CMMC 2.13
CMMC Practices
Each practice, grouped by domain and cross-referenced to the NIST controls that support it.
149 practices
AC
Access Control28AC.L1-b.1.iAuthorized Access Control [FCI Data]1 refL1AC.L1-b.1.iiTransaction & Function Control [FCI Data]1 refL1AC.L1-b.1.iiiExternal Connections [FCI Data]1 refL1AC.L1-b.1.ivControl Public Information [FCI Data]1 refL1AC.L2-3.1.1Authorized Access Control [CUI Data]1 refL2AC.L2-3.1.2Transaction & Function Control [CUI Data]1 refL2AC.L2-3.1.3Control CUI Flow1 refL2AC.L2-3.1.4Separation of Duties1 refL2AC.L2-3.1.5Least Privilege1 refL2AC.L2-3.1.6Non-Privileged Account Use1 refL2AC.L2-3.1.7Privileged Functions1 refL2AC.L2-3.1.8Unsuccessful Logon Attempts1 refL2AC.L2-3.1.9Privacy & Security Notices1 refL2AC.L2-3.1.10Session Lock1 refL2AC.L2-3.1.11Session Termination1 refL2AC.L2-3.1.12Control Remote Access1 refL2AC.L2-3.1.13Remote Access Confidentiality1 refL2AC.L2-3.1.14Remote Access Routing1 refL2AC.L2-3.1.15Privileged Remote Access1 refL2AC.L2-3.1.16Wireless Access Authorization1 refL2AC.L2-3.1.17Wireless Access Protection1 refL2AC.L2-3.1.18Mobile Device Connection1 refL2AC.L2-3.1.19Encrypt CUI on Mobile1 refL2AC.L2-3.1.20External Connections [CUI Data]1 refL2AC.L2-3.1.21Portable Storage Use1 refL2AC.L2-3.1.22Control Public Information [CUI Data]1 refL2AC.L3-3.1.2eOrganizationally Controlled AssetsL3AC.L3-3.1.3eSecured Information TransferL3
AT
Awareness & Training5AU
Audit & Accountability9AU.L2-3.3.1System Auditing1 refL2AU.L2-3.3.2User Accountability1 refL2AU.L2-3.3.3Event Review1 refL2AU.L2-3.3.4Audit Failure Alerting1 refL2AU.L2-3.3.5Audit Correlation1 refL2AU.L2-3.3.6Reduction & Reporting1 refL2AU.L2-3.3.7Authoritative Time Source1 refL2AU.L2-3.3.8Audit Protection1 refL2AU.L2-3.3.9Audit Management1 refL2
CM
Configuration Management12CM.L2-3.4.1System Baselining1 refL2CM.L2-3.4.2Security Configuration Enforcement1 refL2CM.L2-3.4.3System Change Management1 refL2CM.L2-3.4.4Security Impact Analysis1 refL2CM.L2-3.4.5Access Restrictions for Change1 refL2CM.L2-3.4.6Least Functionality1 refL2CM.L2-3.4.7Nonessential Functionality1 refL2CM.L2-3.4.8Application Execution Policy1 refL2CM.L2-3.4.9User-Installed Software1 refL2CM.L3-3.4.1eAuthoritative RepositoryL3CM.L3-3.4.2eAutomated Detection & RemediationL3CM.L3-3.4.3eAutomated InventoryL3
IA
Identification & Authentication15IA.L1-b.1.vIdentification [FCI Data]1 refL1IA.L1-b.1.viAuthentication [FCI Data]1 refL1IA.L2-3.5.1Identification [CUI Data]1 refL2IA.L2-3.5.2Authentication [CUI Data]1 refL2IA.L2-3.5.3Multifactor Authentication1 refL2IA.L2-3.5.4Replay-Resistant Authentication1 refL2IA.L2-3.5.5Identifier Reuse1 refL2IA.L2-3.5.6Identifier Handling1 refL2IA.L2-3.5.7Password Complexity1 refL2IA.L2-3.5.8Password Reuse1 refL2IA.L2-3.5.9Temporary Passwords1 refL2IA.L2-3.5.10Cryptographically-Protected Passwords1 refL2IA.L2-3.5.11Obscure Feedback1 refL2IA.L3-3.5.1eBidirectional AuthenticationL3IA.L3-3.5.3eBlock Untrusted AssetsL3
