← Frameworks / CMMC 2.0 / Control Mappings

Cybersecurity Maturity Model Certification 2.0 Level 2

US Department of Defense cybersecurity certification framework for the defense industrial base. Level 2 aligns to NIST SP 800-171 Rev 2 (110 security requirements) across 14 domains: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Required for contractors handling Controlled Unclassified Information (CUI). Third-party assessment (C3PAO) mandatory.

AC Access Control

Control Name CMMC 2.0 References
AC-01 Policy and Procedures
AC
AC-02 Account Management
AC
AC-03 Access Enforcement
AC
AC-04 Information Flow Enforcement
AC
AC-05 Separation of Duties
AC
AC-06 Least Privilege
AC
AC-07 Unsuccessful Logon Attempts
AC
AC-08 System Use Notification
AC
AC-09 Previous Logon Notification
AC
AC-10 Concurrent Session Control
AC
AC-11 Device Lock
AC
AC-12 Session Termination
AC
AC-13 Supervision and Review — Access Control
AC
AC-14 Permitted Actions Without Identification or Authentication
AC
AC-16 Security and Privacy Attributes
AC
AC-17 Remote Access
AC
AC-18 Wireless Access
AC
AC-19 Access Control for Mobile Devices
AC
AC-20 Use of External Systems
AC
AC-21 Information Sharing
AC
AC-22 Publicly Accessible Content
AC
AC-24 Access Control Decisions
AC

AT Awareness and Training

Control Name CMMC 2.0 References
AT-01 Policy and Procedures
AT
AT-02 Literacy Training and Awareness
AT
AT-03 Role-based Training
AT
AT-04 Training Records
AT
AT-05 Contacts with Security Groups and Associations
AT
AT-06 Training Feedback
AT

AU Audit and Accountability

Control Name CMMC 2.0 References
AU-01 Policy and Procedures
AU
AU-02 Event Logging
AU
AU-03 Content of Audit Records
AU
AU-04 Audit Log Storage Capacity
AU
AU-05 Response to Audit Logging Process Failures
AU
AU-06 Audit Record Review, Analysis, and Reporting
AU
AU-07 Audit Record Reduction and Report Generation
AU
AU-08 Time Stamps
AU
AU-09 Protection of Audit Information
AU
AU-10 Non-repudiation
AU
AU-11 Audit Record Retention
AU
AU-12 Audit Record Generation
AU
AU-13 Monitoring for Information Disclosure
AU
AU-14 Session Audit
AU
AU-16 Cross-organizational Audit Logging
AU

CA Security Assessment and Authorization

Control Name CMMC 2.0 References
CA-01 Policy and Procedures
CA
CA-02 Control Assessments
CARA
CA-03 Information Exchange
CA
CA-04 Security Certification
CA
CA-05 Plan of Action and Milestones
CA
CA-06 Authorization
CA
CA-07 Continuous Monitoring
CA
CA-08 Penetration Testing
CARA
CA-09 Internal System Connections
CA

CM Configuration Management

Control Name CMMC 2.0 References
CM-01 Policy and Procedures
CM
CM-02 Baseline Configuration
CM
CM-03 Configuration Change Control
CM
CM-04 Impact Analyses
CM
CM-05 Access Restrictions for Change
CM
CM-06 Configuration Settings
CM
CM-07 Least Functionality
CM
CM-08 System Component Inventory
CM
CM-09 Configuration Management Plan
CM
CM-10 Software Usage Restrictions
CM
CM-11 User-installed Software
CM
CM-12 Information Location
CM
CM-13 Data Action Mapping
CM
CM-14 Signed Components
CM

CP Contingency Planning

Control Name CMMC 2.0 References
CP-09 System Backup
MP

IA Identification and Authentication

Control Name CMMC 2.0 References
IA-01 Policy and Procedures
IA
IA-02 Identification and Authentication (Organizational Users)
ACIA
IA-03 Device Identification and Authentication
IA
IA-04 Identifier Management
ACIA
IA-05 Authenticator Management
ACIA
IA-06 Authentication Feedback
IA
IA-07 Cryptographic Module Authentication
IA
IA-08 Identification and Authentication (Non-organizational Users)
IA
IA-09 Service Identification and Authentication
IA
IA-10 Adaptive Authentication
IA
IA-11 Re-authentication
IA
IA-12 Identity Proofing
IA

IR Incident Response

Control Name CMMC 2.0 References
IR-01 Policy and Procedures
IR
IR-02 Incident Response Training
IR
IR-03 Incident Response Testing
IR
IR-04 Incident Handling
IR
IR-05 Incident Monitoring
IR
IR-06 Incident Reporting
IR
IR-07 Incident Response Assistance
IR
IR-08 Incident Response Plan
IR
IR-09 Information Spillage Response
IR

