Frameworks / CMMC 2.0 / CM.L2-3.4.1 CMMC 2.0
Configuration Management
CMMC 2.0 CM.L2-3.4.1: System Baselining Establish and maintain baseline configurations and inventories of systems, covering hardware, software, firmware and documentation, across the system life cycle.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 77 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.1 1.2.1 Ruleset configuration standards for NSCs 1.2.8 1.2.8 NSC configuration files secured and consistent 11.2.2 11.2.2 Inventory of authorized wireless access points 12.5.1 12.5.1 Inventory of in-scope system components 2.2.1 2.2.1 System configuration standards maintained 2.2.6 2.2.6 System security parameters configured against misuse 6.3.2 6.3.2 Inventory of bespoke software and components CM-2 Baseline Configuration CM-2(2) Automation Support for Accuracy and Currency CM-8 System Component Inventory CM-8(1) Updates During Installation and Removal CM-8(3) Automated Unauthorized Component Detection CM-9 Configuration Management Plan CM-2 Baseline Configuration CM-2(2) Automation Support for Accuracy and Currency CM-8 System Component Inventory CM-8(1) Updates During Installation and Removal CM-8(3) Automated Unauthorized Component Detection CM-9 Configuration Management Plan CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-2.1 Establish and Maintain a Software Inventory CIS-4.1 Establish and Maintain a Secure Configuration Process CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems AM-3 Ensure security of asset lifecycle management ASBv3-AM-1 Track asset inventory and their risks ASBv3-PV-1 Define and establish secure configurations ASBv3-PV-3 Define and establish secure configurations for compute resources C5-AM-01 Asset Inventory C5-AM-03 Commissioning of Hardware C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening C5-PSS-11 Images for Virtual Machines and Containers NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-PR.PS-01 Configuration management practices are established and applied ASD37-11 Operating system hardening (Very Good) ASD37-36 System recovery capabilities (Very Good) SEC01-BP06 Automate deployment of standard security controls SEC06-BP02 Provision compute from hardened images 5.9 Inventory of information and other associated assets 8.9 Configuration management 5.9 Inventory of information and other associated assets 8.9 Configuration management Art.21.2.g Basic cyber hygiene practices and cybersecurity training Art.21.2.i Human resources security, access control policies and asset management 3.14.4e Refresh Systems and Components from a Trusted Baseline 3.4.3e Automated Inventory of System Components SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-UAH-ML2 User Application Hardening - Maturity Level 2 CPS230-P25 Information and Technology Capability and Asset Health AUCDR-IS-2 Secure the network and systems within the data environment STIG-PGM-1 STIG/SRG applicability determination and baseline 6.5.1 Responsibility for assets A.4.5 System and computing resources Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Configuration Management You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 CM.L2-3.4.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.