
CMMC Level 3 is the Department of Defense's mandatory cybersecurity standard for contractors handling Controlled Unclassified Information (CUI). It requires full implementation of all 110 security controls outlined in NIST SP 800-171 across 14 distinct domains.
Limit system access to authorized users, processes, and devices. Control the types of transactions and functions authorized users may execute. Applies to all CUI systems and environments.
Requirement AC.L1-3.1.1 (CMMC Level 2 (L2 Baseline)): Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
Requirement AC.L1-3.1.2 (CMMC Level 2 (L2 Baseline)): Limit system access to the types of transactions and functions that authorized users are permitted to execute.
Requirement AC.L2-3.1.3 (CMMC Level 2 (L2 Baseline)): Control the flow of CUI in accordance with approved authorizations.
Requirement AC.L2-3.1.4 (CMMC Level 2 (L2 Baseline)): Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
Requirement AC.L2-3.1.5 (CMMC Level 2 (L2 Baseline)): Employ the principle of least privilege, including for specific security functions and privileged accounts.
Requirement AC.L2-3.1.6 (CMMC Level 2 (L2 Baseline)): Use non-privileged accounts or roles when accessing non-security functions.
Requirement AC.L2-3.1.7 (CMMC Level 2 (L2 Baseline)): Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
Requirement AC.L2-3.1.8 (CMMC Level 2 (L2 Baseline)): Limit unsuccessful logon attempts.
Requirement AC.L2-3.1.9 (CMMC Level 2 (L2 Baseline)): Provide privacy and security notices consistent with CUI rules.
Requirement AC.L2-3.1.10 (CMMC Level 2 (L2 Baseline)): Use session lock with pattern-hiding displays after a period of inactivity.
Requirement AC.L2-3.1.11 (CMMC Level 2 (L2 Baseline)): Terminate (automatically) a user session after a defined condition.
Requirement AC.L2-3.1.12 (CMMC Level 2 (L2 Baseline)): Monitor and control remote access sessions.
Requirement AC.L2-3.1.13 (CMMC Level 2 (L2 Baseline)): Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
Requirement AC.L2-3.1.14 (CMMC Level 2 (L2 Baseline)): Route remote access via managed access control points.
Requirement AC.L2-3.1.15 (CMMC Level 2 (L2 Baseline)): Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs.
Requirement AC.L2-3.1.16 (CMMC Level 2 (L2 Baseline)): Authorize wireless access prior to allowing such connections.
Requirement AC.L2-3.1.17 (CMMC Level 2 (L2 Baseline)): Protect wireless access using authentication and encryption.
Requirement AC.L2-3.1.18 (CMMC Level 2 (L2 Baseline)): Control connection of mobile devices.
Requirement AC.L2-3.1.19 (CMMC Level 2 (L2 Baseline)): Encrypt CUI on mobile devices and mobile computing platforms.
Requirement AC.L2-3.1.20 (CMMC Level 2 (L2 Baseline)): Verify and control/limit connections to external systems.
Requirement AC.L2-3.1.21 (CMMC Level 2 (L2 Baseline)): Limit use of portable storage devices on external systems.
Requirement AC.L2-3.1.22 (CMMC Level 2 (L2 Baseline)): Control CUI posted or processed on publicly accessible systems.
Requirement AC.L3-3.1.2e (CMMC Level 3 (L3 Enhanced)): Employ dynamic access control approaches (e.g., attribute-based access control) that allow access decisions to incorporate additional factors.
Requirement AC.L3-3.1.3e (CMMC Level 3 (L3 Enhanced)): Use automated mechanisms to enforce access control policies.
Ensure managers, administrators, and users are aware of security risks and trained to carry out assigned information security responsibilities including recognition of advanced threats.
Requirement AT.L2-3.2.1 (CMMC Level 2 (L2 Baseline)): Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities.
Requirement AT.L2-3.2.2 (CMMC Level 2 (L2 Baseline)): Ensure that personnel are trained to carry out their assigned information security responsibilities.
Requirement AT.L2-3.2.3 (CMMC Level 2 (L2 Baseline)): Provide security awareness training on recognizing and reporting potential threats (e.g., social engineering attacks).
Requirement AT.L3-3.2.1e (CMMC Level 3 (L3 Enhanced)): Provide awareness training focused on recognizing and responding to threats from adversarial tactics, techniques, and procedures (TTPs).
Create, retain, and review system audit logs to enable monitoring, analysis, investigation, and reporting of unauthorized activity. Employ SIEM for centralized detection and correlation.
