Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · SI

System & Information Integrity

That flaws are fixed, malicious code is stopped, and systems are monitored for attacks and unauthorized use.

7
requirements in this family
What it requires

The 7 requirements, in plain language.

3.14.1 Flaw Remediation [CUI Data]

Identify, report, and correct system flaws in a timely manner

3.14.2 Malicious Code Protection [CUI Data]

Provide protection from malicious code at designated locations within organizational systems

3.14.3 Security Alerts & Advisories

Monitor system security alerts and advisories and take action in response

3.14.4 Update Malicious Code Protection [CUI Data]

Update malicious code protection mechanisms when new releases are available

3.14.5 System & File Scanning [CUI Data]

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed

3.14.6 Monitor Communications for Attacks

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks

3.14.7 Identify Unauthorized Use

Identify unauthorized use of organizational systems

NIST SP 800-171 Rev 2 — Family SI. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.