Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · CA

Security Assessment

That controls are assessed, documented in an SSP, tracked via POA&Ms, and monitored continuously.

4
requirements in this family
What it requires

The 4 requirements, in plain language.

3.12.1 Security Control Assessment

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application

3.12.2 Operational Plan of Action

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems

3.12.3 Security Control Monitoring

Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls

3.12.4 System Security Plan

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems

NIST SP 800-171 Rev 2 — Family CA. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.