Requirement AU.L2-3.3.1 (CMMC Level 2 (L2 Baseline)): Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
Requirement AU.L2-3.3.2 (CMMC Level 2 (L2 Baseline)): Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
Requirement AU.L2-3.3.3 (CMMC Level 2 (L2 Baseline)): Review and update logged events.
Requirement AU.L2-3.3.4 (CMMC Level 2 (L2 Baseline)): Alert in the event of an audit logging process failure.
Requirement AU.L2-3.3.5 (CMMC Level 2 (L2 Baseline)): Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
Requirement AU.L2-3.3.6 (CMMC Level 2 (L2 Baseline)): Provide audit record reduction and report generation to support on-demand analysis and reporting.
Requirement AU.L2-3.3.7 (CMMC Level 2 (L2 Baseline)): Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
Requirement AU.L2-3.3.8 (CMMC Level 2 (L2 Baseline)): Protect audit information and audit tools from unauthorized access, modification, and deletion.
Requirement AU.L2-3.3.9 (CMMC Level 2 (L2 Baseline)): Limit management of audit logging to a subset of privileged users.
Requirement AU.L3-3.3.1e (CMMC Level 3 (L3 Enhanced)): Employ a Security Information and Event Management (SIEM) system to centralize log collection, analysis, and reporting to detect, correlate, and respond to security events and anomalous activities.
Periodically assess security controls, develop plans of action, monitor controls on an ongoing basis, and maintain system security plans. Use authorized third-party assessors for comprehensive evaluations.
Requirement CA.L2-3.12.1 (CMMC Level 2 (L2 Baseline)): Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
Requirement CA.L2-3.12.2 (CMMC Level 2 (L2 Baseline)): Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
Requirement CA.L2-3.12.3 (CMMC Level 2 (L2 Baseline)): Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
Requirement CA.L2-3.12.4 (CMMC Level 2 (L2 Baseline)): Develop, document, and periodically update system security plans that describe system boundaries, environments of operation, how security requirements are implemented, and relationships with or connections to other systems.
Requirement CA.L3-3.12.1e (CMMC Level 3 (L3 Enhanced)): Employ a security assessment organization that meets the requirements of appropriate law, policy, or regulation to conduct comprehensive security assessments of organizational systems and the environments in which those systems operate.
Establish and maintain baseline configurations and inventories of organizational systems. Enforce security configuration settings and control changes to systems through automated and manual processes.
Requirement CM.L2-3.4.1 (CMMC Level 2 (L2 Baseline)): Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation).
Requirement CM.L2-3.4.2 (CMMC Level 2 (L2 Baseline)): Establish and enforce security configuration settings for information technology products employed in organizational systems.
Requirement CM.L2-3.4.3 (CMMC Level 2 (L2 Baseline)): Track, review, approve, and log changes to organizational systems.
Requirement CM.L2-3.4.4 (CMMC Level 2 (L2 Baseline)): Analyze the security impact of changes prior to implementation.
Requirement CM.L2-3.4.5 (CMMC Level 2 (L2 Baseline)): Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
Requirement CM.L2-3.4.6 (CMMC Level 2 (L2 Baseline)): Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
Requirement CM.L2-3.4.7 (CMMC Level 2 (L2 Baseline)): Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
Requirement CM.L2-3.4.8 (CMMC Level 2 (L2 Baseline)): Apply deny-by-exception (blacklisting) to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
Requirement CM.L2-3.4.9 (CMMC Level 2 (L2 Baseline)): Control and monitor user-installed software.
Requirement CM.L3-3.4.1e (CMMC Level 3 (L3 Enhanced)): Establish and maintain an accurate, current, and complete inventory of organizational systems, components, and software, including unauthorized software, using automated discovery tools.
Identify and authenticate users, processes, and devices before granting access to organizational systems. Enforce MFA, strong password policies, and replay-resistant authentication mechanisms.
Requirement IA.L2-3.5.1 (CMMC Level 2 (L2 Baseline)): Identify system users, processes acting on behalf of users, and devices.
Requirement IA.L2-3.5.2 (CMMC Level 2 (L2 Baseline)): Authenticate (or verify) the identities of users, processes, or devices as a prerequisite to allowing access to organizational systems.
Requirement IA.L2-3.5.3 (CMMC Level 2 (L2 Baseline)): Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Requirement IA.L2-3.5.4 (CMMC Level 2 (L2 Baseline)): Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
Requirement IA.L2-3.5.5 (CMMC Level 2 (L2 Baseline)): Employ identifier management practices that include: binding identifiers to devices, not reusing identifiers for a defined period, and disabling inactive identifiers.
