Incident Response (IR): the 3 CMMC Level 2 requirements a subcontractor self-assesses
The Incident Response family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- SOC 2reuse candidates 2 high, 1 medium; 0 of 3 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- CIS Controls v8reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
The requirements
3CMMC L2 IR.L2-3.6.1Incident Handling 5 points in the scoreOperate an incident handling capability covering preparation, detection, analysis, containment, recovery and user response.
What an assessor asks to see: Incident response plan covering all named lifecycle activities; Assigned incident response roles and contact details; Records of handled incidents showing the lifecycle applied
Where subcontractors usually fall short: Plan covers detection and containment but omits recovery or user response; Capability documented with no assigned or trained personnel; No records demonstrating the plan is actually used
CMMC L2 IR.L2-3.6.2Incident Reporting 5 points in the scoreTrack, document and report incidents to the designated internal officials and to external authorities where required.
What an assessor asks to see: Incident register with tracking and documentation per incident; Defined internal officials and external reporting obligations; Evidence of reports made within required timeframes
Where subcontractors usually fall short: External reporting obligations unidentified; Incidents handled informally and never documented; Reporting timeframes undefined so notifications are late
CMMC L2 IR.L2-3.6.3Incident Response Testing 1 point in the scoreTest the organizational incident response capability to confirm it works.
What an assessor asks to see: Incident response test or exercise records; Defined test frequency and scenario scope; Lessons learned and resulting plan updates
Where subcontractors usually fall short: Testing never performed or long lapsed; Exercises run without capturing findings; Findings identified but the plan never updated