Risk Assessment (RA): the 3 CMMC Level 2 requirements a subcontractor self-assesses
The Risk Assessment family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 2 high, 1 medium; 0 of 3 need CMMC-specific evidence
- SOC 2reuse candidates 2 high, 1 medium; 0 of 3 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- CIS Controls v8reuse candidates 2 high, 1 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 3 high, 0 medium; 0 of 3 need CMMC-specific evidence
The requirements
3CMMC L2 RA.L2-3.11.1Risk Assessments 3 points in the scorePeriodically assess the risk that operating organizational systems, and processing, storing or transmitting CUI, creates for operations, assets and individuals.
What an assessor asks to see: Risk assessment methodology and defined frequency; Completed risk assessment covering CUI processing, storage and transmission; Evidence results are communicated and used
Where subcontractors usually fall short: Assessment covers technology risk only, omitting mission and individual impact; Performed once with no defined recurrence; Results not linked to remediation decisions
CMMC L2 RA.L2-3.11.2Vulnerability Scan 5 points in the scoreScan systems and applications for vulnerabilities periodically and again when new vulnerabilities affecting them are identified.
What an assessor asks to see: Scan schedule and scope covering systems and applications; Scan reports across the defined period; Evidence of additional scanning triggered by new vulnerability information
Where subcontractors usually fall short: Infrastructure scanned while applications are not; Scanning periodic only, with no trigger on new vulnerability disclosure; Authenticated scanning not used so coverage is shallow
CMMC L2 RA.L2-3.11.3Vulnerability Remediation 1 point in the scoreRemediate identified vulnerabilities in line with the priorities set by risk assessment.
What an assessor asks to see: Remediation procedure with risk based timeframes; Evidence of remediation against identified findings; Records of accepted risk with approval where remediation is deferred
Where subcontractors usually fall short: Findings tracked but remediation timeframes undefined; Prioritization by scanner severity alone, ignoring organizational risk; Deferred items accepted without documented approval