Frameworks / CMMC 2.0 / SI.L2-3.14.1 CMMC 2.0
System and Information Integrity
CMMC 2.0 SI.L2-3.14.1: Flaw Remediation Identify system flaws, report them, and correct them within a timely period.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 84 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2.1 11.3.2.1 External scans after significant change 12.3.4 12.3.4 Annual review of hardware and software technologies 12.6.1 12.6.1 Formal security awareness program 2.2.1 2.2.1 System configuration standards maintained 6.2.1 6.2.1 Secure development of bespoke and custom software 6.2.4 6.2.4 Engineering techniques against common software attacks 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.3 6.3.3 Timely installation of security patches CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-18.3 Remediate Penetration Test Findings CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.7 Remediate Detected Vulnerabilities SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHAPP-ML3 Patch Applications (ML3) E8-PATCHOS-ML1 Patch Operating Systems (ML1) E8-PATCHOS-ML3 Patch Operating Systems (ML3) 10.2 Nonconformity and corrective action 6.1.3 AI risk treatment 8.3 AI risk treatment 9.1 Monitoring, measurement, analysis and evaluation NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) 5.36 Compliance with policies, rules and standards for information security 8.25 Secure development life cycle 8.8 Management of technical vulnerabilities ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems ASD37-02 Patch applications (Essential) ASD37-19 Patch operating systems (Essential) ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities PV-5 Perform vulnerability assessments C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-22 Testing and Documentation of known Vulnerabilities 8.26 Application security requirements 8.8 Management of technical vulnerabilities Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Art.21.2.g Basic cyber hygiene practices and cybersecurity training CE-SU.2 Automatic Updates Enabled Where Possible CE-SU.3 Critical and High Updates within 14 Days CPS230-P25 Information and Technology Capability and Asset Health AUCDR-IS-4 Formal vulnerability management program CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies 6.9.6 Technical vulnerability management 3.14.7e Verify Correctness of Security Functions Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in System and Information Integrity You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 SI.L2-3.14.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.