Subcontractor CMMC Tracker

Security Assessment (CA): the 4 CMMC Level 2 requirements a subcontractor self-assesses

The Security Assessment family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

4
CMMC L2 CA.L2-3.12.1Security Control Assessment 5 points in the score

Assess the security controls in place periodically to determine whether they are effective as implemented.

What an assessor asks to see: Assessment plan defining scope, method and frequency; Completed assessment results per control; Evidence assessments cover effectiveness and not just presence
Where subcontractors usually fall short: Assessment confirms a control exists without testing whether it works; Scope excludes parts of the CUI environment; No defined periodicity so assessments lapse
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CA.L2-3.12.2Plan of Action 3 points in the score

Develop and carry out plans of action that correct identified deficiencies and reduce or eliminate vulnerabilities.

What an assessor asks to see: Plan of action and milestones with owners and target dates; Evidence of progress and closure for completed items; Linkage from assessment findings to plan entries
Where subcontractors usually fall short: Plan maintained as a static list with no progress; Findings closed without evidence of correction; Deficiencies identified but never entered into the plan
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CA.L2-3.12.3Security Control Monitoring 5 points in the score

Monitor security controls continuously so their effectiveness is known on an ongoing basis rather than only at assessment time.

What an assessor asks to see: Continuous monitoring strategy naming controls, metrics and frequency; Monitoring output such as dashboards or periodic reports; Records of action taken when monitoring shows degradation
Where subcontractors usually fall short: Monitoring limited to the annual assessment; Metrics collected but not evaluated against expectations; Degradation detected without follow up
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CA.L2-3.12.4System Security Plan 0 points in the score

Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.

What an assessor asks to see: Current system security plan covering boundary, environment, implementation and interconnections; Version history showing periodic update; Approval record for the current version
Where subcontractors usually fall short: Plan describes intent rather than actual implementation; Boundary and interconnections omitted or stale; No defined update trigger or cadence
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)