CMMC 2.0 Level 2 (Advanced)
Version: CMMC 2.0 (32 CFR Part 170, effective 2024-12-16)
The DoD Cybersecurity Maturity Model Certification level for contractors that handle Controlled Unclassified Information (CUI). Its 110 practices align one to one with NIST SP 800-171 Rev. 2 and are assessed every three years by a C3PAO or, for some contracts, by self-assessment, with annual affirmation.
Where we stand
Controls
58%
Evidence
30%
Policies
20%
70 of 110 clauses mapped to adopted controls · 1 known gap
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| AC Access Control | |||||
| AC.L2-3.1.1 | Authorized Access Control Controls: IAM-01, IAM-07, IAM-09 | Not passing | Current | Not approved | (29 d ago) |
| AC.L2-3.1.2 | Transaction and Function Control Controls: IAM-01, IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| AC.L2-3.1.3 | Control CUI Flow | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.4 | Separation of Duties Controls: BIZ-15, PDP-05 | Passing | Not current | Not approved | (29 d ago) |
| AC.L2-3.1.5 | Least Privilege Controls: IAM-04, IAM-06, IAM-09 | Passing | Not current | Not approved | (29 d ago) |
| AC.L2-3.1.6 | Non-Privileged Account Use Controls: IAM-06 | Passing | Current | Not approved | (29 d ago) |
| AC.L2-3.1.7 | Privileged Functions Controls: IAM-05, IAM-06, MON-02 | Passing | Not current | Not approved | (29 d ago) |
| AC.L2-3.1.8 | Unsuccessful Logon Attempts | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.9 | Privacy and Security Notices | Known gap | Known gap | Known gap | Not yet |
| AC.L2-3.1.10 | Session Lock | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.11 | Session Termination | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.12 | Control Remote Access Controls: IAM-01, IAM-02, MON-02 | Not passing | Not current | Not approved | (8 h ago) |
| AC.L2-3.1.13 | Remote Access Confidentiality Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| AC.L2-3.1.14 | Remote Access Routing Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| AC.L2-3.1.15 | Privileged Remote Access Controls: IAM-06 | Passing | Current | Not approved | (29 d ago) |
| AC.L2-3.1.16 | Wireless Access Authorization | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.17 | Wireless Access Protection | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.18 | Mobile Device Connection | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.19 | Encrypt CUI on Mobile Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| AC.L2-3.1.20 | External Connections Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| AC.L2-3.1.21 | Portable Storage Use | Unmapped | Unmapped | Unmapped | Not yet |
| AC.L2-3.1.22 | Control Public Information Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| AT Awareness and Training | |||||
| AT.L2-3.2.1 | Role-Based Risk Awareness Controls: PEOPLE-04, PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| AT.L2-3.2.2 | Role-Based Training | Unmapped | Unmapped | Unmapped | Not yet |
| AT.L2-3.2.3 | Insider Threat Awareness Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| AU Audit and Accountability | |||||
| AU.L2-3.3.1 | System Auditing Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| AU.L2-3.3.2 | User Accountability | Unmapped | Unmapped | Unmapped | Not yet |
| AU.L2-3.3.3 | Event Review Controls: BIZ-08, MON-02 | Passing | Not current | Not approved | (4 mo ago) |
| AU.L2-3.3.4 | Audit Failure Alerting | Unmapped | Unmapped | Unmapped | Not yet |
| AU.L2-3.3.5 | Audit Correlation Controls: MON-01, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| AU.L2-3.3.6 | Reduction and Reporting Controls: MON-01, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| AU.L2-3.3.7 | Authoritative Time Source | Unmapped | Unmapped | Unmapped | Not yet |
| AU.L2-3.3.8 | Audit Protection | Unmapped | Unmapped | Unmapped | Not yet |
| AU.L2-3.3.9 | Audit Management Controls: IAM-06 | Passing | Current | Not approved | (29 d ago) |
| CM Configuration Management | |||||
| CM.L2-3.4.1 | System Baselining Controls: CLOUD-02, IT-04, IT-05 | Passing | Not current | Not approved | (29 d ago) |
| CM.L2-3.4.2 | Security Configuration Enforcement Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| CM.L2-3.4.3 | System Change Management Controls: PDP-02, PDP-03 | Not passing | Not current | Not approved | (8 h ago) |
| CM.L2-3.4.4 | Security Impact Analysis Controls: PDP-14 | Passing | Current | Approved | (4 mo ago) |
| CM.L2-3.4.5 | Access Restrictions for Change Controls: PDP-05, PDP-06 | Passing | Current | Not approved | (29 d ago) |
| CM.L2-3.4.6 | Least Functionality Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| CM.L2-3.4.7 | Nonessential Functionality Controls: CLOUD-03, CLOUD-04 | Passing | Not current | Approved | Not yet |
| CM.L2-3.4.8 | Application Execution Policy | Unmapped | Unmapped | Unmapped | Not yet |
| CM.L2-3.4.9 | User-Installed Software | Unmapped | Unmapped | Unmapped | Not yet |
| IA Identification and Authentication | |||||
| IA.L2-3.5.1 | Identification Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| IA.L2-3.5.2 | Authentication Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.3 | Multifactor Authentication Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.4 | Replay-Resistant Authentication Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.5 | Identifier Reuse Controls: IAM-07 | Not passing | Current | Not approved | (29 d ago) |
| IA.L2-3.5.6 | Identifier Handling Controls: IAM-09 | Passing | Current | Not approved | (29 d ago) |
| IA.L2-3.5.7 | Password Complexity Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.8 | Password Reuse Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.9 | Temporary Passwords Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| IA.L2-3.5.10 | Cryptographically-Protected Passwords Controls: DATA-03, IAM-01, IAM-03 | Passing | Current | Not approved | (8 h ago) |
