FintastIQTrust Center
LoginBook a Consultation
Framework

CMMC 2.0 Level 2 (Advanced)

Version: CMMC 2.0 (32 CFR Part 170, effective 2024-12-16)

The DoD Cybersecurity Maturity Model Certification level for contractors that handle Controlled Unclassified Information (CUI). Its 110 practices align one to one with NIST SP 800-171 Rev. 2 and are assessed every three years by a C3PAO or, for some contracts, by self-assessment, with annual affirmation.

Official source

Summary

Where we stand

Controls
58%
Evidence
30%
Policies
20%

70 of 110 clauses mapped to adopted controls · 1 known gap

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
AC Access Control
AC.L2-3.1.1Authorized Access Control
Controls: IAM-01, IAM-07, IAM-09
Not passingCurrentNot approved(29 d ago)
AC.L2-3.1.2Transaction and Function Control
Controls: IAM-01, IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
AC.L2-3.1.3Control CUI FlowUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.4Separation of Duties
Controls: BIZ-15, PDP-05
PassingNot currentNot approved(29 d ago)
AC.L2-3.1.5Least Privilege
Controls: IAM-04, IAM-06, IAM-09
PassingNot currentNot approved(29 d ago)
AC.L2-3.1.6Non-Privileged Account Use
Controls: IAM-06
PassingCurrentNot approved(29 d ago)
AC.L2-3.1.7Privileged Functions
Controls: IAM-05, IAM-06, MON-02
PassingNot currentNot approved(29 d ago)
AC.L2-3.1.8Unsuccessful Logon AttemptsUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.9Privacy and Security NoticesKnown gapKnown gapKnown gapNot yet
AC.L2-3.1.10Session LockUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.11Session TerminationUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.12Control Remote Access
Controls: IAM-01, IAM-02, MON-02
Not passingNot currentNot approved(8 h ago)
AC.L2-3.1.13Remote Access Confidentiality
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
AC.L2-3.1.14Remote Access Routing
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
AC.L2-3.1.15Privileged Remote Access
Controls: IAM-06
PassingCurrentNot approved(29 d ago)
AC.L2-3.1.16Wireless Access AuthorizationUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.17Wireless Access ProtectionUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.18Mobile Device ConnectionUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.19Encrypt CUI on Mobile
Controls: IT-02
Not passingNot currentApprovedNot yet
AC.L2-3.1.20External Connections
Controls: VEND-03
PassingNot currentNot approvedNot yet
AC.L2-3.1.21Portable Storage UseUnmappedUnmappedUnmappedNot yet
AC.L2-3.1.22Control Public Information
Controls: DATA-01
PassingNot currentNot approvedNot yet
AT Awareness and Training
AT.L2-3.2.1Role-Based Risk Awareness
Controls: PEOPLE-04, PEOPLE-06
Not passingCurrentApproved(8 h ago)
AT.L2-3.2.2Role-Based TrainingUnmappedUnmappedUnmappedNot yet
AT.L2-3.2.3Insider Threat Awareness
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
AU Audit and Accountability
AU.L2-3.3.1System Auditing
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
AU.L2-3.3.2User AccountabilityUnmappedUnmappedUnmappedNot yet
AU.L2-3.3.3Event Review
Controls: BIZ-08, MON-02
PassingNot currentNot approved(4 mo ago)
AU.L2-3.3.4Audit Failure AlertingUnmappedUnmappedUnmappedNot yet
AU.L2-3.3.5Audit Correlation
Controls: MON-01, MON-03
Not passingNot currentNot approved(3 mo ago)
AU.L2-3.3.6Reduction and Reporting
Controls: MON-01, MON-03
Not passingNot currentNot approved(3 mo ago)
