Managed IT and Managed Security · Leesburg, VA

CMMC

How Is a CMMC Level 2 Score Calculated?

The score starts at 110, one point for each NIST SP 800-171 Rev 2 requirement, and every requirement not met subtracts its value: 5 points for the requirements whose absence could lead to significant exploitation or loss of CUI, 3 points for those with a confined effect, and 1 point for the rest (32 CFR 170.24). A perfect score is 110.

Capital Cyber. Sources are listed at the end of the article.

Met, Not Met and Not Applicable

Each requirement is scored Met, Not Met or Not Applicable (32 CFR 170.24(b)). Met means all applicable objectives are satisfied by evidence in final form; drafts, working papers and unapproved policies do not count. A requirement that does not apply in your environment is treated the same as Met.

The 5, 3 and 1 Point Requirements

32 CFR 170.24(c) lists them by number. Five point requirements include limiting system access to authorized users, security awareness training, creating audit logs, baseline configurations, identifying and authenticating users, incident handling, sanitizing media before disposal, periodic security assessments and ongoing monitoring of controls, boundary protection, and flaw remediation and malware protection. Three point requirements include audit accountability, maintenance, media protection, personnel screening, risk assessment and developing plans of action. The remaining requirements are worth 1 point each.

Two requirements can earn partial credit (32 CFR 170.24(c)). Multi-factor authentication loses 3 points if it covers only remote and privileged users and 5 if it covers no users. Encryption of CUI loses 3 points if encryption is used but not FIPS-validated and 5 if it is not used at all.

When a Plan of Action Is Allowed

A Conditional Level 2 status with a POA&M needs a score of at least 80 percent of 110, which is 88 (32 CFR 170.21(a)(2)). Only 1 point requirements can go on the POA&M, plus encryption that is in place but not FIPS-validated. Six requirements can never be on it: external connections, control of public information, the System Security Plan, and the three physical access requirements for escorting visitors, keeping access logs and managing physical access devices.

The POA&M must be closed, confirmed by a closeout assessment and posted within 180 days of the conditional status date, or the status expires (32 CFR 170.21(b)).

Frequently Asked Questions

4 QUESTIONS
What is a perfect CMMC Level 2 score?

110, when every NIST SP 800-171 Rev 2 requirement is met (32 CFR 170.24(c)(2)).

What is the minimum score for a Conditional Level 2 status?

The score divided by 110 must be at least 0.8, so 88, and the POA&M may only hold eligible requirements (32 CFR 170.21(a)(2)).

How long do I have to close a CMMC POA&M?

180 days from the Conditional CMMC Status Date. If it is not closed in time, the conditional status expires (32 CFR 170.21(b)).

Can the System Security Plan be on a POA&M?

No. CA.L2-3.12.4, the System Security Plan, is one of the six requirements 32 CFR 170.21(a)(2)(iii) keeps off the POA&M.

Talk it through in 30 minutes.

A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call