prioritize vendor-neutral integration to avoid lock-in. Implementation succeeds or fails on sequencing. Establish full device visibility first, then define access policies based on what you find. Run NAC in monitor-only mode to see what enforcement would do, then tighten it gradually. The most common mistake is enforcing before you have complete visibility, which locks out legitimate devices.
Conclusion
Network access control answers one question: should this device and user be on the network, and with what access?
By authenticating identity, checking posture, and enforcing policy at connection, NAC keeps risky devices out. It also limits the damage when something slips through. As BYOD and IoT expand the attack surface, NAC remains foundational, and it is increasingly delivered from the cloud.
See where your network access stands
Use the ZTNA checklist to assess how your organization authenticates users and devices, applies access policies, and closes gaps across guest, BYOD, and IoT connections.
Frequently asked questions
What is network access control (NAC)?
NAC is a security solution that controls which users and devices can connect to a network. It also governs what they can access once connected.
How does network access control work?
It authenticates the user and device, then checks whether the device meets policy. Based on that, it allows, limits, or blocks access and keeps monitoring afterward.
What is the difference between NAC and a firewall?
A firewall filters the traffic moving in and out of a network. NAC controls which devices and users may join the network in the first place.
Is NAC the same as ZTNA?
No, they are complementary. NAC governs admission to the network, while ZTNA governs access to specific applications.
Does NAC require installing agents on every device?
No. Modern NAC supports agentless profiling, which is often preferred for IoT and OT devices.
What are the main types of NAC?
NAC can be pre-admission or post-admission, agent-based or agentless, and delivered on-premises or from the cloud.