AU.L2-3.3.7Authoritative Time SourceUnmappedUnmappedUnmappedNot yet
AU.L2-3.3.8Audit ProtectionUnmappedUnmappedUnmappedNot yet
AU.L2-3.3.9Audit Management
Controls: IAM-06
PassingCurrentNot approved(29 d ago)
CM Configuration Management
CM.L2-3.4.1System Baselining
Controls: CLOUD-02, IT-04, IT-05
PassingNot currentNot approved(29 d ago)
CM.L2-3.4.2Security Configuration Enforcement
Controls: CLOUD-04
PassingNot currentApprovedNot yet
CM.L2-3.4.3System Change Management
Controls: PDP-02, PDP-03
Not passingNot currentNot approved(8 h ago)
CM.L2-3.4.4Security Impact Analysis
Controls: PDP-14
PassingCurrentApproved(4 mo ago)
CM.L2-3.4.5Access Restrictions for Change
Controls: PDP-05, PDP-06
PassingCurrentNot approved(29 d ago)
CM.L2-3.4.6Least Functionality
Controls: CLOUD-04
PassingNot currentApprovedNot yet
CM.L2-3.4.7Nonessential Functionality
Controls: CLOUD-03, CLOUD-04
PassingNot currentApprovedNot yet
CM.L2-3.4.8Application Execution PolicyUnmappedUnmappedUnmappedNot yet
CM.L2-3.4.9User-Installed SoftwareUnmappedUnmappedUnmappedNot yet
IA Identification and Authentication
IA.L2-3.5.1Identification
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
IA.L2-3.5.2Authentication
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
IA.L2-3.5.3Multifactor Authentication
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
IA.L2-3.5.4Replay-Resistant Authentication
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
IA.L2-3.5.5Identifier Reuse
Controls: IAM-07
Not passingCurrentNot approved(29 d ago)
IA.L2-3.5.6Identifier Handling
Controls: IAM-09
PassingCurrentNot approved(29 d ago)
IA.L2-3.5.7Password Complexity
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
IA.L2-3.5.8Password Reuse
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
IA.L2-3.5.9Temporary Passwords
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
IA.L2-3.5.10Cryptographically-Protected Passwords
Controls: DATA-03, IAM-01, IAM-03
PassingCurrentNot approved(8 h ago)
IA.L2-3.5.11Obscure Feedback
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
IR Incident Response
IR.L2-3.6.1Incident Handling
Controls: BIZ-02, BIZ-03, BIZ-13
PassingNot currentNot approved(8 h ago)
IR.L2-3.6.2Incident Reporting
Controls: BIZ-02, BIZ-03, BIZ-13
PassingNot currentNot approved(8 h ago)
IR.L2-3.6.3Incident Response Testing
Controls: BIZ-21
PassingCurrentApproved(4 mo ago)
MA Maintenance
MA.L2-3.7.1Perform Maintenance
Controls: CLOUD-05
Not passingNot currentApprovedNot yet
MA.L2-3.7.2System Maintenance ControlUnmappedUnmappedUnmappedNot yet
MA.L2-3.7.3Equipment SanitizationUnmappedUnmappedUnmappedNot yet
MA.L2-3.7.4Media InspectionUnmappedUnmappedUnmappedNot yet
MA.L2-3.7.5Nonlocal Maintenance
Controls: IAM-02, MON-02
Not passingNot currentNot approved(8 h ago)
MA.L2-3.7.6Maintenance PersonnelUnmappedUnmappedUnmappedNot yet
MP Media Protection
MP.L2-3.8.1Media Protection
Controls: IT-02
Not passingNot currentApprovedNot yet
MP.L2-3.8.2Media AccessUnmappedUnmappedUnmappedNot yet
MP.L2-3.8.3Media Disposal
Controls: DATA-05
PassingNot currentNot approvedNot yet
MP.L2-3.8.4Media Markings
Controls: DATA-01
PassingNot currentNot approvedNot yet
MP.L2-3.8.5Media Accountability
Controls: IT-02, IT-04
Not passingNot currentNot approvedNot yet
MP.L2-3.8.6Portable Storage Encryption
Controls: IT-02
Not passingNot currentApprovedNot yet
MP.L2-3.8.7Removable MediaUnmappedUnmappedUnmappedNot yet
MP.L2-3.8.8Shared MediaUnmappedUnmappedUnmappedNot yet
