CMMC Level 2¶
CMMC Level 2 applies to defense contractors that handle Controlled Unclassified Information (CUI). Its requirements are the 110 controls of NIST SP 800-171 revision 2.
About this standard
CMMC Level 2 is the Department of Defense requirement for contractors that handle Controlled Unclassified Information (CUI). Its 110 requirements are the same ones published in NIST SP 800-171 revision 2.
Official sources: NIST SP 800-171 r2 (official requirements, PDF) · NIST SP 800-171 r2 publication page · DoD CMMC documentation (assessment guides)
Trimtab checks 32 of this standard's requirements with technical evidence. Requirements about policies, training, and physical security need their own evidence and are not listed here.
AC · Access Control¶
AC.L2-3.1.1¶
Limit system access to authorized users
In plain terms: Only people, programs, and devices you have approved should be able to get into your systems. No shared or leftover accounts that nobody owns.
Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
AC.L2-3.1.3¶
Control the flow of CUI
In plain terms: Sensitive information should only go where it's allowed. For example, email shouldn't automatically forward outside the company.
Control the flow of CUI in accordance with approved authorizations.
AC.L2-3.1.5¶
Employ the principle of least privilege
In plain terms: Give everyone the minimum access they need to do their job, nothing more. Admin rights in particular should be rare and deliberate.
Employ the principle of least privilege, including for specific security functions and privileged accounts.
Proven by: ACC-001, ACC-003, ACC-008, M365-002, M365-005, M365-007
AC.L2-3.1.6¶
Use non-privileged accounts for nonsecurity functions
In plain terms: Admins should do everyday work like email and browsing from a normal account, and only use their admin account when they actually need it.
Use non-privileged accounts or roles when accessing nonsecurity functions.
Proven by: ACC-001
AC.L2-3.1.7¶
Prevent non-privileged users from executing privileged functions
In plain terms: Regular users should not be able to make admin-level changes, and when admin-level actions do happen they should be logged.
Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
Proven by: ACC-009
AC.L2-3.1.8¶
Limit unsuccessful logon attempts
In plain terms: Lock an account after a handful of wrong passwords so an attacker cannot keep guessing.
Limit unsuccessful logon attempts.
Proven by: ACC-004
AC.L2-3.1.9¶
Provide privacy and security notices
In plain terms: Show a sign-in banner telling people the system is monitored and only for authorized use.
Provide privacy and security notices consistent with applicable CUI rules.
Proven by: SES-002
AC.L2-3.1.10¶
Use session lock with pattern-hiding displays
In plain terms: If someone walks away from their computer, the screen should lock automatically and hide what was on it.
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
Proven by: SES-001
AC.L2-3.1.12¶
Monitor and control remote access sessions
In plain terms: Know who is connecting in from outside, control how they do it, and keep an eye on those connections.
Monitor and control remote access sessions.
Proven by: SES-003
AC.L2-3.1.20¶
Verify and control connections to external systems
In plain terms: Know which outside people, systems, and services can connect to your data, and limit them to what you approve.
Verify and control/limit connections to and use of external systems.
AC.L2-3.1.22¶
Control CUI on publicly accessible systems
In plain terms: Make sure sensitive information can't end up somewhere the public can reach, like an open sharing link.
Control CUI posted or processed on publicly accessible systems.
Proven by: M365-009
AU · Audit and Accountability¶
AU.L2-3.3.1¶
Create and retain system audit logs
In plain terms: Record important activity on your systems and keep those records long enough to investigate if something goes wrong.
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
Proven by: AUD-001, AUD-002, AUD-003, EXO-001, EXO-002
AU.L2-3.3.2¶
Ensure actions of individual users can be traced
In plain terms: Logs should show exactly which person did what, so actions can be tied back to someone.
Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions.
Proven by: AUD-001, AUD-003, AUD-004, EXO-001, EXO-002
AU.L2-3.3.7¶
Synchronize system clocks with an authoritative source
In plain terms: All computers should keep the same correct time so log entries from different machines line up during an investigation.
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
Proven by: AUD-005
CM · Configuration Management¶
CM.L2-3.4.2¶
Establish and enforce security configuration settings
In plain terms: Decide on secure standard settings for your computers and make sure every machine actually uses them.