IR
Incident Response5MA
Maintenance6MP
Media Protection10MP.L1-b.1.viiMedia Disposal [FCI Data]1 refL1MP.L2-3.8.1Media Protection1 refL2MP.L2-3.8.2Media Access1 refL2MP.L2-3.8.3Media Disposal [CUI Data]1 refL2MP.L2-3.8.4Media Markings1 refL2MP.L2-3.8.5Media Accountability1 refL2MP.L2-3.8.6Portable Storage Encryption1 refL2MP.L2-3.8.7Removable Media1 refL2MP.L2-3.8.8Shared Media1 refL2MP.L2-3.8.9Protect Backups1 refL2
PS
Personnel Security3PE
Physical Protection8PE.L1-b.1.viiiLimit Physical Access [FCI Data]1 refL1PE.L1-b.1.ixManage Visitors & Physical Access [FCI Data]3 refsL1PE.L2-3.10.1Limit Physical Access [CUI Data]1 refL2PE.L2-3.10.2Monitor Facility1 refL2PE.L2-3.10.3Escort Visitors [CUI Data]1 refL2PE.L2-3.10.4Physical Access Logs [CUI Data]1 refL2PE.L2-3.10.5Manage Physical Access [CUI Data]1 refL2PE.L2-3.10.6Alternative Work Sites1 refL2
RA
Risk Assessment10RA.L2-3.11.1Risk Assessments1 refL2RA.L2-3.11.2Vulnerability Scan1 refL2RA.L2-3.11.3Vulnerability Remediation1 refL2RA.L3-3.11.1eThreat-Informed Risk AssessmentL3RA.L3-3.11.2eThreat HuntingL3RA.L3-3.11.3eAdvanced Risk IdentificationL3RA.L3-3.11.4eSecurity Solution RationaleL3RA.L3-3.11.5eSecurity Solution EffectivenessL3RA.L3-3.11.6eSupply Chain Risk ResponseL3RA.L3-3.11.7eSupply Chain Risk PlanL3
CA
Security Assessment5SC
System & Communications Protection19SC.L1-b.1.xBoundary Protection [FCI Data]1 refL1SC.L1-b.1.xiPublic-Access System Separation [FCI Data]1 refL1SC.L2-3.13.1Boundary Protection [CUI Data]1 refL2SC.L2-3.13.2Security Engineering1 refL2SC.L2-3.13.3Role Separation1 refL2SC.L2-3.13.4Shared Resource Control1 refL2SC.L2-3.13.5Public-Access System Separation [CUI Data]1 refL2SC.L2-3.13.6Network Communication by Exception1 refL2SC.L2-3.13.7Split Tunneling1 refL2SC.L2-3.13.8Data in Transit1 refL2SC.L2-3.13.9Connections Termination1 refL2SC.L2-3.13.10Key Management1 refL2SC.L2-3.13.11CUI Encryption1 refL2SC.L2-3.13.12Collaborative Device Control1 refL2SC.L2-3.13.13Mobile Code1 refL2SC.L2-3.13.14Voice over Internet Protocol1 refL2SC.L2-3.13.15Communications Authenticity1 refL2SC.L2-3.13.16Data at Rest1 refL2SC.L3-3.13.4eIsolationL3
SI
System & Information Integrity14SI.L1-b.1.xiiFlaw Remediation [FCI Data]1 refL1SI.L1-b.1.xiiiMalicious Code Protection [FCI Data]1 refL1SI.L1-b.1.xivUpdate Malicious Code Protection [FCI Data]1 refL1SI.L1-b.1.xvSystem & File Scanning [FCI Data]1 refL1SI.L2-3.14.1Flaw Remediation [CUI Data]1 refL2SI.L2-3.14.2Malicious Code Protection [CUI Data]1 refL2SI.L2-3.14.3Security Alerts & Advisories1 refL2SI.L2-3.14.4Update Malicious Code Protection [CUI Data]1 refL2SI.L2-3.14.5System & File Scanning [CUI Data]1 refL2SI.L2-3.14.6Monitor Communications for Attacks1 refL2SI.L2-3.14.7Identify Unauthorized Use1 refL2SI.L3-3.14.1eIntegrity VerificationL3SI.L3-3.14.3eSpecialized Asset SecurityL3SI.L3-3.14.6eThreat-Guided Intrusion DetectionL3
Looking for the underlying standards? Browse NIST SP 800-171, 800-172 & 800-53 →