MP.L2-3.8.9Protect Backups
Controls: DATA-02, DATA-13
PassingNot currentNot approved(29 d ago)
PS Personnel Security
PS.L2-3.9.1Screen Individuals
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
PS.L2-3.9.2Personnel Actions
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
PE Physical Protection
PE.L2-3.10.1Limit Physical Access
Controls: PHYS-01
PassingNot currentNot approvedNot yet
PE.L2-3.10.2Monitor Facility
Controls: PHYS-01
PassingNot currentNot approvedNot yet
PE.L2-3.10.3Escort VisitorsUnmappedUnmappedUnmappedNot yet
PE.L2-3.10.4Physical Access LogsUnmappedUnmappedUnmappedNot yet
PE.L2-3.10.5Manage Physical AccessUnmappedUnmappedUnmappedNot yet
PE.L2-3.10.6Alternative Work SitesUnmappedUnmappedUnmappedNot yet
RA Risk Assessment
RA.L2-3.11.1Risk Assessments
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
RA.L2-3.11.2Vulnerability Scan
Controls: MON-04, MON-05
Not passingNot currentNot approved(8 h ago)
RA.L2-3.11.3Vulnerability Remediation
Controls: CLOUD-05, MON-06
Not passingNot currentNot approved(3 mo ago)
CA Security Assessment
CA.L2-3.12.1Security Control Assessment
Controls: BIZ-08, MON-04
Not passingNot currentNot approved(8 h ago)
CA.L2-3.12.2Plans of Action
Controls: BIZ-09
PassingNot currentApprovedNot yet
CA.L2-3.12.3Security Control Monitoring
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
CA.L2-3.12.4System Security PlanUnmappedUnmappedUnmappedNot yet
SC System and Communications Protection
SC.L2-3.13.1Boundary Protection
Controls: CLOUD-03
PassingNot currentApprovedNot yet
SC.L2-3.13.2Security EngineeringUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.3Role Separation
Controls: IAM-06
PassingCurrentNot approved(29 d ago)
SC.L2-3.13.4Shared Resource ControlUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.5Public-Access System SeparationUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.6Network Communication by Exception
Controls: CLOUD-03
PassingNot currentApprovedNot yet
SC.L2-3.13.7Split TunnelingUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.8Data in Transit
Controls: CLOUD-01, DATA-03
PassingCurrentNot approved(8 h ago)
SC.L2-3.13.9Connections TerminationUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.10Key ManagementUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.11CUI Encryption
Controls: DATA-06
Not passingNot currentNot approvedNot yet
SC.L2-3.13.12Collaborative Device ControlUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.13Mobile CodeUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.14Voice over Internet ProtocolUnmappedUnmappedUnmappedNot yet
SC.L2-3.13.15Communications Authenticity
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
SC.L2-3.13.16Data at Rest
Controls: DATA-02, IT-02
Not passingNot currentNot approvedNot yet
SI System and Information Integrity
SI.L2-3.14.1Flaw Remediation
Controls: CLOUD-05, IT-03, MON-06
Not passingNot currentNot approved(8 h ago)
SI.L2-3.14.2Malicious Code ProtectionUnmappedUnmappedUnmappedNot yet
SI.L2-3.14.3Security Alerts and AdvisoriesUnmappedUnmappedUnmappedNot yet
SI.L2-3.14.4Update Malicious Code ProtectionUnmappedUnmappedUnmappedNot yet
SI.L2-3.14.5System and File Scanning
Controls: MON-05
Not passingNot currentNot approved(3 mo ago)
SI.L2-3.14.6Monitor Communications for Attacks
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
SI.L2-3.14.7Identify Unauthorized Use
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)