CMMC Level 2

Every domain.
Every requirement.

14 NIST SP 800-171 security domains. 110 practices. 320 assessment objectives. Mapped, scored, and tracked inside one platform your C3PAO can assess on site.

14
CMMC Level 2 security domains
110
NIST SP 800-171 practices covered
320
Assessment objectives mapped
100%
Complete Level 2 coverage
AC

Access Control

22 Requirements

Limit system access to authorized users, processes, and devices.

Explore domain
AT

Awareness & Training

3 Requirements

Ensure personnel are aware of security risks and trained in their responsibilities.

Explore domain
AU

Audit & Accountability

9 Requirements

Create, protect, and retain system audit records for monitoring and investigation.

Explore domain
CM

Configuration Management

9 Requirements

Establish and enforce security configuration settings across organizational systems.

Explore domain
IA

Identification & Authentication

11 Requirements

Identify and authenticate users, processes, and devices before granting access.

Explore domain
IR

Incident Response

3 Requirements

Establish operational incident handling capabilities for organizational systems.

Explore domain
MA

Maintenance

6 Requirements

Perform timely maintenance and control maintenance tools and personnel.

Explore domain
MP

Media Protection

9 Requirements

Protect, sanitize, and control system media containing CUI.

Explore domain
PS

Personnel Security

2 Requirements

Screen individuals prior to access and ensure CUI protection during personnel actions.

Explore domain
PE

Physical Protection

6 Requirements

Limit physical access to systems, equipment, and operating environments.

Explore domain
RA

Risk Assessment

3 Requirements

Assess organizational risk and scan for system vulnerabilities.

Explore domain
CA

Security Assessment

4 Requirements

Assess, monitor, and correct deficiencies in organizational security controls.

Explore domain
SC

System & Communications Protection

16 Requirements

Monitor, control, and protect communications at system boundaries.

Explore domain
SI

System & Information Integrity

7 Requirements

Identify, report, and correct system flaws and malicious activity.

Explore domain
14 Security Domains
110 NIST SP 800-171 Requirements
320 Assessment Objectives
100% Level 2 Coverage

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo