MA Domain

Maintenance CMMC Level 2

Perform and control maintenance of organizational systems — 6 requirements covering 14 total SPRS points.

6 Requirements
14 SPRS Points at Risk
100% Complete Coverage

Maintenance Domain Overview

The Maintenance domain requires organizations to control who performs maintenance on CUI systems, how maintenance is performed, and how tools and media used for maintenance are managed — including remote maintenance sessions. Maintenance activities represent a privileged, often poorly controlled access vector. Third-party technicians, remote diagnostic sessions, and unsanitized maintenance tools all create pathways for CUI exposure or system compromise.

All 6 Maintenance Requirements

Every NIST SP 800-171 Rev 2 requirement in the MA family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
MA.L2-3.7.1Perform maintenance on organizational systems.3Yes
MA.L2-3.7.2Provide controls on the tools, techniques, mechanisms, and personnel for the performance of organizational system maintenance.5Conditional
MA.L2-3.7.3Ensure equipment removed for off-site maintenance is sanitized of any CUI.1Yes
MA.L2-3.7.4Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.3Yes
MA.L2-3.7.5Require MFA to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.5Conditional
MA.L2-3.7.6Supervise the maintenance activities of maintenance personnel without required access authorization.1Yes

How 1TEN Covers This Domain

Maintenance Scheduling & Logging

Schedule, track, and document all system maintenance activities with complete audit trails. The platform captures who performed maintenance, what was done, and when, satisfying 3.7.1 with assessment-ready evidence.

Tool & Personnel Controls

Maintain approved lists of maintenance tools, techniques, and authorized personnel. The platform tracks tool inspections, personnel clearances, and supervision requirements for 3.7.2 and 3.7.6 compliance.

Off-Site Equipment Sanitization

Document sanitization procedures for equipment removed for off-site maintenance and media scanning protocols. The platform provides checklists and evidence capture for 3.7.3 and 3.7.4 requirements.

Remote Maintenance Security

Track nonlocal maintenance sessions with MFA enforcement and session termination controls. The platform documents your remote maintenance architecture and access controls to satisfy 3.7.5.

Common Tools for MA Compliance

These tools are commonly used by defense contractors to satisfy MA requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will look for maintenance logs, check whether remote maintenance sessions are monitored and controlled, and verify that tools used for maintenance are inspected for malicious code. They’ll ask about procedures for authorizing maintenance personnel and handling maintenance-related media.

Why This Domain Matters
Maintenance windows are security windows. Every technician, every tool, every remote session is a potential vector into your CUI boundary.

Related Domains

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo