CMMC Level 2 Requirements and the AIC Level 2 Kit

Cybersecurity Maturity Model Certification (CMMC) Level 2 protects Controlled Unclassified Information (CUI) with the 110 security requirements in National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 2. The Analog Informatics Corporation (AIC) Level 2 kit includes every Level 1 module, plus Privileged Identity Management, Privileged Access Management, Privileged User Management, Identity Governance and Administration, Audit, training and attestation, Secure Application Launch, Jump, command restriction, Incident Response, and validated cryptography.

What Availability Means

How to read the kit role

Kit roleMeaning
PerformsOn the systems and paths the kit manages, the named feature carries out the requirement.
AssistsThe feature supplies the tool, workflow, or record. People carry out the requirement.
RecordsThe work is physical, personnel, or policy work. The Assessment Binder stores the organization's record.

Feature names used in the tables

The tables name the kit feature that does the work. Short names used below:

  • Privileged Identity Management (PIM): vaulted privileged credentials with checkout, rotation, and propagation.
  • Privileged Access Management (PAM): brokered Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) sessions in the browser, with approvals and command restriction.
  • Privileged User Management (PUM): just-in-time elevation on Windows, Mac, and Linux endpoints, with approvals and signed grants.
  • Identity Governance and Administration (IGA): account lifecycle and access review for kit accounts.
  • Role-based access control (RBAC): permission checks on every console page and interface.
  • Multi-factor authentication (MFA): a password plus a second step.
  • Security Information and Event Management (SIEM): the organization's log collector.
  • Plan of Action and Milestones (POA&M) and system security plan (SSP): assessment documents the Assessment Binder supports.
  • Security Technical Implementation Guide (STIG): a published configuration baseline.
  • Federal Contract Information (FCI) and Controlled Unclassified Information (CUI): the information each level protects.
  • Current State Compliance: the console page that lists control findings and runs Rescan.
  • Configuration compliance: checks of each enrolled system against its approved baseline configuration.
  • Transport Layer Security (TLS): encryption for data moving across the network.
  • Advanced Encryption Standard (AES-256, AES-256-GCM): encryption for stored data.
  • Password-Based Key Derivation Function 2 (PBKDF2): the one-way hash used to store local passwords.
  • Lightweight Directory Access Protocol (LDAP) and Security Assertion Markup Language (SAML 2.0): directory and single sign-on standards the kit connects to.
  • Amazon Web Services LibCrypto (AWS-LC): the cryptographic module the server uses. It holds a Federal Information Processing Standards (FIPS) 140-3 certificate.
  • Hardware Security Module (HSM): a device that holds encryption keys.
  • Common Event Format (CEF) and Log Event Extended Format (LEEF): log formats SIEM products read.
  • Coordinated Universal Time (UTC): the time standard on every audit record.
  • Endpoint Detection and Response (EDR): antimalware software that also detects attacks.
  • Virtual Private Network (VPN): an encrypted network connection into the organization.
  • Defense Federal Acquisition Regulation Supplement (DFARS): the defense contract rules that set incident reporting.
  • Fix-It: the console action that repairs a known setting on an enrolled system.
  • Jump: the isolated access server that privileged sessions pass through.

All 110 Level 2 requirements

Jump to a family: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity.

Access Control (AC)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
AC.L2-3.1.1Authorized Access ControlPerformsOnly people with a kit account and an assigned role can sign in, with MFA. RBAC checks every console page and interface. PIM releases a vaulted privileged password only to an approved user, and PAM connects that user only to an approved target. Vault documents open only for named users.Grant and remove access on systems the kit does not manage.
AC.L2-3.1.2Transaction & Function ControlPerformsEach role allows only its assigned console functions. PAM approval policies set which systems and protocols each user reaches. Command restriction blocks a disallowed command as it is typed. Secure Application Launch starts only approved applications.Define the functions each role needs.
AC.L2-3.1.3Control CUI FlowPerformsData classification marks FCI and CUI, checks each person's clearance before release, and records every release. The document sharing vault and governed mail keep CUI on kit paths.Control the flow of CUI on systems outside the kit.
AC.L2-3.1.4Separation of DutiesAssistsAdministrator, approver, auditor, and user are separate roles, and privileged access goes through an approval workflow. IGA access review shows who holds each role.Decide which duties must be separated, and assign people to roles.
AC.L2-3.1.5Least PrivilegePerformsPUM grants administrator rights for one task and removes them afterward, so users keep no standing administrator rights. PIM checks out privileged passwords for a limited time and rotates them. PAM approvals expire.Apply least privilege on systems the kit does not manage.
AC.L2-3.1.6Non-Privileged Account UsePerformsPrivileged accounts live in the PIM vault. People sign in with their own everyday identity and check out a privileged account, or request elevation, only when a task needs it.Issue separate everyday accounts on systems outside the kit.
AC.L2-3.1.7Privileged FunctionsPerformsPUM stops a non-privileged user from running a privileged function until a request is approved and a signed grant is issued. Every privileged action is written to the audit log with the person's name.Review privileged activity on schedule.
AC.L2-3.1.8Unsuccessful Logon AttemptsPerformsThe console locks an account after repeated failed sign-ins. Conditional access and threat feeds block sign-in attempts from denied locations and known bad addresses.Set lockout on systems outside the kit.
AC.L2-3.1.9Privacy & Security NoticesRecordsA logon banner for every managed host is planned. Today the Assessment Binder stores the banner text and where it is set.Set logon banners on each system.
AC.L2-3.1.10Session LockAssistsConsole sessions end after an idle timeout.Set a pattern-hiding screen lock on each workstation.
AC.L2-3.1.11Session TerminationPerformsSessions end at an idle timeout and at an absolute time limit. Signing out revokes the session on the server, so its token cannot be reused.Set session termination on other systems.
AC.L2-3.1.12Control Remote AccessPerformsPAM brokers SSH, RDP, and VNC sessions in the browser, so privileged remote access takes one approved, audited path. Conditional access checks country, network address, and MFA before the session starts.Control remote access through the organization's VPN and other paths.
AC.L2-3.1.13Remote Access ConfidentialityPerformsConsole, Agent, and session traffic is encrypted with TLS through AWS-LC, which holds a FIPS 140-3 certificate.Encrypt remote access paths outside the kit.
AC.L2-3.1.14Remote Access RoutingAssistsWhen Jump is deployed, privileged remote sessions route through it as the managed access point.Route all other remote access through managed access points.
AC.L2-3.1.15Privileged Remote AccessPerformsEach PAM session needs approval before it starts. PUM elevation needs approval and a signed grant. Command restriction blocks disallowed SSH commands as they are typed.Authorize privileged remote access on other paths.
AC.L2-3.1.16Wireless Access AuthorizationRecordsThe Assessment Binder stores the organization's record.Authorize wireless access before connections are allowed.
AC.L2-3.1.17Wireless Access ProtectionRecordsThe Assessment Binder stores the organization's record.Protect wireless access with authentication and encryption.
AC.L2-3.1.18Mobile Device ConnectionRecordsThe Assessment Binder stores the organization's record.Control the connection of mobile devices.
AC.L2-3.1.19Encrypt CUI on MobileAssistsCUI stored in the kit is encrypted with AES-256.Encrypt the storage of phones and laptops.
AC.L2-3.1.20External ConnectionsPerformsConfiguration compliance checks each connecting system and can block one that fails. Data classification limits release of CUI on kit paths.Approve and document external connections.
AC.L2-3.1.21Portable Storage UseRecordsThe Assessment Binder stores the organization's record.Limit portable storage on external systems.
AC.L2-3.1.22Control Public InformationRecordsThe Assessment Binder stores the organization's record.Review and approve what is posted on public systems.

Awareness and Training (AT)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
AT.L2-3.2.1Role-Based Risk AwarenessAssistsTraining and attestation assigns security awareness material from 53 ready-made templates to named people, sends reminders, and stores each signed attestation. Completion reports show who is done.Choose content that fits the environment.
AT.L2-3.2.2Role-Based TrainingAssistsThe kit assigns templates to the named people in each role, with due dates, reminders, and completion reports.Design the role-based training.
AT.L2-3.2.3Insider Threat AwarenessAssistsThe Insider Threat Awareness template is assigned to named people, and each signed attestation is stored.Run the insider threat program.

Audit and Accountability (AU)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
AU.L2-3.3.1System AuditingPerformsThe kit writes audit records for sign-in, access, elevation, sessions, configuration changes, and secret actions. Records go to the Windows Event Log and, as syslog in RFC 5424, CEF, or LEEF format, to your SIEM.Set retention, and log systems outside the kit.
AU.L2-3.3.2User AccountabilityPerformsEach record names the person, the action, the target, the outcome, and a request ID, so every action traces to one individual.Use named accounts on other systems.
AU.L2-3.3.3Event ReviewAssistsAudit event selection and SIEM forwarding settings let you change which events are logged after each review.Review which events are logged.
AU.L2-3.3.4Audit Failure AlertingPerformsThe kit alerts when the audit or forwarding pipeline fails.Respond to the alert.
AU.L2-3.3.5Audit CorrelationAssistsA request ID links related records, and forwarding sends them to your SIEM for correlation. The attack report maps blocked attacks to MITRE ATT&CK.Correlate all sources in the SIEM.
AU.L2-3.3.6Reduction & ReportingAssistsAudit search, filters, and export reduce records to what a review needs. The Assessment Binder produces reports.Report on sources outside the kit.
AU.L2-3.3.7Authoritative Time SourceAssistsThe server stamps every record in UTC and warns when a clock drifts.Run the authoritative time source.
AU.L2-3.3.8Audit ProtectionPerformsAudit records are insert-only, so they cannot be edited in place. Audit exports are hash-chained, so a changed record is detectable.Protect copies in the SIEM and archive.
AU.L2-3.3.9Audit ManagementPerformsOnly authorized roles can view or export audit records.Limit audit management on other systems.

Configuration Management (CM)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
CM.L2-3.4.1System BaseliningAssistsConfiguration compliance holds a STIG-oriented baseline for each enrolled system and keeps an inventory of enrolled systems.Set baselines and keep inventory for systems outside the kit.
CM.L2-3.4.2Security Configuration EnforcementPerformsConfiguration compliance checks each setting against the baseline. Fix-It repairs known settings. Findings the kit cannot repair are flagged for IT.Fix the flagged findings.
CM.L2-3.4.3System Change ManagementAssistsKit setting changes are audited with the person's name. Current State Compliance records drift between scans, so an unapproved change shows up.Run change approval.
CM.L2-3.4.4Security Impact AnalysisAssistsCurrent State Compliance Rescan shows the effect of a change on each control.Analyze security impact before each change.
CM.L2-3.4.5Access Restrictions for ChangePerformsOnly authorized roles can change kit settings, and each change is audited.Restrict changes on other systems.
CM.L2-3.4.6Least FunctionalityAssistsConfiguration compliance flags settings outside the baseline. Secure Application Launch starts only approved applications.Decide which functions are essential.
CM.L2-3.4.7Nonessential FunctionalityAssistsConfiguration compliance flags services that are not in the baseline.Remove or disable nonessential programs, ports, and services.
CM.L2-3.4.8Application Execution PolicyRecordsThe Assessment Binder stores the organization's record.Set the application allow or deny policy.
CM.L2-3.4.9User-Installed SoftwareRecordsThe Assessment Binder stores the organization's record.Control and monitor user-installed software.

Identification and Authentication (IA)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
IA.L2-3.5.1IdentificationPerformsPeople come from your directory as named users. Each enrolled system has its own Agent identity. Vaulted accounts are inventoried.Identify users and devices on other systems.
IA.L2-3.5.2AuthenticationPerformsSign-in goes through Active Directory, LDAP, Microsoft Entra ID, Okta, Ping Identity, OpenID Connect, or SAML 2.0. Local passwords are stored as PBKDF2 hashes.Authenticate users on other systems.
IA.L2-3.5.3Multifactor AuthenticationPerformsConsole sign-in requires MFA. PAM sessions and PUM requests start from that sign-in, so privileged access always passes MFA.Require MFA for network access to other systems.
IA.L2-3.5.4Replay-Resistant AuthenticationPerformsOne-time codes and per-session tokens cannot be replayed, and every kit path uses TLS.Use replay-resistant sign-in on other systems.
IA.L2-3.5.5Identifier ReuseAssistsEach person keeps one durable identity record in the kit, so an identifier is not handed to someone else.Prevent identifier reuse in the directory.
IA.L2-3.5.6Identifier HandlingAssistsIGA lifecycle and access review show inactive kit accounts so they can be disabled.Disable inactive identities in the identity provider.
IA.L2-3.5.7Password ComplexityPerformsPIM generates rotated passwords that meet your complexity policy. Local console passwords must meet a complexity rule.Set complexity on other systems.
IA.L2-3.5.8Password ReusePerformsPassword history blocks reuse of rotated passwords and local console passwords.Set password history on other systems.
IA.L2-3.5.9Temporary PasswordsAssistsPIM rotates managed account passwords on a schedule, so a shared temporary password does not last.Force temporary password changes on other systems.
IA.L2-3.5.10Cryptographically-Protected PasswordsPerformsPasswords are stored as PBKDF2 hashes, vaulted secrets are encrypted with AES-256, and passwords travel only over TLS.Protect passwords on other systems.
IA.L2-3.5.11Obscure FeedbackPerformsPassword fields are masked, and a failed sign-in returns one generic message that does not say which part was wrong.Obscure feedback on other systems.

Incident Response (IR)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
IR.L2-3.6.1Incident HandlingAssistsIncident Response records each incident, runs detections, and alerts the right people by email, text message, and ticket.Staff the response team and run each incident.
IR.L2-3.6.2Incident ReportingAssistsIncident records keep status and history, and they forward to ticket systems and the SIEM.Report incidents to the Department of Defense as DFARS 252.204-7012 requires.
IR.L2-3.6.3Incident Response TestingAssistsIncident Response records can hold the results of tests and tabletop exercises.Run tests and tabletop exercises.

Maintenance (MA)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
MA.L2-3.7.1Perform MaintenanceAssistsMaintenance on managed systems can run through PAM sessions, which leave audit records.Plan and perform maintenance.
MA.L2-3.7.2System Maintenance ControlAssistsMaintenance runs through PAM and Jump with approvals. Secure Application Launch starts only approved tools.Control the tools brought on site.
MA.L2-3.7.3Equipment SanitizationRecordsThe Assessment Binder stores the organization's record.Sanitize equipment sent off site for maintenance.
MA.L2-3.7.4Media InspectionRecordsThe Assessment Binder stores the organization's record.Check media with diagnostic programs before use.
MA.L2-3.7.5Nonlocal MaintenancePerformsA PAM maintenance session starts only after MFA at console sign-in, and it ends at the session timeout.Require MFA for nonlocal maintenance on other systems.
MA.L2-3.7.6Maintenance PersonnelAssistsEach vendor session needs approval, command restriction limits what the vendor can run, and the session leaves an audit record.Escort maintenance staff on site.

Media Protection (MP)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
MP.L2-3.8.1Media ProtectionAssistsThe document sharing vault protects digital CUI with named-user access, encryption, and classification markings.Protect paper and removable media.
MP.L2-3.8.2Media AccessPerformsThe vault checks named-user permissions and clearance before CUI opens.Limit access to physical media.
MP.L2-3.8.3Media DisposalRecordsThe Assessment Binder stores the organization's record.Sanitize or destroy media.
MP.L2-3.8.4Media MarkingsPerformsData classification applies CUI markings to documents in the vault and messages in governed mail.Mark physical media.
MP.L2-3.8.5Media AccountabilityRecordsThe Assessment Binder stores the organization's record.Control media during transport.
MP.L2-3.8.6Portable Storage EncryptionPerformsData the kit stores is encrypted with AES-256, and data it moves is protected by TLS, through AWS-LC cryptography.Encrypt media transported outside the kit.
MP.L2-3.8.7Removable MediaRecordsThe Assessment Binder stores the organization's record.Control removable media.
MP.L2-3.8.8Shared MediaRecordsThe Assessment Binder stores the organization's record.Prohibit portable storage with no identifiable owner.
MP.L2-3.8.9Protect BackupsAssistsData the kit stores is encrypted with keys the organization holds, so backup copies of kit data stay encrypted.Protect backup copies.

Personnel Security (PS)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
PS.L2-3.9.1Screen IndividualsRecordsThe workforce roster records who is in scope, and the Assessment Binder stores screening records.Screen people before they get access to CUI.
PS.L2-3.9.2Personnel ActionsAssistsDisabling a person revokes their kit sessions and access at once. IGA access review confirms the access was removed.Run transfer and termination steps.

Physical Protection (PE)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
PE.L2-3.10.1Limit Physical AccessRecordsThe Assessment Binder stores the organization's record.Limit physical access.
PE.L2-3.10.2Monitor FacilityRecordsThe Assessment Binder stores the organization's record.Protect and monitor the facility.
PE.L2-3.10.3Escort VisitorsRecordsThe Assessment Binder stores the organization's record.Escort visitors and monitor their activity.
PE.L2-3.10.4Physical Access LogsRecordsThe Assessment Binder stores the organization's record.Keep physical access logs.
PE.L2-3.10.5Manage Physical AccessRecordsThe Assessment Binder stores the organization's record.Manage physical access devices.
PE.L2-3.10.6Alternative Work SitesRecordsThe Assessment Binder stores the organization's record.Enforce safeguards at alternate work sites.

Risk Assessment (RA)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
RA.L2-3.11.1Risk AssessmentsAssistsCurrent State Compliance findings and the risk register in the Assessment Binder feed the risk assessment.Perform the risk assessment.
RA.L2-3.11.2Vulnerability ScanAssistsA vulnerability analysis add-on is planned. Network scan and known default credential detection are available now.Run a vulnerability scanner.
RA.L2-3.11.3Vulnerability RemediationAssistsCurrent State Compliance lists findings. Fix-It repairs known settings, other findings are flagged for IT, and open items become POA&M entries.Remediate the findings.

Security Assessment (CA)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
CA.L2-3.12.1Security Control AssessmentAssistsCurrent State Compliance rescans each control, and the Assessment Binder holds the results.Assess controls periodically.
CA.L2-3.12.2Operational Plan of ActionAssistsThe Assessment Binder holds the POA&M and the risk register.Own and maintain the plan.
CA.L2-3.12.3Security Control MonitoringPerformsCurrent State Compliance rescans controls and records drift.Monitor controls outside the kit.
CA.L2-3.12.4System Security PlanAssistsThe Assessment Binder supports the SSP with a narrative wizard.Write and maintain the SSP.

