CMMC Level 3 Requirements and the AIC Level 3 Kit
Cybersecurity Maturity Model Certification (CMMC) Level 3 adds 24 requirements selected from National Institute of Standards and Technology (NIST) Special Publication 800-172 to the 110 Level 2 requirements. The Analog Informatics Corporation (AIC) Level 3 kit includes every Level 2 module, plus an isolated Jump with session recording and the 800-172 map in the Assessment Binder. The government assessment team decides the Level 3 outcome.
How to read the kit role
| Kit role | Meaning |
|---|---|
| Performs | On the systems and paths the kit manages, the named feature carries out the requirement. |
| Assists | The feature supplies the tool, workflow, or record. People carry out the requirement. |
| Records | The work is physical, personnel, or policy work. The Assessment Binder stores the organization's record. |
Feature names used in the table
Every Level 2 feature is included. Short names used below:
- Privileged Access Management (PAM): brokered Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) sessions in the browser.
- Jump: the isolated access server. In the Level 3 kit, Jump records each session for replay.
- Security Information and Event Management (SIEM): the organization's log collector.
- Current State Compliance: the console page that lists control findings and runs Rescan.
- Configuration compliance: checks of each enrolled system against its approved baseline configuration.
- Fix-It: the console action that repairs a known setting on an enrolled system.
- MITRE ATT&CK: a public catalog of attacker techniques.
The 24 Level 3 requirements
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| AC.L3-3.1.2e | Organizationally Controlled Assets | Performs | Configuration compliance checks each connecting system and can block one that fails. Each enrolled system has its own Agent identity, so only systems the organization controls reach the kit. | Decide which systems are organization-owned or issued. |
| AC.L3-3.1.3e | Secured Information Transfer | Assists | Data classification enforces clearances and records each release. The document sharing vault and the isolated Jump carry information between security domains. | Define the security domains. |
| AT.L3-3.2.1e | Advanced Threat Awareness | Assists | Training and attestation assigns the Phishing Awareness and Insider Threat Awareness templates and stores signed attestations. | Provide advanced-threat content. |
| AT.L3-3.2.2e | Practical Training Exercises | Assists | Training and attestation assigns the material and records completion. | Run practical exercises. |
| CM.L3-3.4.1e | Authoritative Repository | Assists | The kit keeps an inventory of enrolled systems, with the approved baseline for each. | Approve components and maintain the repository. |
| CM.L3-3.4.2e | Automated Detection & Remediation | Performs | Configuration compliance detects drift automatically, Fix-It repairs known settings, and a failing system can be blocked. Current State Compliance records each finding. | Remove or repair components the kit flags. |
| CM.L3-3.4.3e | Automated Inventory | Assists | The kit inventories enrolled systems. Network scan and known default credential detection find other systems on the network. | Inventory systems outside the scan. |
| IA.L3-3.5.1e | Bidirectional Authentication | Assists | Each enrolled system has its own Agent identity, which is checked before the Agent connects. | Authenticate network devices outside the kit. |
| IA.L3-3.5.3e | Block Untrusted Assets | Performs | Configuration compliance can block a system that fails its checks. Conditional access blocks sign-in from untrusted locations and addresses. | Block unknown components on the network. |
| IR.L3-3.6.1e | Security Operations Center | Assists | Incident Response detections and alerts, Current State Compliance monitoring, and SIEM forwarding give the security operations center its data. | Staff the security operations center. |
| IR.L3-3.6.2e | Cyber Incident Response Team | Assists | Incident records and alerts by email, text message, and ticket reach the response team quickly. | Staff and deploy the response team. |
| PS.L3-3.9.2e | Adverse Information | Assists | When the organization directs it, disabling a person revokes their kit sessions and access at once. | Act on adverse information. |
| RA.L3-3.11.1e | Threat-Informed Risk Assessment | Assists | Threat indicator feeds are applied at sign-in, and the attack report maps blocked attacks to MITRE ATT&CK, giving the risk assessment current threat data. | Choose intelligence sources. |
| RA.L3-3.11.2e | Threat Hunting | Assists | Recorded Jump sessions can be replayed, and audit search and indicator search give hunters the records they need. | Run the hunting program. |
| RA.L3-3.11.3e | Advanced Risk Identification | Assists | Current State Compliance and Incident Response analytics, plus SIEM forwarding, surface risk across the kit. | Apply analytics outside the kit. |
| RA.L3-3.11.4e | Security Solution Rationale | Assists | The Assessment Binder maps NIST SP 800-172 and holds the SSP narrative where the rationale is written. | Document the rationale. |
| RA.L3-3.11.5e | Security Solution Effectiveness | Assists | Current State Compliance Rescan tests each control, and the Assessment Binder keeps the results. | Assess effectiveness. |
| RA.L3-3.11.6e | Supply Chain Risk Response | Records | The Assessment Binder stores the organization's record. | Assess and monitor supply chain risk. |
| RA.L3-3.11.7e | Supply Chain Risk Plan | Records | The Assessment Binder stores the organization's record. | Write and maintain the supply chain risk plan. |
| CA.L3-3.12.1e | Penetration Testing | Records | The Assessment Binder stores the organization's record. | Commission penetration testing. |
| SC.L3-3.13.4e | Isolation | Performs | The isolated Jump separates privileged sessions from the rest of the network and records each SSH, RDP, and VNC session. The secure enclave isolates its network. | Isolate systems outside the enclave. |
| SI.L3-3.14.1e | Integrity Verification | Assists | The kit checks signatures on product updates, and configuration compliance detects changed settings. | Verify other security-critical software. |
| SI.L3-3.14.3e | Specialized Asset Security | Assists | The kit supports operational technology systems, so they can be brought into scope. | Bring other specialized assets into scope. |
| SI.L3-3.14.6e | Threat-Guided Intrusion Detection | Assists | Threat indicator feeds drive sign-in blocking, detections, and the attack report. | Guide hunting outside the kit. |
Requirement identifiers and short names follow the CMMC Model in 32 CFR 170.14. The full set of 35 enhanced requirements is on the NIST SP 800-172 page.
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.