MA Maintenance

Control Name CMMC 2.0 References
MA-01 Policy and Procedures
MA
MA-02 Controlled Maintenance
MA
MA-03 Maintenance Tools
MA
MA-04 Nonlocal Maintenance
MA
MA-05 Maintenance Personnel
MA
MA-06 Timely Maintenance
MA
MA-07 Field Maintenance
MA

MP Media Protection

Control Name CMMC 2.0 References
MP-01 Policy and Procedures
MP
MP-02 Media Access
MP
MP-03 Media Marking
MP
MP-04 Media Storage
MP
MP-05 Media Transport
MP
MP-06 Media Sanitization
MP
MP-07 Media Use
MP
MP-08 Media Downgrading
MP

PE Physical and Environmental Protection

Control Name CMMC 2.0 References
PE-01 Policy and Procedures
PE
PE-02 Physical Access Authorizations
PE
PE-03 Physical Access Control
PE
PE-04 Access Control for Transmission
PE
PE-05 Access Control for Output Devices
PE
PE-06 Monitoring Physical Access
PE
PE-07 Visitor Control
PE
PE-08 Visitor Access Records
PE
PE-09 Power Equipment and Cabling
PE
PE-10 Emergency Shutoff
PE
PE-11 Emergency Power
PE
PE-12 Emergency Lighting
PE
PE-13 Fire Protection
PE
PE-14 Environmental Controls
PE
PE-15 Water Damage Protection
PE
PE-16 Delivery and Removal
PE
PE-17 Alternate Work Site
PE
PE-18 Location of System Components
PE

PL Planning

Control Name CMMC 2.0 References
PL-01 Policy and Procedures
CA
PL-02 System Security and Privacy Plans
CA
PL-04 Rules of Behavior
AT

PM Program Management

Control Name CMMC 2.0 References
PM-06 Measures of Performance
CA
PM-09 Risk Management Strategy
RA
PM-10 Authorization Process
CA
PM-12 Insider Threat Program
IR
PM-13 Security and Privacy Workforce
AT
PM-14 Testing, Training, and Monitoring
ATCA
PM-28 Risk Framing
RA

PS Personnel Security

Control Name CMMC 2.0 References
PS-01 Policy and Procedures
PS
PS-02 Position Risk Designation
PS
PS-03 Personnel Screening
PS
PS-04 Personnel Termination
PS
PS-05 Personnel Transfer
PS
PS-06 Access Agreements
PS
PS-07 External Personnel Security
PS
PS-08 Personnel Sanctions
PS
PS-09 Position Descriptions
PS

RA Risk Assessment

Control Name CMMC 2.0 References
RA-01 Policy and Procedures
RA
RA-02 Security Categorization
RA
RA-03 Risk Assessment
RA
RA-04 Risk Assessment Update
RA
RA-05 Vulnerability Monitoring and Scanning
RASI
RA-06 Technical Surveillance Countermeasures Survey
RA
RA-07 Risk Response
RA
RA-08 Privacy Impact Assessments
RA
RA-09 Criticality Analysis
RA
RA-10 Threat Hunting
RA

SA System and Services Acquisition

Control Name CMMC 2.0 References
SA-08 Security and Privacy Engineering Principles
SC
SA-10 Developer Configuration Management
CM

SC System and Communications Protection

Control Name CMMC 2.0 References
SC-01 Policy and Procedures
SC
SC-02 Separation of System and User Functionality
SC
SC-03 Security Function Isolation
SC
SC-04 Information in Shared System Resources
SC
SC-05 Denial-of-service Protection
SC
SC-07 Boundary Protection
SC
SC-08 Transmission Confidentiality and Integrity
SC
SC-10 Network Disconnect
SC
SC-11 Trusted Path
SC
SC-12 Cryptographic Key Establishment and Management
SC
SC-13 Cryptographic Protection
SC
SC-15 Collaborative Computing Devices and Applications
SC
SC-17 Public Key Infrastructure Certificates
SC
SC-18 Mobile Code
SC
SC-20 Secure Name/Address Resolution Service (Authoritative Source)
SC
SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC
SC-22 Architecture and Provisioning for Name/Address Resolution Service
SC
SC-23 Session Authenticity
SC
SC-28 Protection of Information at Rest
MPSC
SC-39 Process Isolation
SC

SI System and Information Integrity

Control Name CMMC 2.0 References
SI-01 Policy and Procedures
SI
SI-02 Flaw Remediation
SI
SI-03 Malicious Code Protection
SI
SI-04 System Monitoring
AUSI
SI-05 Security Alerts, Advisories, and Directives
IRSI
SI-06 Security and Privacy Function Verification
SI
SI-07 Software, Firmware, and Information Integrity
SI
SI-08 Spam Protection
SI
SI-10 Information Input Validation
SI
SI-11 Error Handling
SI
SI-12 Information Management and Retention
SI
SI-16 Memory Protection
SI