Frameworks / CMMC 2.0 / IR.L2-3.6.1 CMMC 2.0
Incident Response
CMMC 2.0 IR.L2-3.6.1: Incident Handling Operate an incident handling capability covering preparation, detection, analysis, containment, recovery and user response.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 101 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.3 Roles, responsibilities and authorities 8.4 Business continuity plans and procedures 8.4.1 General 8.4.2 Response structure 8.4.3 Warning and communication 8.4.4 Business continuity plans 8.4.5 Recovery 8.5 Exercise programme CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.5 Assign Key Roles and Responsibilities CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.8 Conduct Post-Incident Reviews CIS-17.9 Establish and Maintain Security Incident Thresholds ASBv3-GS-7 Define and implement logging, threat detection and incident response strategy ASBv3-IR-1 Preparation - update incident response plan and handling process ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence SEC10-BP01 Identify key personnel and external resources SEC10-BP02 Develop incident management plans SEC10-BP03 Prepare forensic capabilities SEC10-BP04 Develop and test security incident response playbooks SEC10-BP08 Establish a framework for learning from incidents IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-7 Incident Response Assistance IR-8 Incident Response Plan IR-4 Incident Handling IR-4(1) Automated Incident Handling Processes IR-5 Incident Monitoring IR-7 Incident Response Assistance IR-8 Incident Response Plan SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches SOC2-P6.6 P6.6 Notifying breaches and incidents ASD37-28 Continuous incident detection and response (Excellent) ASD37-30 Endpoint detection and response (Very Good) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents CPS230-20 Prevention, Adaptation and Return to Normal Operations CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-P41 BCP Execution Capability and Tolerance Breach Reporting CPS234-30 Detection and Response Mechanisms CPS234-P24 Information Security Response Plans CPS234-P25 Response Plan Content and Escalation Mechanisms 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 3.6.1e Establish Security Operations Center (SOC) 3.6.2e Establish and Maintain a Cyber Incident Response Team 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.1 12.10.1 Incident response plan ready for activation E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure AEO-12 Crisis Management and Incident Recovery CFTC-SS-16 Security Incident Response Plan and Testing 6.13.1 Management of information security incidents and improvements Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Incident Response You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 IR.L2-3.6.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.