Subcontractor CMMC Tracker

Risk Assessment (RA): the 3 CMMC Level 2 requirements a subcontractor self-assesses

The Risk Assessment family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

3
CMMC L2 RA.L2-3.11.1Risk Assessments 3 points in the score

Periodically assess the risk that operating organizational systems, and processing, storing or transmitting CUI, creates for operations, assets and individuals.

What an assessor asks to see: Risk assessment methodology and defined frequency; Completed risk assessment covering CUI processing, storage and transmission; Evidence results are communicated and used
Where subcontractors usually fall short: Assessment covers technology risk only, omitting mission and individual impact; Performed once with no defined recurrence; Results not linked to remediation decisions
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 RA.L2-3.11.2Vulnerability Scan 5 points in the score

Scan systems and applications for vulnerabilities periodically and again when new vulnerabilities affecting them are identified.

What an assessor asks to see: Scan schedule and scope covering systems and applications; Scan reports across the defined period; Evidence of additional scanning triggered by new vulnerability information
Where subcontractors usually fall short: Infrastructure scanned while applications are not; Scanning periodic only, with no trigger on new vulnerability disclosure; Authenticated scanning not used so coverage is shallow
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 RA.L2-3.11.3Vulnerability Remediation 1 point in the score

Remediate identified vulnerabilities in line with the priorities set by risk assessment.

What an assessor asks to see: Remediation procedure with risk based timeframes; Evidence of remediation against identified findings; Records of accepted risk with approval where remediation is deferred
Where subcontractors usually fall short: Findings tracked but remediation timeframes undefined; Prioritization by scanner severity alone, ignoring organizational risk; Deferred items accepted without documented approval
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)