Requirement IA.L2-3.5.6 (CMMC Level 2 (L2 Baseline)): Disable identifiers after a defined inactivity period.
Requirement IA.L2-3.5.7 (CMMC Level 2 (L2 Baseline)): Enforce a minimum password complexity and change requirements when passwords are used as authentication.
Requirement IA.L2-3.5.8 (CMMC Level 2 (L2 Baseline)): Prohibit password reuse for a specified number of generations.
Requirement IA.L2-3.5.9 (CMMC Level 2 (L2 Baseline)): Allow temporary password use with an immediate change requirement.
Requirement IA.L2-3.5.10 (CMMC Level 2 (L2 Baseline)): Store and transmit only cryptographically-protected passwords.
Requirement IA.L2-3.5.11 (CMMC Level 2 (L2 Baseline)): Obscure feedback of authentication information.
Requirement IA.L3-3.5.3e (CMMC Level 3 (L3 Enhanced)): Employ multifactor authentication (MFA) for local access to non-privileged accounts in addition to network access.
Requirement IA.L3-3.5.4e (CMMC Level 3 (L3 Enhanced)): Employ replay-resistant authentication mechanisms and prevent the reuse of authentication factors for the defined period.
Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user response. Maintain a cyber incident response team capable of operating anywhere.
Requirement IR.L2-3.6.1 (CMMC Level 2 (L2 Baseline)): Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
Requirement IR.L2-3.6.2 (CMMC Level 2 (L2 Baseline)): Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
Requirement IR.L2-3.6.3 (CMMC Level 2 (L2 Baseline)): Test the organizational incident response capability.
Requirement IR.L3-3.6.1e (CMMC Level 3 (L3 Enhanced)): Establish and maintain a cyber incident response team capable of investigating a cyber incident anywhere the organization operates.
Perform maintenance on organizational systems and provide controls on the tools, techniques, mechanisms, and personnel that conduct maintenance. Ensure remote maintenance uses MFA and encrypted sessions.
Requirement MA.L2-3.7.1 (CMMC Level 2 (L2 Baseline)): Perform maintenance on organizational systems.
Requirement MA.L2-3.7.2 (CMMC Level 2 (L2 Baseline)): Provide controls on the tools, techniques, mechanisms, and personnel that conduct system maintenance.
Requirement MA.L2-3.7.3 (CMMC Level 2 (L2 Baseline)): Ensure equipment removed for maintenance is sanitized.
Requirement MA.L2-3.7.4 (CMMC Level 2 (L2 Baseline)): Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.
Requirement MA.L2-3.7.5 (CMMC Level 2 (L2 Baseline)): Require MFA for remote maintenance sessions and terminate such connections when no longer in use.
Requirement MA.L2-3.7.6 (CMMC Level 2 (L2 Baseline)): Supervise the maintenance activities of maintenance personnel without required access authorization.
Protect system media containing CUI — both paper and digital. Limit access, sanitize or destroy before disposal, mark, and control transport. Encrypt CUI during transmission and protect backups.
Requirement MP.L2-3.8.1 (CMMC Level 2 (L2 Baseline)): Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.
Requirement MP.L2-3.8.2 (CMMC Level 2 (L2 Baseline)): Limit access to CUI on system media to authorized users.
Requirement MP.L2-3.8.3 (CMMC Level 2 (L2 Baseline)): Sanitize or destroy system media before disposal or reuse.
Requirement MP.L2-3.8.4 (CMMC Level 2 (L2 Baseline)): Mark media with necessary CUI markings and distribution limitations.
Requirement MP.L2-3.8.5 (CMMC Level 2 (L2 Baseline)): Control access to media containing CUI and maintain accountability for media during transport.
Requirement MP.L2-3.8.6 (CMMC Level 2 (L2 Baseline)): Implement cryptographic mechanisms to protect CUI during transmission unless otherwise protected by alternative physical safeguards.
Requirement MP.L2-3.8.7 (CMMC Level 2 (L2 Baseline)): Control the use of removable media on system components.
Requirement MP.L2-3.8.8 (CMMC Level 2 (L2 Baseline)): Prohibit the use of portable storage devices when such devices have no identifiable owner.
Requirement MP.L2-3.8.9 (CMMC Level 2 (L2 Baseline)): Protect the confidentiality of backup CUI at storage locations.
