United States

CMMC 2.0

110 controls. 48 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

110 controls 48 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AC.L2-3.1.1Authorized Access Control32
AC.L2-3.1.10Session Lock16
AC.L2-3.1.11Session Termination16
AC.L2-3.1.12Control Remote Access25
AC.L2-3.1.13Remote Access Confidentiality20
AC.L2-3.1.14Remote Access Routing19
AC.L2-3.1.15Privileged Remote Access21
AC.L2-3.1.16Wireless Access Authorization15
AC.L2-3.1.17Wireless Access Protection13
AC.L2-3.1.18Mobile Device Connection19
AC.L2-3.1.19Encrypt CUI on Mobile17
AC.L2-3.1.2Transaction & Function Control25
AC.L2-3.1.20External Connections25
AC.L2-3.1.21Portable Storage Use19
AC.L2-3.1.22Control Public Information20
AC.L2-3.1.3Control CUI Flow24
AC.L2-3.1.4Separation of Duties24
AC.L2-3.1.5Least Privilege28
AC.L2-3.1.6Non-Privileged Account Use23
AC.L2-3.1.7Privileged Functions23
AC.L2-3.1.8Unsuccessful Logon Attempts18
AC.L2-3.1.9Privacy & Security Notices12
AT.L2-3.2.1Role-Based Risk Awareness34
AT.L2-3.2.2Role-Based Training32
AT.L2-3.2.3Insider Threat Awareness21
AU.L2-3.3.1System Auditing28
AU.L2-3.3.2User Accountability25
AU.L2-3.3.3Event Review24
AU.L2-3.3.4Audit Failure Alerting17
AU.L2-3.3.5Audit Correlation25
AU.L2-3.3.6Reduction & Reporting19
AU.L2-3.3.7Time Stamps & Synchronization16
AU.L2-3.3.8Audit Protection21
AU.L2-3.3.9Audit Management21
CA.L2-3.12.1Security Control Assessment35
CA.L2-3.12.2Plan of Action31
CA.L2-3.12.3Security Control Monitoring38
CA.L2-3.12.4System Security Plan32
CM.L2-3.4.1System Baselining31
CM.L2-3.4.2Security Configuration Enforcement27
CM.L2-3.4.3System Change Management24
CM.L2-3.4.4Security Impact Analysis25
CM.L2-3.4.5Access Restrictions for Change22
CM.L2-3.4.6Least Functionality24
CM.L2-3.4.7Nonessential Functionality22
CM.L2-3.4.8Application Execution Policy23
CM.L2-3.4.9User-Installed Software28
IA.L2-3.5.1Identification32
IA.L2-3.5.10Cryptographically-Protected Passwords20
IA.L2-3.5.11Obscure Feedback13
IA.L2-3.5.2Authentication29
IA.L2-3.5.3Multifactor Authentication24
IA.L2-3.5.4Replay-Resistant Authentication18
IA.L2-3.5.5Identifier Reuse18
IA.L2-3.5.6Identifier Handling23
IA.L2-3.5.7Password Complexity21
IA.L2-3.5.8Password Reuse16
IA.L2-3.5.9Temporary Passwords15
IR.L2-3.6.1Incident Handling32
IR.L2-3.6.2Incident Reporting35
IR.L2-3.6.3Incident Response Testing29
MA.L2-3.7.1Perform Maintenance18
MA.L2-3.7.2System Maintenance Control18
MA.L2-3.7.3Equipment Sanitization21
MA.L2-3.7.4Media Inspection16
MA.L2-3.7.5Nonlocal Maintenance21
MA.L2-3.7.6Maintenance Personnel17
MP.L2-3.8.1Media Protection25
MP.L2-3.8.2Media Access20
MP.L2-3.8.3Media Disposal27
MP.L2-3.8.4Media Markings18
MP.L2-3.8.5Media Accountability19
MP.L2-3.8.6Portable Storage Encryption18
MP.L2-3.8.7Removable Media19
MP.L2-3.8.8Shared Media15
MP.L2-3.8.9Protect Backups26
PE.L2-3.10.1Limit Physical Access23
PE.L2-3.10.2Monitor Facility22
PE.L2-3.10.3Escort Visitors21
PE.L2-3.10.4Physical Access Logs20
PE.L2-3.10.5Manage Physical Access22
PE.L2-3.10.6Alternative Work Sites19
PS.L2-3.9.1Screen Individuals26
PS.L2-3.9.2Personnel Actions27
RA.L2-3.11.1Risk Assessments33
RA.L2-3.11.2Vulnerability Scan30
RA.L2-3.11.3Vulnerability Remediation34
SC.L2-3.13.1Boundary Protection26
SC.L2-3.13.10Key Management21
SC.L2-3.13.11CUI Encryption23
SC.L2-3.13.12Collaborative Device Control12
SC.L2-3.13.13Mobile Code18
SC.L2-3.13.14Voice over Internet Protocol3
SC.L2-3.13.15Communications Authenticity23
SC.L2-3.13.16Data at Rest24
SC.L2-3.13.2Security Engineering24
SC.L2-3.13.3Role Separation21
SC.L2-3.13.4Shared Resource Control16
SC.L2-3.13.5Public-Access System Separation25
SC.L2-3.13.6Network Communication by Exception20
SC.L2-3.13.7Split Tunneling9
SC.L2-3.13.8Data in Transit26
SC.L2-3.13.9Connections Termination14
SI.L2-3.14.1Flaw Remediation33
SI.L2-3.14.2Malicious Code Protection30
SI.L2-3.14.3Security Alerts & Advisories27
SI.L2-3.14.4Update Malicious Code Protection26
SI.L2-3.14.5System & File Scanning24
SI.L2-3.14.6Monitor Communications for Attacks26
SI.L2-3.14.7Identify Unauthorized Use24

Tell me when CMMC 2.0 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Pre-employment screening records
  • CUI protection on personnel transfer/termination
  • Screening for sensitive roles
  • Onboarding/offboarding access controls
  • Third party screening procedure
  • Contractual clauses
  • Baseline configurations + inventory
  • Change control records + security impact analysis
  • Least-functionality/allowlisting + user-installed-software restriction
  • Configuration baselines

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for CMMC 2.0, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition