Back to Frameworks

CMMC 2.0

United States
v2.0
14 domains
110 controls

Cybersecurity Maturity Model Certification for defense industrial base

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (14)

Access Control

22 controls
Controls in the Access Control domain of CMMC 2.022 controls
CodeTitle
AC.L2-3.1.1Authorized Access Control
AC.L2-3.1.10Session Lock
AC.L2-3.1.11Session Termination
AC.L2-3.1.12Control Remote Access
AC.L2-3.1.13Remote Access Confidentiality
AC.L2-3.1.14Remote Access Routing
AC.L2-3.1.15Privileged Remote Access
AC.L2-3.1.16Wireless Access Authorization
AC.L2-3.1.17Wireless Access Protection
AC.L2-3.1.18Mobile Device Connection
AC.L2-3.1.19Encrypt CUI on Mobile
AC.L2-3.1.2Transaction & Function Control
AC.L2-3.1.20External Connections
AC.L2-3.1.21Portable Storage Use
AC.L2-3.1.22Control Public Information
AC.L2-3.1.3Control CUI Flow
AC.L2-3.1.4Separation of Duties
AC.L2-3.1.5Least Privilege
AC.L2-3.1.6Non-Privileged Account Use
AC.L2-3.1.7Privileged Functions
AC.L2-3.1.8Unsuccessful Logon Attempts
AC.L2-3.1.9Privacy & Security Notices

Audit and Accountability

9 controls
Controls in the Audit and Accountability domain of CMMC 2.09 controls
CodeTitle
AU.L2-3.3.1System Auditing
AU.L2-3.3.2User Accountability
AU.L2-3.3.3Event Review
AU.L2-3.3.4Audit Failure Alerting
AU.L2-3.3.5Audit Correlation
AU.L2-3.3.6Reduction & Reporting
AU.L2-3.3.7Time Stamps & Synchronization
AU.L2-3.3.8Audit Protection
AU.L2-3.3.9Audit Management

Awareness and Training

3 controls
Controls in the Awareness and Training domain of CMMC 2.03 controls
CodeTitle
AT.L2-3.2.1Role-Based Risk Awareness
AT.L2-3.2.2Role-Based Training
AT.L2-3.2.3Insider Threat Awareness

Configuration Management

9 controls
Controls in the Configuration Management domain of CMMC 2.09 controls
CodeTitle
CM.L2-3.4.1System Baselining
CM.L2-3.4.2Security Configuration Enforcement
CM.L2-3.4.3System Change Management
CM.L2-3.4.4Security Impact Analysis
CM.L2-3.4.5Access Restrictions for Change
CM.L2-3.4.6Least Functionality
CM.L2-3.4.7Nonessential Functionality
CM.L2-3.4.8Application Execution Policy
CM.L2-3.4.9User-Installed Software

Identification and Authentication

11 controls
Controls in the Identification and Authentication domain of CMMC 2.011 controls
CodeTitle
IA.L2-3.5.1Identification
IA.L2-3.5.10Cryptographically-Protected Passwords
IA.L2-3.5.11Obscure Feedback
IA.L2-3.5.2Authentication
IA.L2-3.5.3Multifactor Authentication
IA.L2-3.5.4Replay-Resistant Authentication
IA.L2-3.5.5Identifier Reuse
IA.L2-3.5.6Identifier Handling
IA.L2-3.5.7Password Complexity
IA.L2-3.5.8Password Reuse
IA.L2-3.5.9Temporary Passwords

Incident Response

3 controls
Controls in the Incident Response domain of CMMC 2.03 controls
CodeTitle
IR.L2-3.6.1Incident Handling
IR.L2-3.6.2Incident Reporting
IR.L2-3.6.3Incident Response Testing

Maintenance

6 controls
Controls in the Maintenance domain of CMMC 2.06 controls
CodeTitle
MA.L2-3.7.1Perform Maintenance
MA.L2-3.7.2System Maintenance Control
MA.L2-3.7.3Equipment Sanitization
MA.L2-3.7.4Media Inspection
MA.L2-3.7.5Nonlocal Maintenance
MA.L2-3.7.6Maintenance Personnel

Media Protection

9 controls
Controls in the Media Protection domain of CMMC 2.09 controls
CodeTitle
MP.L2-3.8.1Media Protection
MP.L2-3.8.2Media Access
MP.L2-3.8.3Media Disposal
MP.L2-3.8.4Media Markings
MP.L2-3.8.5Media Accountability
MP.L2-3.8.6Portable Storage Encryption
MP.L2-3.8.7Removable Media
MP.L2-3.8.8Shared Media
MP.L2-3.8.9Protect Backups

Personnel Security

2 controls
Controls in the Personnel Security domain of CMMC 2.02 controls
CodeTitle
PS.L2-3.9.1Screen Individuals
PS.L2-3.9.2Personnel Actions

Physical Protection

6 controls
Controls in the Physical Protection domain of CMMC 2.06 controls
CodeTitle
PE.L2-3.10.1Limit Physical Access
PE.L2-3.10.2Monitor Facility
PE.L2-3.10.3Escort Visitors
PE.L2-3.10.4Physical Access Logs
PE.L2-3.10.5Manage Physical Access
PE.L2-3.10.6Alternative Work Sites

Risk Assessment

3 controls
Controls in the Risk Assessment domain of CMMC 2.03 controls
CodeTitle
RA.L2-3.11.1Risk Assessments
RA.L2-3.11.2Vulnerability Scan
RA.L2-3.11.3Vulnerability Remediation

Security Assessment

4 controls
Controls in the Security Assessment domain of CMMC 2.04 controls
CodeTitle
CA.L2-3.12.1Security Control Assessment
CA.L2-3.12.2Plan of Action
CA.L2-3.12.3Security Control Monitoring
CA.L2-3.12.4System Security Plan

System and Communications Protection

16 controls
Controls in the System and Communications Protection domain of CMMC 2.016 controls
CodeTitle
SC.L2-3.13.1Boundary Protection
SC.L2-3.13.10Key Management
SC.L2-3.13.11CUI Encryption
SC.L2-3.13.12Collaborative Device Control
SC.L2-3.13.13Mobile Code
SC.L2-3.13.14Voice over Internet Protocol
SC.L2-3.13.15Communications Authenticity
SC.L2-3.13.16Data at Rest
SC.L2-3.13.2Security Engineering
SC.L2-3.13.3Role Separation
SC.L2-3.13.4Shared Resource Control
SC.L2-3.13.5Public-Access System Separation
SC.L2-3.13.6Network Communication by Exception
SC.L2-3.13.7Split Tunneling
SC.L2-3.13.8Data in Transit
SC.L2-3.13.9Connections Termination

System and Information Integrity

7 controls
Controls in the System and Information Integrity domain of CMMC 2.07 controls
CodeTitle
SI.L2-3.14.1Flaw Remediation
SI.L2-3.14.2Malicious Code Protection
SI.L2-3.14.3Security Alerts & Advisories
SI.L2-3.14.4Update Malicious Code Protection
SI.L2-3.14.5System & File Scanning
SI.L2-3.14.6Monitor Communications for Attacks
SI.L2-3.14.7Identify Unauthorized Use

Your Compliance Coverage

If you comply with CMMC 2.0, you already cover:

+ 2 more: DFARS 252.204-7012 - Safeguarding Covered Defense Information (3%), DISA Security Technical Implementation Guides (STIGs) (3%)

See all 5 mapped frameworks ↓

Maps to 5 other frameworks

110 total controls
NIST SP 800-53 Rev 5
32 source controls mapped|32 target controls covered
29%
CMMC 2.0 Level 1
17 source controls mapped|17 target controls covered
15%
NIST Cybersecurity Framework 2.0
7 source controls mapped|6 target controls covered
6%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
3 source controls mapped|2 target controls covered
3%
DISA Security Technical Implementation Guides (STIGs)
3 source controls mapped|3 target controls covered
3%

Frequently Asked Questions

What is CMMC 2.0?

CMMC 2.0 is a compliance framework from United States with 14 domains and 110 controls. Cybersecurity Maturity Model Certification for defense industrial base It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CMMC 2.0 have?

CMMC 2.0 has 110 controls organised across 14 domains. The largest domains are Access Control (22 controls), System and Communications Protection (16 controls), Identification and Authentication (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CMMC 2.0 map to?

CMMC 2.0 maps to 5 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (29% coverage), CMMC 2.0 Level 1 (15% coverage), NIST Cybersecurity Framework 2.0 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CMMC 2.0 compliance?

Start your CMMC 2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CMMC 2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 110 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required