Limit physical access to systems, equipment, and operating environments to authorized individuals. Monitor facilities, escort visitors, maintain audit logs of physical access, and enforce CUI safeguards at alternate work sites.
Requirement PE.L2-3.10.1 (CMMC Level 2 (L2 Baseline)): Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
Requirement PE.L2-3.10.2 (CMMC Level 2 (L2 Baseline)): Protect and monitor the physical facility and support infrastructure for those systems.
Requirement PE.L2-3.10.3 (CMMC Level 2 (L2 Baseline)): Escort visitors and monitor visitor activity.
Requirement PE.L2-3.10.4 (CMMC Level 2 (L2 Baseline)): Maintain audit logs of physical access.
Requirement PE.L2-3.10.5 (CMMC Level 2 (L2 Baseline)): Control and manage physical access devices.
Requirement PE.L2-3.10.6 (CMMC Level 2 (L2 Baseline)): Enforce safeguarding measures for CUI at alternate work sites.
Screen individuals prior to authorizing access to systems containing CUI. Ensure CUI is protected during and after personnel actions such as terminations and transfers.
Requirement PS.L2-3.9.1 (CMMC Level 2 (L2 Baseline)): Screen individuals prior to authorizing access to organizational systems containing CUI.
Requirement PS.L2-3.9.2 (CMMC Level 2 (L2 Baseline)): Ensure that CUI is protected during and after personnel actions such as terminations and transfers.
Periodically assess risk to operations, assets, and individuals from system operation and CUI processing. Employ threat-informed risk assessments, threat intelligence, and advanced vulnerability scanning including penetration testing.
Requirement RA.L2-3.11.1 (CMMC Level 2 (L2 Baseline)): Periodically assess the risk to organizational operations, organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
Requirement RA.L2-3.11.2 (CMMC Level 2 (L2 Baseline)): Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
Requirement RA.L2-3.11.3 (CMMC Level 2 (L2 Baseline)): Remediate vulnerabilities in accordance with risk assessments.
Requirement RA.L3-3.11.1e (CMMC Level 3 (L3 Enhanced)): Employ threat-informed risk assessments and threat modeling that incorporates cyber threat intelligence from sources such as federal agencies, ISACs, and commercial providers.
Requirement RA.L3-3.11.2e (CMMC Level 3 (L3 Enhanced)): Conduct vulnerability analysis to determine the attack surface and assess the likelihood and severity of vulnerabilities, employing advanced vulnerability scanning and penetration testing that reflect the actual threat environment.
Monitor, control, and protect communications at external and key internal boundaries. Employ deny-by-default policies, FIPS-validated cryptography, network segmentation, and comprehensive key management.
Requirement SC.L2-3.13.1 (CMMC Level 2 (L2 Baseline)): Monitor, control, and protect communications at the external boundaries and key internal boundaries of organizational systems.
Requirement SC.L2-3.13.2 (CMMC Level 2 (L2 Baseline)): Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
Requirement SC.L2-3.13.3 (CMMC Level 2 (L2 Baseline)): Separate user functionality from system management functionality.
Requirement SC.L2-3.13.4 (CMMC Level 2 (L2 Baseline)): Prevent unauthorized and unintended information transfer via shared system resources.
Requirement SC.L2-3.13.5 (CMMC Level 2 (L2 Baseline)): Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
Requirement SC.L2-3.13.6 (CMMC Level 2 (L2 Baseline)): Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
Requirement SC.L2-3.13.7 (CMMC Level 2 (L2 Baseline)): Prevent remote devices from simultaneously establishing connections with the system and communicating via some other connection (split tunneling).
Requirement SC.L2-3.13.8 (CMMC Level 2 (L2 Baseline)): Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
Requirement SC.L2-3.13.9 (CMMC Level 2 (L2 Baseline)): Terminate network connections after a defined period of inactivity.
Requirement SC.L2-3.13.10 (CMMC Level 2 (L2 Baseline)): Establish and manage cryptographic keys when cryptography is employed.
Requirement SC.L2-3.13.11 (CMMC Level 2 (L2 Baseline)): Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
Requirement SC.L2-3.13.12 (CMMC Level 2 (L2 Baseline)): Prohibit remote activation of collaborative computing devices and provide indication of use to present users.
Requirement SC.L2-3.13.13 (CMMC Level 2 (L2 Baseline)): Control and monitor the use of mobile code.
Requirement SC.L2-3.13.14 (CMMC Level 2 (L2 Baseline)): Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
Requirement SC.L2-3.13.15 (CMMC Level 2 (L2 Baseline)): Protect the authenticity of communications sessions.
