CMMC Level 3 Requirements and the AIC Level 3 Kit

Cybersecurity Maturity Model Certification (CMMC) Level 3 adds 24 requirements selected from National Institute of Standards and Technology (NIST) Special Publication 800-172 to the 110 Level 2 requirements. The Analog Informatics Corporation (AIC) Level 3 kit includes every Level 2 module, plus an isolated Jump with session recording and the 800-172 map in the Assessment Binder. The government assessment team decides the Level 3 outcome.

What Availability Means

How to read the kit role

Kit roleMeaning
PerformsOn the systems and paths the kit manages, the named feature carries out the requirement.
AssistsThe feature supplies the tool, workflow, or record. People carry out the requirement.
RecordsThe work is physical, personnel, or policy work. The Assessment Binder stores the organization's record.

Feature names used in the table

Every Level 2 feature is included. Short names used below:

  • Privileged Access Management (PAM): brokered Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) sessions in the browser.
  • Jump: the isolated access server. In the Level 3 kit, Jump records each session for replay.
  • Security Information and Event Management (SIEM): the organization's log collector.
  • Current State Compliance: the console page that lists control findings and runs Rescan.
  • Configuration compliance: checks of each enrolled system against its approved baseline configuration.
  • Fix-It: the console action that repairs a known setting on an enrolled system.
  • MITRE ATT&CK: a public catalog of attacker techniques.

The 24 Level 3 requirements

RequirementCMMC short nameKit roleHow the kit meets or supports itWhat the organization does by hand
AC.L3-3.1.2eOrganizationally Controlled AssetsPerformsConfiguration compliance checks each connecting system and can block one that fails. Each enrolled system has its own Agent identity, so only systems the organization controls reach the kit.Decide which systems are organization-owned or issued.
AC.L3-3.1.3eSecured Information TransferAssistsData classification enforces clearances and records each release. The document sharing vault and the isolated Jump carry information between security domains.Define the security domains.
AT.L3-3.2.1eAdvanced Threat AwarenessAssistsTraining and attestation assigns the Phishing Awareness and Insider Threat Awareness templates and stores signed attestations.Provide advanced-threat content.
AT.L3-3.2.2ePractical Training ExercisesAssistsTraining and attestation assigns the material and records completion.Run practical exercises.
CM.L3-3.4.1eAuthoritative RepositoryAssistsThe kit keeps an inventory of enrolled systems, with the approved baseline for each.Approve components and maintain the repository.
CM.L3-3.4.2eAutomated Detection & RemediationPerformsConfiguration compliance detects drift automatically, Fix-It repairs known settings, and a failing system can be blocked. Current State Compliance records each finding.Remove or repair components the kit flags.
CM.L3-3.4.3eAutomated InventoryAssistsThe kit inventories enrolled systems. Network scan and known default credential detection find other systems on the network.Inventory systems outside the scan.
IA.L3-3.5.1eBidirectional AuthenticationAssistsEach enrolled system has its own Agent identity, which is checked before the Agent connects.Authenticate network devices outside the kit.
IA.L3-3.5.3eBlock Untrusted AssetsPerformsConfiguration compliance can block a system that fails its checks. Conditional access blocks sign-in from untrusted locations and addresses.Block unknown components on the network.
IR.L3-3.6.1eSecurity Operations CenterAssistsIncident Response detections and alerts, Current State Compliance monitoring, and SIEM forwarding give the security operations center its data.Staff the security operations center.
IR.L3-3.6.2eCyber Incident Response TeamAssistsIncident records and alerts by email, text message, and ticket reach the response team quickly.Staff and deploy the response team.
PS.L3-3.9.2eAdverse InformationAssistsWhen the organization directs it, disabling a person revokes their kit sessions and access at once.Act on adverse information.
RA.L3-3.11.1eThreat-Informed Risk AssessmentAssistsThreat indicator feeds are applied at sign-in, and the attack report maps blocked attacks to MITRE ATT&CK, giving the risk assessment current threat data.Choose intelligence sources.
RA.L3-3.11.2eThreat HuntingAssistsRecorded Jump sessions can be replayed, and audit search and indicator search give hunters the records they need.Run the hunting program.
RA.L3-3.11.3eAdvanced Risk IdentificationAssistsCurrent State Compliance and Incident Response analytics, plus SIEM forwarding, surface risk across the kit.Apply analytics outside the kit.
RA.L3-3.11.4eSecurity Solution RationaleAssistsThe Assessment Binder maps NIST SP 800-172 and holds the SSP narrative where the rationale is written.Document the rationale.
RA.L3-3.11.5eSecurity Solution EffectivenessAssistsCurrent State Compliance Rescan tests each control, and the Assessment Binder keeps the results.Assess effectiveness.
RA.L3-3.11.6eSupply Chain Risk ResponseRecordsThe Assessment Binder stores the organization's record.Assess and monitor supply chain risk.
RA.L3-3.11.7eSupply Chain Risk PlanRecordsThe Assessment Binder stores the organization's record.Write and maintain the supply chain risk plan.
CA.L3-3.12.1ePenetration TestingRecordsThe Assessment Binder stores the organization's record.Commission penetration testing.
SC.L3-3.13.4eIsolationPerformsThe isolated Jump separates privileged sessions from the rest of the network and records each SSH, RDP, and VNC session. The secure enclave isolates its network.Isolate systems outside the enclave.
SI.L3-3.14.1eIntegrity VerificationAssistsThe kit checks signatures on product updates, and configuration compliance detects changed settings.Verify other security-critical software.
SI.L3-3.14.3eSpecialized Asset SecurityAssistsThe kit supports operational technology systems, so they can be brought into scope.Bring other specialized assets into scope.
SI.L3-3.14.6eThreat-Guided Intrusion DetectionAssistsThreat indicator feeds drive sign-in blocking, detections, and the attack report.Guide hunting outside the kit.

Requirement identifiers and short names follow the CMMC Model in 32 CFR 170.14. The full set of 35 enhanced requirements is on the NIST SP 800-172 page.

Screenshots

Playback of a recorded SSH session requires a case or review reason, and every attempt is audited.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.