Skip to content

CMMC Level 2

CMMC Level 2 applies to defense contractors that handle Controlled Unclassified Information (CUI). Its requirements are the 110 controls of NIST SP 800-171 revision 2.

About this standard

CMMC Level 2 is the Department of Defense requirement for contractors that handle Controlled Unclassified Information (CUI). Its 110 requirements are the same ones published in NIST SP 800-171 revision 2.

Official sources: NIST SP 800-171 r2 (official requirements, PDF) · NIST SP 800-171 r2 publication page · DoD CMMC documentation (assessment guides)

Trimtab checks 32 of this standard's requirements with technical evidence. Requirements about policies, training, and physical security need their own evidence and are not listed here.

AC · Access Control

AC.L2-3.1.1

Limit system access to authorized users

In plain terms: Only people, programs, and devices you have approved should be able to get into your systems. No shared or leftover accounts that nobody owns.

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Proven by: ACC-002, M365-008

AC.L2-3.1.3

Control the flow of CUI

In plain terms: Sensitive information should only go where it's allowed. For example, email shouldn't automatically forward outside the company.

Control the flow of CUI in accordance with approved authorizations.

Proven by: EXO-003, EXO-004

AC.L2-3.1.5

Employ the principle of least privilege

In plain terms: Give everyone the minimum access they need to do their job, nothing more. Admin rights in particular should be rare and deliberate.

Employ the principle of least privilege, including for specific security functions and privileged accounts.

Proven by: ACC-001, ACC-003, ACC-008, M365-002, M365-005, M365-007

AC.L2-3.1.6

Use non-privileged accounts for nonsecurity functions

In plain terms: Admins should do everyday work like email and browsing from a normal account, and only use their admin account when they actually need it.

Use non-privileged accounts or roles when accessing nonsecurity functions.

Proven by: ACC-001

AC.L2-3.1.7

Prevent non-privileged users from executing privileged functions

In plain terms: Regular users should not be able to make admin-level changes, and when admin-level actions do happen they should be logged.

Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

Proven by: ACC-009

AC.L2-3.1.8

Limit unsuccessful logon attempts

In plain terms: Lock an account after a handful of wrong passwords so an attacker cannot keep guessing.

Limit unsuccessful logon attempts.

Proven by: ACC-004

AC.L2-3.1.9

Provide privacy and security notices

In plain terms: Show a sign-in banner telling people the system is monitored and only for authorized use.

Provide privacy and security notices consistent with applicable CUI rules.

Proven by: SES-002

AC.L2-3.1.10

Use session lock with pattern-hiding displays

In plain terms: If someone walks away from their computer, the screen should lock automatically and hide what was on it.

Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

Proven by: SES-001

AC.L2-3.1.12

Monitor and control remote access sessions

In plain terms: Know who is connecting in from outside, control how they do it, and keep an eye on those connections.

Monitor and control remote access sessions.

Proven by: SES-003

AC.L2-3.1.20

Verify and control connections to external systems

In plain terms: Know which outside people, systems, and services can connect to your data, and limit them to what you approve.

Verify and control/limit connections to and use of external systems.

Proven by: M365-008, M365-009

AC.L2-3.1.22

Control CUI on publicly accessible systems

In plain terms: Make sure sensitive information can't end up somewhere the public can reach, like an open sharing link.

Control CUI posted or processed on publicly accessible systems.

Proven by: M365-009

AU · Audit and Accountability

AU.L2-3.3.1

Create and retain system audit logs

In plain terms: Record important activity on your systems and keep those records long enough to investigate if something goes wrong.

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

Proven by: AUD-001, AUD-002, AUD-003, EXO-001, EXO-002

AU.L2-3.3.2

Ensure actions of individual users can be traced

In plain terms: Logs should show exactly which person did what, so actions can be tied back to someone.

Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions.

Proven by: AUD-001, AUD-003, AUD-004, EXO-001, EXO-002

AU.L2-3.3.7

Synchronize system clocks with an authoritative source

In plain terms: All computers should keep the same correct time so log entries from different machines line up during an investigation.

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

Proven by: AUD-005

CM · Configuration Management

CM.L2-3.4.2

Establish and enforce security configuration settings

In plain terms: Decide on secure standard settings for your computers and make sure every machine actually uses them.

