System and Communications Protection (SC): the 16 CMMC Level 2 requirements a subcontractor self-assesses
The System and Communications Protection family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.
Where frameworks a subcontractor holds may supply evidence here
- ISO/IEC 27001:2022reuse candidates 12 high, 0 medium; 4 of 16 need CMMC-specific evidence
- SOC 2reuse candidates 4 high, 3 medium; 9 of 16 need CMMC-specific evidence
- NIST CSF 2.0reuse candidates 7 high, 5 medium; 4 of 16 need CMMC-specific evidence
- FedRAMP Moderatereuse candidates 15 high, 0 medium; 1 of 16 need CMMC-specific evidence
- CIS Controls v8reuse candidates 10 high, 0 medium; 6 of 16 need CMMC-specific evidence
- NIST SP 800-53 Rev 5reuse candidates 15 high, 0 medium; 1 of 16 need CMMC-specific evidence
- NIST SP 800-171 Rev 3reuse candidates 13 high, 1 medium; 2 of 16 need CMMC-specific evidence
The requirements
16CMMC L2 SC.L2-3.13.1Boundary Protection 5 points in the score
Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.
What an assessor asks to see: Network architecture identifying external and key internal boundaries; Boundary device configuration such as firewall and gateway rulesets; Monitoring evidence at those boundaries
Where subcontractors usually fall short: External boundary protected while internal boundaries are flat; Boundary devices configured but traffic not monitored; Cloud and remote boundaries omitted from the architecture
CMMC L2 SC.L2-3.13.10Key Management 1 point in the score
Establish and manage the cryptographic keys used by cryptography employed in organizational systems, across their life cycle.
What an assessor asks to see: Key management procedure covering generation, distribution, storage, rotation and destruction; Key inventory and custodian assignments; Evidence of key rotation and secure storage
Where subcontractors usually fall short: Keys generated and then never rotated or inventoried; Private keys stored alongside the data they protect; Key custodianship undefined so departures leave keys orphaned
CMMC L2 SC.L2-3.13.11CUI Encryption 5 points in the score
Use FIPS validated cryptography wherever cryptography is relied on to protect the confidentiality of CUI.
What an assessor asks to see: Inventory of cryptographic modules protecting CUI with validation certificate references; Configuration evidence showing validated modules and approved modes in use; Evidence non validated cryptography is not relied on for CUI
Where subcontractors usually fall short: Cryptography strong but not FIPS validated; Validated module present but operated outside its approved mode; Certificate references stale or covering a different version
CMMC L2 SC.L2-3.13.12Collaborative Device Control 1 point in the score
Prohibit remote activation of collaborative computing devices such as cameras and microphones, and indicate to people present when such a device is in use.
What an assessor asks to see: Policy prohibiting remote activation of collaborative devices; Configuration preventing remote activation; Evidence of an in use indicator visible to those present
Where subcontractors usually fall short: Prohibition stated with no technical enforcement; Indicator absent on conference room equipment; Conferencing software permitted to auto enable cameras or microphones
CMMC L2 SC.L2-3.13.13Mobile Code 1 point in the score
Define which mobile code technologies are permitted, enforce that decision, and keep mobile code use under observation.
What an assessor asks to see: Policy defining acceptable and prohibited mobile code technologies; Technical controls restricting mobile code execution; Monitoring evidence for mobile code use
Where subcontractors usually fall short: Mobile code technologies undefined so the policy is unenforceable; Controls applied at the browser only, ignoring documents and email; Use controlled but never monitored
CMMC L2 SC.L2-3.13.14Voice over Internet Protocol 1 point in the score
Govern how Voice over Internet Protocol technology may be used, and keep its use under observation once deployed.
What an assessor asks to see: Policy governing permitted VoIP use; VoIP configuration and access controls; Monitoring records for VoIP usage
Where subcontractors usually fall short: VoIP deployed with no governing policy; Voice network not segmented from data; Usage unmonitored and default credentials retained
CMMC L2 SC.L2-3.13.15Communications Authenticity 5 points in the score
Protect the authenticity of communications sessions so a session cannot be hijacked or spoofed.
