Configuration Management (CM): the 9 CMMC Level 2 requirements a subcontractor self-assesses
The Configuration Management family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 8 high, 1 medium; 0 of 9 need CMMC-specific evidence
- SOC 2reuse candidates 7 high, 1 medium; 1 of 9 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 7 high, 2 medium; 0 of 9 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
- CIS Controls v8reuse candidates 6 high, 0 medium; 3 of 9 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 9 high, 0 medium; 0 of 9 need CMMC-specific evidence
The requirements
9CMMC L2 CM.L2-3.4.1System Baselining 5 points in the score
Establish and maintain baseline configurations and inventories of systems, covering hardware, software, firmware and documentation, across the system life cycle.
What an assessor asks to see: Documented baseline configurations per system type; Asset inventory covering hardware, software and firmware; Evidence baselines are updated as systems change
Where subcontractors usually fall short: Inventory maintained but no configuration baseline defined; Baselines captured once and never maintained; Firmware and documentation excluded from scope
CMMC L2 CM.L2-3.4.2Security Configuration Enforcement 5 points in the score
Define security configuration settings for the IT products used in the system and enforce those settings in operation.
What an assessor asks to see: Documented security configuration settings or hardening standards; Evidence of enforcement, for example policy objects or configuration management tooling; Compliance scan results against the defined settings
Where subcontractors usually fall short: Standards documented but drift never measured; Settings applied at build with no ongoing enforcement; Products in use with no defined hardening standard
CMMC L2 CM.L2-3.4.3System Change Management 1 point in the score
Track changes to systems, review them, approve or reject them, and log the decision together with the change.
What an assessor asks to see: Change records showing request, review, decision and implementation; Change approval authority definition; Evidence unapproved changes are detected
Where subcontractors usually fall short: Emergency changes bypass the process with no retrospective record; Approvals recorded without evidence of review; Infrastructure changes tracked but application changes not
CMMC L2 CM.L2-3.4.4Security Impact Analysis 1 point in the score
Analyze the security impact of a proposed change before it is implemented.
What an assessor asks to see: Security impact analysis recorded within change records; Criteria defining when deeper analysis is required; Evidence analysis occurs prior to implementation
Where subcontractors usually fall short: Impact analysis performed after deployment; Analysis reduced to a checkbox with no substance; Changes deemed routine exempted without criteria
CMMC L2 CM.L2-3.4.5Access Restrictions for Change 5 points in the score
Define, document, approve and enforce the physical and logical access restrictions that apply to making changes to systems.
What an assessor asks to see: Documented and approved change access restrictions; Access control configuration limiting who can implement changes; Records showing enforcement, including physical restrictions where relevant
Where subcontractors usually fall short: Logical restrictions defined but physical access unaddressed; Restrictions documented without technical enforcement; Developers able to deploy directly to production
CMMC L2 CM.L2-3.4.6Least Functionality 5 points in the score
Configure systems to provide only the capabilities that are essential, applying the principle of least functionality.
What an assessor asks to see: Documented determination of essential capabilities per system type; Configuration evidence showing nonessential capabilities removed; Periodic review of enabled capabilities
Where subcontractors usually fall short: Default installations left intact; Essential capability never actually defined; Review performed without removing anything
CMMC L2 CM.L2-3.4.7Nonessential Functionality 5 points in the score
Prevent nonessential programs, functions, ports, protocols and services from being used, by restricting or disabling each one identified as unnecessary.
What an assessor asks to see: List of prohibited or restricted programs, ports, protocols and services; Configuration and scan evidence showing they are disabled or blocked; Exception records with justification
Where subcontractors usually fall short: Ports and services addressed but programs and functions ignored; Blocking at perimeter only while hosts remain open; Exceptions granted permanently without review
CMMC L2 CM.L2-3.4.8Application Execution Policy 5 points in the score
Operate a software execution policy, either deny by exception blocking of unauthorized software or permit by exception allowing only authorized software.
What an assessor asks to see: Documented decision on which policy approach is used; Application control configuration implementing that policy; Maintained allow or deny list and its review records
Where subcontractors usually fall short: Policy chosen but deployed in audit mode only; Lists never maintained after initial deployment; Coverage limited to a subset of endpoints
CMMC L2 CM.L2-3.4.9User-Installed Software 1 point in the score
Control which software users are able to install, and monitor what has in fact been installed on organizational systems.
What an assessor asks to see: Policy governing user installed software; Technical control restricting installation rights; Monitoring output identifying user installed software
Where subcontractors usually fall short: Users hold local administrator rights so installation is unrestricted; Control present but no monitoring of what was installed; Browser extensions and portable applications out of scope