Establish and enforce security configuration settings for information technology products employed in organizational systems.

Proven by: ENC-002, ENC-003, AV-004, M365-011

CM.L2-3.4.6

Employ the principle of least functionality

In plain terms: Turn off features a computer does not need. Every extra feature is another way in.

Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

Proven by: HRD-001, HRD-004

CM.L2-3.4.7

Restrict nonessential programs, functions, ports, protocols, and services

In plain terms: Disable old or unneeded network protocols and services, especially ones attackers commonly abuse.

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

Proven by: HRD-001, HRD-002, HRD-003, M365-003, EXO-006

CM.L2-3.4.9

Control and monitor user-installed software

In plain terms: Users shouldn't be able to add software or connect apps to company data on their own without review.

Control and monitor user-installed software.

Proven by: M365-006, M365-007

IA · Identification and Authentication

IA.L2-3.5.3

Use multifactor authentication

In plain terms: Require a second proof of identity, like an authenticator app, in addition to a password, especially for admins.

Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Proven by: M365-001, M365-002, M365-003, M365-004, EXO-005, EXO-006

IA.L2-3.5.6

Disable identifiers after a period of inactivity

In plain terms: Turn off accounts nobody has used in a while, so forgotten logins can't be abused.

Disable identifiers after a defined period of inactivity.

Proven by: M365-010

IA.L2-3.5.7

Enforce minimum password complexity

In plain terms: Require passwords that are long and hard to guess, and do not allow a new password that is nearly the same as the old one.

Enforce a minimum password complexity and change of characters when new passwords are created.

Proven by: ACC-005, ACC-006

IA.L2-3.5.8

Prohibit password reuse for a specified number of generations

In plain terms: Stop people from cycling back to passwords they have used recently.

Prohibit password reuse for a specified number of generations.

Proven by: ACC-007

IA.L2-3.5.10

Store and transmit only cryptographically-protected passwords

In plain terms: Passwords should never sit in plain text, on disk, in memory, or on the network, where an attacker could read them.

Store and transmit only cryptographically-protected passwords.

Proven by: ACC-008, HRD-007, HRD-008, HRD-009

MP · Media Protection

MP.L2-3.8.7

Control the use of removable media on system components

In plain terms: Control whether USB drives and similar media can be used, so data cannot walk out the door and malware cannot walk in.

Control the use of removable media on system components.

Proven by: HRD-005

SC · System and Communications Protection

SC.L2-3.13.1

Monitor, control, and protect communications at system boundaries

In plain terms: Use firewalls to control what traffic gets in and out of your network and devices.

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

Proven by: FW-001, EXO-007, EXO-008

SC.L2-3.13.6

Deny network communications traffic by default

In plain terms: Block all network traffic unless you have specifically decided to allow it.

Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

Proven by: FW-001

SC.L2-3.13.11

Employ FIPS-validated cryptography to protect CUI

In plain terms: When encryption protects government data, it must use encryption modules the government has tested and approved (FIPS 140).

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Proven by: HRD-006

SC.L2-3.13.16

Protect the confidentiality of CUI at rest

In plain terms: Encrypt stored data, like laptop drives, so a lost or stolen device does not expose it.

Protect the confidentiality of CUI at rest.

Proven by: ENC-001, ENC-002

SI · System and Information Integrity

SI.L2-3.14.1

Identify, report, and correct system flaws in a timely manner

In plain terms: Install security updates promptly and replace software that no longer gets updates.

Identify, report, and correct system flaws in a timely manner.

Proven by: PAT-001, PAT-002, PAT-003

SI.L2-3.14.2

Provide protection from malicious code

In plain terms: Run antivirus or endpoint protection and use built-in defenses that block common malware tricks.

Provide protection from malicious code at designated locations within organizational systems.

Proven by: AV-001, AV-003, AV-004, HRD-004

SI.L2-3.14.4

Update malicious code protection mechanisms

In plain terms: Keep antivirus definitions and engines up to date so they recognize new threats.

Update malicious code protection mechanisms when new releases are available.

Proven by: AV-002

SI.L2-3.14.5

Perform periodic and real-time scans

In plain terms: Scan computers on a schedule, and scan files the moment they are downloaded or opened.

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

Proven by: AV-001