IR Domain

Incident Response CMMC Level 2

Establish capability to respond to and report incidents — 3 requirements covering 11 total SPRS points.

3 Requirements
11 SPRS Points at Risk
100% Complete Coverage

Incident Response Domain Overview

The Incident Response domain requires organizations to establish an operational capability for handling security incidents — including detection, containment, eradication, recovery, and the 72-hour reporting obligation to DoD under DFARS 7012. When a breach occurs, the difference between a manageable incident and a catastrophic one is response speed and preparation. Contractors without a tested IR plan face both security exposure and regulatory liability.

All 3 Incident Response Requirements

Every NIST SP 800-171 Rev 2 requirement in the IR family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
IR.L2-3.6.1Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.5Conditional
IR.L2-3.6.2Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.3Yes
IR.L2-3.6.3Test the organizational incident response capability.3Yes

How 1TEN Covers This Domain

Incident Response Plan Builder

Build a complete incident response plan covering all six phases: preparation, detection, analysis, containment, recovery, and user response. The platform generates assessment-ready documentation satisfying 3.6.1.

Incident Tracking & Reporting

Log and track every security incident from detection through resolution. The platform maintains reporting chains, notification timelines, and authority contacts to satisfy 3.6.2 with complete audit trails.

Tabletop Exercise Management

Schedule, execute, and document incident response tests and tabletop exercises. The platform captures lessons learned and plan updates, providing the evidence 3.6.3 requires during assessment.

72-Hour Response Timeline

Built-in response timelines ensure your team meets DFARS 252.204-7012 reporting requirements. Automated checklists guide responders through each phase of containment and recovery.

Common Tools for IR Compliance

These tools are commonly used by defense contractors to satisfy IR requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will ask to see your incident response plan and verify it addresses the required elements: detection, reporting, containment, eradication, and recovery. They’ll ask who is responsible for IR, how the 72-hour clock is tracked, and whether the plan has been tested. Expect a tabletop exercise scenario.

Why This Domain Matters
The first 72 hours after a CUI breach determine whether your organization survives the investigation. The time to build your IR capability is not during an incident.

Related Domains

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo