CMMC 2.0: the clauses behind the split
CMMC 2.0. Pick Level 1 or Level 2: Level 1 is the 17 practices of FAR 52.204-21 and the page shows only those; Level 2 adds the rest of NIST SP 800-171. The CMMC assessment guide is named, not quoted. A Level 1 practice is also a Level 2 practice.
Shown when ticked. The framework on the compliance library.
Control areas it anchors
14Every clause cited, quoted
16 of the 110 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
CMMC AC.L2-3.1.1 Authorized Access Control Level 1 and 2Restrict system access so only identified, authorized users, the processes running on their behalf, and approved devices including other connected systems can connect.
- Account inventory listing authorized users, service/process accounts and approved devices
- Account provisioning and approval records showing authorization before access
- System configuration showing device and system-to-system connection allow lists
- Periodic account recertification results
- Service and machine accounts never authorized or reviewed
- Device-level access unrestricted while user access is controlled
- Stale accounts retained after staff depart
CMMC AC.L2-3.1.3 Control CUI Flow Level 2Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.
- Documented CUI flow authorizations and approved flow paths
- Firewall, proxy, DLP or gateway rules enforcing those flows
- Data flow diagrams identifying CUI sources, stores and destinations
- Records of blocked or exception-approved transfers
- CUI flows documented but not technically enforced
- Egress to cloud and email paths unmonitored for CUI
- No defined authorization for flows to external partners
CMMC AC.L2-3.1.20 External Connections Level 1 and 2Verify, then control or limit, connections to and use of external systems that are outside organizational control.
- Inventory of approved external systems and connection terms
- Agreements or terms governing external system use
- Technical controls limiting external system connections
- External cloud services used without review
- Connections permitted with no verification of the external party
- No limit on what CUI may be processed externally
CMMC AC.L2-3.1.22 Control Public Information Level 1 and 2Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.
- Review and approval process for content published publicly
- Designated reviewer authorizations and review records
- Evidence of periodic scanning of public sites for CUI
- Publication approval informal or undocumented
- No periodic check of already published content
- Public facing systems not identified as in scope
CMMC AU.L2-3.3.1 System Auditing Level 2Generate and retain system audit logs in sufficient scope and detail to support monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.
- Defined auditable event list and rationale for its scope
- Logging configuration on in scope systems
- Retention settings and evidence logs are retained for the defined period
- Sample audit records showing captured content
- Logging enabled with default event sets never assessed for sufficiency
- Retention shorter than investigation needs
- In scope systems missing from logging coverage
CMMC CA.L2-3.12.4 System Security Plan Level 2Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.
- Current system security plan covering boundary, environment, implementation and interconnections
- Version history showing periodic update
- Approval record for the current version
- Plan describes intent rather than actual implementation
- Boundary and interconnections omitted or stale
- No defined update trigger or cadence
CMMC CM.L2-3.4.2 Security Configuration Enforcement Level 2Define security configuration settings for the IT products used in the system and enforce those settings in operation.
- Documented security configuration settings or hardening standards
- Evidence of enforcement, for example policy objects or configuration management tooling
- Compliance scan results against the defined settings
- Standards documented but drift never measured
- Settings applied at build with no ongoing enforcement
- Products in use with no defined hardening standard
CMMC IA.L2-3.5.3 Multifactor Authentication Level 2Require more than one authentication factor for privileged account access both locally and across the network, and for non privileged account access across the network.
- Multifactor configuration showing coverage of the required access cases
- Enrolment records for privileged account holders
- Evidence of enforcement for network access by non privileged users
- Multifactor applied to remote access only, missing local privileged access
- Exemptions granted for service or legacy accounts without compensating control
- Second factor is another knowledge factor
CMMC IR.L2-3.6.2 Incident Reporting Level 2Track, document and report incidents to the designated internal officials and to external authorities where required.
- Incident register with tracking and documentation per incident
- Defined internal officials and external reporting obligations
- Evidence of reports made within required timeframes
- External reporting obligations unidentified
- Incidents handled informally and never documented
- Reporting timeframes undefined so notifications are late
CMMC MP.L2-3.8.9 Protect Backups Level 2Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.
- Backup inventory identifying which backups contain CUI
- Protection applied at backup storage locations, encryption or physical control
- Access controls and records for backup storage
- Production data protected while backups are not
- Offsite and cloud backup locations unassessed
- Backup encryption keys stored alongside the backups
CMMC PE.L2-3.10.1 Limit Physical Access Level 1 and 2Limit physical access to systems, equipment and their operating environments to authorized individuals.
- Physical access authorization list for controlled areas
- Access control mechanism evidence such as badge system configuration
- Periodic review of who holds physical access
- Access lists not reviewed so departed staff retain badges
- Server and equipment areas within general office access
- Authorization granted verbally without record
CMMC SC.L2-3.13.1 Boundary Protection Level 1 and 2Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.
- Network architecture identifying external and key internal boundaries
- Boundary device configuration such as firewall and gateway rulesets
- Monitoring evidence at those boundaries
- External boundary protected while internal boundaries are flat
- Boundary devices configured but traffic not monitored
- Cloud and remote boundaries omitted from the architecture
CMMC SC.L2-3.13.2 Security Engineering Level 2Apply architectural design, software development techniques and systems engineering principles that promote effective information security.
- Documented security architecture and design principles
- Secure development standards applied to in house software
- Evidence principles are applied in design reviews
- Principles documented but absent from actual design decisions
- Secure development standards not applied to acquired or outsourced code
- No design review step in the development process
CMMC SC.L2-3.13.10 Key Management Level 2Establish and manage the cryptographic keys used by cryptography employed in organizational systems, across their life cycle.
- Key management procedure covering generation, distribution, storage, rotation and destruction
- Key inventory and custodian assignments
- Evidence of key rotation and secure storage
- Keys generated and then never rotated or inventoried
- Private keys stored alongside the data they protect
- Key custodianship undefined so departures leave keys orphaned
CMMC SC.L2-3.13.16 Data at Rest Level 2Protect the confidentiality of CUI while it is at rest in storage.
- Inventory of locations where CUI is stored at rest
- Encryption or equivalent protection configuration at those locations
- Evidence of protection coverage including databases, file shares and endpoints
- Endpoint encryption in place while servers and shares are unprotected
- Storage locations for CUI never fully inventoried
- Cloud storage protection assumed from the provider without verification
CMMC SI.L2-3.14.1 Flaw Remediation Level 1 and 2Identify system flaws, report them, and correct them within a timely period.
- Flaw identification sources and process
- Patch and remediation records with dates showing timeliness
- Defined timeframes for correction by severity
- Flaws identified but remediation timeframes undefined
- Patching covers operating systems only, omitting applications and firmware
- Reporting step absent so flaws are not tracked