Establish and enforce security configuration settings for information technology products employed in organizational systems.
Proven by: ENC-002, ENC-003, AV-004, M365-011
CM.L2-3.4.6¶
Employ the principle of least functionality
In plain terms: Turn off features a computer does not need. Every extra feature is another way in.
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
CM.L2-3.4.7¶
Restrict nonessential programs, functions, ports, protocols, and services
In plain terms: Disable old or unneeded network protocols and services, especially ones attackers commonly abuse.
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
Proven by: HRD-001, HRD-002, HRD-003, M365-003, EXO-006
CM.L2-3.4.9¶
Control and monitor user-installed software
In plain terms: Users shouldn't be able to add software or connect apps to company data on their own without review.
Control and monitor user-installed software.
IA · Identification and Authentication¶
IA.L2-3.5.3¶
Use multifactor authentication
In plain terms: Require a second proof of identity, like an authenticator app, in addition to a password, especially for admins.
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Proven by: M365-001, M365-002, M365-003, M365-004, EXO-005, EXO-006
IA.L2-3.5.6¶
Disable identifiers after a period of inactivity
In plain terms: Turn off accounts nobody has used in a while, so forgotten logins can't be abused.
Disable identifiers after a defined period of inactivity.
Proven by: M365-010
IA.L2-3.5.7¶
Enforce minimum password complexity
In plain terms: Require passwords that are long and hard to guess, and do not allow a new password that is nearly the same as the old one.
Enforce a minimum password complexity and change of characters when new passwords are created.
IA.L2-3.5.8¶
Prohibit password reuse for a specified number of generations
In plain terms: Stop people from cycling back to passwords they have used recently.
Prohibit password reuse for a specified number of generations.
Proven by: ACC-007
IA.L2-3.5.10¶
Store and transmit only cryptographically-protected passwords
In plain terms: Passwords should never sit in plain text, on disk, in memory, or on the network, where an attacker could read them.
Store and transmit only cryptographically-protected passwords.
Proven by: ACC-008, HRD-007, HRD-008, HRD-009
MP · Media Protection¶
MP.L2-3.8.7¶
Control the use of removable media on system components
In plain terms: Control whether USB drives and similar media can be used, so data cannot walk out the door and malware cannot walk in.
Control the use of removable media on system components.
Proven by: HRD-005
SC · System and Communications Protection¶
SC.L2-3.13.1¶
Monitor, control, and protect communications at system boundaries
In plain terms: Use firewalls to control what traffic gets in and out of your network and devices.
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
Proven by: FW-001, EXO-007, EXO-008
SC.L2-3.13.6¶
Deny network communications traffic by default
In plain terms: Block all network traffic unless you have specifically decided to allow it.
Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
Proven by: FW-001
SC.L2-3.13.11¶
Employ FIPS-validated cryptography to protect CUI
In plain terms: When encryption protects government data, it must use encryption modules the government has tested and approved (FIPS 140).
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
Proven by: HRD-006
SC.L2-3.13.16¶
Protect the confidentiality of CUI at rest
In plain terms: Encrypt stored data, like laptop drives, so a lost or stolen device does not expose it.
Protect the confidentiality of CUI at rest.
SI · System and Information Integrity¶
SI.L2-3.14.1¶
Identify, report, and correct system flaws in a timely manner
In plain terms: Install security updates promptly and replace software that no longer gets updates.
Identify, report, and correct system flaws in a timely manner.
Proven by: PAT-001, PAT-002, PAT-003
SI.L2-3.14.2¶
Provide protection from malicious code
In plain terms: Run antivirus or endpoint protection and use built-in defenses that block common malware tricks.
Provide protection from malicious code at designated locations within organizational systems.
Proven by: AV-001, AV-003, AV-004, HRD-004
SI.L2-3.14.4¶
Update malicious code protection mechanisms
In plain terms: Keep antivirus definitions and engines up to date so they recognize new threats.
Update malicious code protection mechanisms when new releases are available.
Proven by: AV-002
SI.L2-3.14.5¶
Perform periodic and real-time scans
In plain terms: Scan computers on a schedule, and scan files the moment they are downloaded or opened.
Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
Proven by: AV-001