Requirement SC.L2-3.13.16 (CMMC Level 2 (L2 Baseline)): Protect CUI at rest.
Requirement SC.L3-3.13.2e (CMMC Level 3 (L3 Enhanced)): Implement a policy of deny-by-default and least-privilege access to all systems, using network-based and host-based controls, to prevent unauthorized connections and information flow.
Requirement SC.L3-3.13.4e (CMMC Level 3 (L3 Enhanced)): Employ a deny-all, permit-by-exception policy on managed interfaces, enforced by boundary protection devices.
Requirement SC.L3-3.13.10e (CMMC Level 3 (L3 Enhanced)): Employ cryptographic key establishment procedures and key management practices that include all key life-cycle phases and automation for critical systems.
Identify, report, and correct system flaws. Protect against malicious code. Monitor systems and communications for attacks. Use threat intelligence, integrity verification, and advanced threat detection including deception techniques.
Requirement SI.L2-3.14.1 (CMMC Level 2 (L2 Baseline)): Identify, report, and correct information and system flaws in a timely manner.
Requirement SI.L2-3.14.2 (CMMC Level 2 (L2 Baseline)): Provide protection from malicious code at appropriate locations within organizational systems.
Requirement SI.L2-3.14.3 (CMMC Level 2 (L2 Baseline)): Monitor system security alerts and advisories and take appropriate actions in response.
Requirement SI.L2-3.14.4 (CMMC Level 2 (L2 Baseline)): Update malicious code protection mechanisms when new releases are available.
Requirement SI.L2-3.14.5 (CMMC Level 2 (L2 Baseline)): Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
Requirement SI.L2-3.14.6 (CMMC Level 2 (L2 Baseline)): Monitor organizational systems, including the communications at the external boundaries and key internal boundaries of those systems, to detect attacks and indicators of potential attacks.
Requirement SI.L2-3.14.7 (CMMC Level 2 (L2 Baseline)): Identify unauthorized use of organizational systems.
Requirement SI.L3-3.14.1e (CMMC Level 3 (L3 Enhanced)): Use threat indicator information relevant to the information and systems being protected, including systems containing CUI, and obtained from external organizations.
Requirement SI.L3-3.14.3e (CMMC Level 3 (L3 Enhanced)): Verify the integrity of security-critical software using root of trust mechanisms or cryptographic signatures.
Requirement SI.L3-3.14.6e (CMMC Level 3 (L3 Enhanced)): Implement an advanced threat detection capability that includes threat deception techniques (e.g., honey pots, decoys) and adversary-driven hunting based on threat intelligence to detect advanced and sophisticated cyber threats.
Establish a risk-based supply chain risk management program. Assess third-party components, ensure traceability, employ anti-tamper controls, and address nation-state threats targeting the supply chain.
Requirement SR.L2-3.17.1 (CMMC Level 2 (L2 Baseline)): Establish a supply chain risk management program to detect, respond to, and recover from supply chain compromises.
Requirement SR.L2-3.17.2 (CMMC Level 2 (L2 Baseline)): Assess the risk associated with the use of third-party components prior to purchase and integration into the organization's systems.
Requirement SR.L2-3.17.3 (CMMC Level 2 (L2 Baseline)): Use original equipment manufacturer (OEM)-qualified suppliers and assess the cyber security practices of suppliers using established standards.
Requirement SR.L3-3.17.1e (CMMC Level 3 (L3 Enhanced)): Establish a process to address weaknesses or deficiencies in supply chain elements identified during independent third-party assessments of such elements.
Requirement SR.L3-3.17.2e (CMMC Level 3 (L3 Enhanced)): Assess the risk of using existing or new ICT products, services, and outsourced IT/OT operations, with emphasis on provenance, integrity, and authenticity of the ICT supply chain.
Requirement SR.L3-3.17.3e (CMMC Level 3 (L3 Enhanced)): Develop and implement a process to obtain and maintain traceability of critical components throughout the supply chain lifecycle.
Requirement SR.L3-3.17.4e (CMMC Level 3 (L3 Enhanced)): Employ threat awareness programs and processes to detect and respond to threats from nation-state adversaries targeting the supply chain.
Requirement SR.L3-3.17.5e (CMMC Level 3 (L3 Enhanced)): Employ anti-tamper technologies and techniques to prevent the introduction of fraudulent or counterfeit components and detect tampering during delivery, handling, and use.