Establish capability to respond to and report incidents — 3 requirements covering 11 total SPRS points.
The Incident Response domain requires organizations to establish an operational capability for handling security incidents — including detection, containment, eradication, recovery, and the 72-hour reporting obligation to DoD under DFARS 7012. When a breach occurs, the difference between a manageable incident and a catastrophic one is response speed and preparation. Contractors without a tested IR plan face both security exposure and regulatory liability.
Every NIST SP 800-171 Rev 2 requirement in the IR family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| IR.L2-3.6.1 | Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. | 5 | Conditional |
| IR.L2-3.6.2 | Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. | 3 | Yes |
| IR.L2-3.6.3 | Test the organizational incident response capability. | 3 | Yes |
Build a complete incident response plan covering all six phases: preparation, detection, analysis, containment, recovery, and user response. The platform generates assessment-ready documentation satisfying 3.6.1.
Log and track every security incident from detection through resolution. The platform maintains reporting chains, notification timelines, and authority contacts to satisfy 3.6.2 with complete audit trails.
Schedule, execute, and document incident response tests and tabletop exercises. The platform captures lessons learned and plan updates, providing the evidence 3.6.3 requires during assessment.
Built-in response timelines ensure your team meets DFARS 252.204-7012 reporting requirements. Automated checklists guide responders through each phase of containment and recovery.
These tools are commonly used by defense contractors to satisfy IR requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will ask to see your incident response plan and verify it addresses the required elements: detection, reporting, containment, eradication, and recovery. They’ll ask who is responsible for IR, how the 72-hour clock is tracked, and whether the plan has been tested. Expect a tabletop exercise scenario.
The first 72 hours after a CUI breach determine whether your organization survives the investigation. The time to build your IR capability is not during an incident.
1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.
Request a Demo