| IA.L2-3.5.11 | Obscure Feedback Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| IR Incident Response | |||||
| IR.L2-3.6.1 | Incident Handling Controls: BIZ-02, BIZ-03, BIZ-13 | Passing | Not current | Not approved | (8 h ago) |
| IR.L2-3.6.2 | Incident Reporting Controls: BIZ-02, BIZ-03, BIZ-13 | Passing | Not current | Not approved | (8 h ago) |
| IR.L2-3.6.3 | Incident Response Testing Controls: BIZ-21 | Passing | Current | Approved | (4 mo ago) |
| MA Maintenance | |||||
| MA.L2-3.7.1 | Perform Maintenance Controls: CLOUD-05 | Not passing | Not current | Approved | Not yet |
| MA.L2-3.7.2 | System Maintenance Control | Unmapped | Unmapped | Unmapped | Not yet |
| MA.L2-3.7.3 | Equipment Sanitization | Unmapped | Unmapped | Unmapped | Not yet |
| MA.L2-3.7.4 | Media Inspection | Unmapped | Unmapped | Unmapped | Not yet |
| MA.L2-3.7.5 | Nonlocal Maintenance Controls: IAM-02, MON-02 | Not passing | Not current | Not approved | (8 h ago) |
| MA.L2-3.7.6 | Maintenance Personnel | Unmapped | Unmapped | Unmapped | Not yet |
| MP Media Protection | |||||
| MP.L2-3.8.1 | Media Protection Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| MP.L2-3.8.2 | Media Access | Unmapped | Unmapped | Unmapped | Not yet |
| MP.L2-3.8.3 | Media Disposal Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| MP.L2-3.8.4 | Media Markings Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| MP.L2-3.8.5 | Media Accountability Controls: IT-02, IT-04 | Not passing | Not current | Not approved | Not yet |
| MP.L2-3.8.6 | Portable Storage Encryption Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| MP.L2-3.8.7 | Removable Media | Unmapped | Unmapped | Unmapped | Not yet |
| MP.L2-3.8.8 | Shared Media | Unmapped | Unmapped | Unmapped | Not yet |
| MP.L2-3.8.9 | Protect Backups Controls: DATA-02, DATA-13 | Passing | Not current | Not approved | (29 d ago) |
| PS Personnel Security | |||||
| PS.L2-3.9.1 | Screen Individuals Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| PS.L2-3.9.2 | Personnel Actions Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| PE Physical Protection | |||||
| PE.L2-3.10.1 | Limit Physical Access Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| PE.L2-3.10.2 | Monitor Facility Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| PE.L2-3.10.3 | Escort Visitors | Unmapped | Unmapped | Unmapped | Not yet |
| PE.L2-3.10.4 | Physical Access Logs | Unmapped | Unmapped | Unmapped | Not yet |
| PE.L2-3.10.5 | Manage Physical Access | Unmapped | Unmapped | Unmapped | Not yet |
| PE.L2-3.10.6 | Alternative Work Sites | Unmapped | Unmapped | Unmapped | Not yet |
| RA Risk Assessment | |||||
| RA.L2-3.11.1 | Risk Assessments Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| RA.L2-3.11.2 | Vulnerability Scan Controls: MON-04, MON-05 | Not passing | Not current | Not approved | (8 h ago) |
| RA.L2-3.11.3 | Vulnerability Remediation Controls: CLOUD-05, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| CA Security Assessment | |||||
| CA.L2-3.12.1 | Security Control Assessment Controls: BIZ-08, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| CA.L2-3.12.2 | Plans of Action Controls: BIZ-09 | Passing | Not current | Approved | Not yet |
| CA.L2-3.12.3 | Security Control Monitoring Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| CA.L2-3.12.4 | System Security Plan | Unmapped | Unmapped | Unmapped | Not yet |
| SC System and Communications Protection | |||||
| SC.L2-3.13.1 | Boundary Protection Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| SC.L2-3.13.2 | Security Engineering | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.3 | Role Separation Controls: IAM-06 | Passing | Current | Not approved | (29 d ago) |
| SC.L2-3.13.4 | Shared Resource Control | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.5 | Public-Access System Separation | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.6 | Network Communication by Exception Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| SC.L2-3.13.7 | Split Tunneling | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.8 | Data in Transit Controls: CLOUD-01, DATA-03 | Passing | Current | Not approved | (8 h ago) |
| SC.L2-3.13.9 | Connections Termination | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.10 | Key Management | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.11 | CUI Encryption Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| SC.L2-3.13.12 | Collaborative Device Control | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.13 | Mobile Code | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.14 | Voice over Internet Protocol | Unmapped | Unmapped | Unmapped | Not yet |
| SC.L2-3.13.15 | Communications Authenticity Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| SC.L2-3.13.16 | Data at Rest Controls: DATA-02, IT-02 | Not passing | Not current | Not approved | Not yet |
| SI System and Information Integrity | |||||
| SI.L2-3.14.1 | Flaw Remediation Controls: CLOUD-05, IT-03, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| SI.L2-3.14.2 | Malicious Code Protection | Unmapped | Unmapped | Unmapped | Not yet |
| SI.L2-3.14.3 | Security Alerts and Advisories | Unmapped | Unmapped | Unmapped | Not yet |
| SI.L2-3.14.4 | Update Malicious Code Protection | Unmapped | Unmapped | Unmapped | Not yet |
| SI.L2-3.14.5 | System and File Scanning Controls: MON-05 | Not passing | Not current | Not approved | (3 mo ago) |
| SI.L2-3.14.6 | Monitor Communications for Attacks Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| SI.L2-3.14.7 | Identify Unauthorized Use Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