System and Communications Protection (SC)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
SC.L2-3.13.1Boundary ProtectionPerformsThe secure enclave has an isolated network and a secure gateway. Governed mail and data classification release controls govern what leaves the boundary.Operate the boundary firewalls.
SC.L2-3.13.2Security EngineeringAssistsThe enclave comes preconfigured, with separate administration and Agent paths.Engineer the rest of the environment.
SC.L2-3.13.3Role SeparationPerformsRole checks separate the administrator console from user and Agent functions.Separate user and administrator functions on other systems.
SC.L2-3.13.4Shared Resource ControlPerformsVault documents open only for named users. PAM sessions use vaulted credentials without showing them to the user.Prevent unauthorized transfer through shared resources elsewhere.
SC.L2-3.13.5Public-Access System SeparationRecordsThe Assessment Binder stores the organization's record.Design the public-facing subnetwork.
SC.L2-3.13.6Network Communication by ExceptionAssistsThe enclave network sits behind a secure gateway. Conditional access blocks sign-in from denied countries, networks, and threat feeds.Set deny-by-default rules on the network.
SC.L2-3.13.7Split TunnelingRecordsThe Assessment Binder stores the organization's record.Prevent split tunneling.
SC.L2-3.13.8Data in TransitPerformsKit traffic, including governed mail, is encrypted with TLS through AWS-LC.Encrypt CUI in transit outside the kit.
SC.L2-3.13.9Connections TerminationPerformsSessions end at idle and absolute timeouts.Terminate network connections on other systems.
SC.L2-3.13.10Key ManagementPerformsKeys live in software, an HSM, or your cloud key management service. Each group gets its own key set. Keys rotate, and data is re-encrypted under the new key.Manage keys outside the kit.
SC.L2-3.13.11CUI EncryptionPerformsServer paths use AWS-LC, which holds a FIPS 140-3 certificate. The Agent uses the operating system's validated cryptography.Use validated cryptography on other systems.
SC.L2-3.13.12Collaborative Device ControlRecordsThe Assessment Binder stores the organization's record.Control collaborative computing devices.
SC.L2-3.13.13Mobile CodeRecordsThe Assessment Binder stores the organization's record.Control mobile code.
SC.L2-3.13.14Voice over Internet ProtocolRecordsThe Assessment Binder stores the organization's record.Control Voice over Internet Protocol (VoIP).
SC.L2-3.13.15Communications AuthenticityPerformsTLS authenticates each session, and session tokens are bound to the signed-in user.Protect session authenticity on other systems.
SC.L2-3.13.16Data at RestPerformsStored secrets and vault documents are encrypted with AES-256-GCM.Protect CUI at rest outside the kit.

System and Information Integrity (SI)

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
SI.L2-3.14.1Flaw RemediationAssistsConfiguration compliance reports flaws on enrolled systems. Current State Compliance Rescan confirms each repair, and product updates are signed.Patch hosts on schedule.
SI.L2-3.14.2Malicious Code ProtectionAssistsConfiguration compliance reports whether antimalware is running, and flags the system for IT when it is not.Operate antimalware or EDR software.
SI.L2-3.14.3Security Alerts & AdvisoriesAssistsThreat indicator feeds and Current State Compliance findings bring alerts into the console.Subscribe to security advisories and act on them.
SI.L2-3.14.4Update Malicious Code ProtectionRecordsThe Assessment Binder stores the organization's record.Update antimalware signatures.
SI.L2-3.14.5System & File ScanningRecordsThe Assessment Binder stores the organization's record.Schedule periodic and real-time scans.
SI.L2-3.14.6Monitor Communications for AttacksAssistsThreat feeds block sign-in from known bad addresses, Incident Response runs detections, the attack report maps blocked attacks to MITRE ATT&CK, and records go to your SIEM.Monitor traffic outside the kit.
SI.L2-3.14.7Identify Unauthorized UseAssistsDetections flag unusual sign-in and privileged activity, and session and audit records show what each person did.Define authorized use.

Requirement identifiers and short names follow the CMMC Model in 32 CFR 170.14 and the CMMC Model Overview.

Screenshots

Every brokered SSH, RDP, and VNC session is recorded, encrypted, and listed for review.
53 training templates are built in and mapped to the clauses they address.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.