What an assessor asks to see: Session authenticity mechanism configuration, for example session tokens and mutual authentication; Evidence sessions are bound and validated; Configuration preventing session fixation and reuse
Where subcontractors usually fall short: Confidentiality protected while session authenticity is not; Session identifiers predictable or not regenerated after authentication; Application sessions outside the assessed scope
CMMC L2 SC.L2-3.13.16Data at Rest 1 point in the score
Protect the confidentiality of CUI while it is at rest in storage.
What an assessor asks to see: Inventory of locations where CUI is stored at rest; Encryption or equivalent protection configuration at those locations; Evidence of protection coverage including databases, file shares and endpoints
Where subcontractors usually fall short: Endpoint encryption in place while servers and shares are unprotected; Storage locations for CUI never fully inventoried; Cloud storage protection assumed from the provider without verification
CMMC L2 SC.L2-3.13.2Security Engineering 5 points in the score
Apply architectural design, software development techniques and systems engineering principles that promote effective information security.
What an assessor asks to see: Documented security architecture and design principles; Secure development standards applied to in house software; Evidence principles are applied in design reviews
Where subcontractors usually fall short: Principles documented but absent from actual design decisions; Secure development standards not applied to acquired or outsourced code; No design review step in the development process
CMMC L2 SC.L2-3.13.3Role Separation 1 point in the score
Separate user functionality from system management functionality so ordinary users are not presented with administrative interfaces.
What an assessor asks to see: Evidence of separation between user and management interfaces; Configuration restricting administrative interface exposure; Architecture showing management plane separation
Where subcontractors usually fall short: Administrative consoles reachable from user networks; Separation logical in name only with shared credentials; Management interfaces exposed to the internet
CMMC L2 SC.L2-3.13.4Shared Resource Control 1 point in the score
Prevent information from being transferred, intentionally or unintentionally, between users through shared system resources.
What an assessor asks to see: Configuration evidence for object reuse and memory or storage clearing; Evidence of isolation between users in shared and virtualized environments; Testing results showing residual data is not accessible
Where subcontractors usually fall short: Shared and virtualized environments assumed isolated without verification; Temporary files and shared directories accessible across users; Object reuse protections disabled for performance
CMMC L2 SC.L2-3.13.5Public-Access System Separation 5 points in the score
Place publicly accessible system components on subnetworks that are physically or logically separated from internal networks.
What an assessor asks to see: Network diagram showing the separated subnetwork for public components; Firewall or routing configuration enforcing the separation; Inventory of publicly accessible components
Where subcontractors usually fall short: Public facing servers residing on internal networks; Separation exists but permissive rules allow broad internal access; New public services deployed outside the segmented zone
CMMC L2 SC.L2-3.13.6Network Communication by Exception 5 points in the score
Deny network communications traffic by default and permit only traffic explicitly allowed by exception.
What an assessor asks to see: Firewall and access control lists showing a default deny posture; Documented and approved exceptions with justification; Review records for permitted exceptions
Where subcontractors usually fall short: Default deny at perimeter only while internal traffic is permit all; Any to any rules present alongside the deny default; Exceptions accumulated with no periodic review
CMMC L2 SC.L2-3.13.7Split Tunneling 1 point in the score
Prevent a remote device from holding a connection to organizational systems while simultaneously connecting through another path to external network resources, the split tunneling case.
What an assessor asks to see: VPN or remote client configuration disabling split tunneling; Evidence the setting is enforced and not user changeable; Coverage across all remote client platforms
Where subcontractors usually fall short: Split tunneling disabled by policy but user configurable; Some client platforms or vendor clients still permit it; Exceptions granted for bandwidth with no compensating control
CMMC L2 SC.L2-3.13.8Data in Transit 3 points in the score
Apply cryptographic protection to prevent unauthorized disclosure of CUI during transmission, unless alternative physical safeguards protect it instead.
What an assessor asks to see: Transmission encryption configuration for CUI bearing paths; Inventory of CUI transmission paths, internal and external; Documented alternative physical safeguards where used
Where subcontractors usually fall short: External transmission encrypted while internal paths are clear; Email carrying CUI sent without protection; Alternative safeguards asserted without documentation
CMMC L2 SC.L2-3.13.9Connections Termination 1 point in the score
Terminate network connections when the associated session ends or after a defined period of inactivity.
What an assessor asks to see: Defined inactivity period for connection termination; Configuration on network devices and services implementing termination; Evidence of termination occurring in logs
Where subcontractors usually fall short: Inactivity period undefined; Termination applied to remote access only; Long lived connections exempt without justification