Perform and control maintenance of organizational systems — 6 requirements covering 14 total SPRS points.
The Maintenance domain requires organizations to control who performs maintenance on CUI systems, how maintenance is performed, and how tools and media used for maintenance are managed — including remote maintenance sessions. Maintenance activities represent a privileged, often poorly controlled access vector. Third-party technicians, remote diagnostic sessions, and unsanitized maintenance tools all create pathways for CUI exposure or system compromise.
Every NIST SP 800-171 Rev 2 requirement in the MA family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| MA.L2-3.7.1 | Perform maintenance on organizational systems. | 3 | Yes |
| MA.L2-3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel for the performance of organizational system maintenance. | 5 | Conditional |
| MA.L2-3.7.3 | Ensure equipment removed for off-site maintenance is sanitized of any CUI. | 1 | Yes |
| MA.L2-3.7.4 | Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. | 3 | Yes |
| MA.L2-3.7.5 | Require MFA to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. | 5 | Conditional |
| MA.L2-3.7.6 | Supervise the maintenance activities of maintenance personnel without required access authorization. | 1 | Yes |
Schedule, track, and document all system maintenance activities with complete audit trails. The platform captures who performed maintenance, what was done, and when, satisfying 3.7.1 with assessment-ready evidence.
Maintain approved lists of maintenance tools, techniques, and authorized personnel. The platform tracks tool inspections, personnel clearances, and supervision requirements for 3.7.2 and 3.7.6 compliance.
Document sanitization procedures for equipment removed for off-site maintenance and media scanning protocols. The platform provides checklists and evidence capture for 3.7.3 and 3.7.4 requirements.
Track nonlocal maintenance sessions with MFA enforcement and session termination controls. The platform documents your remote maintenance architecture and access controls to satisfy 3.7.5.
These tools are commonly used by defense contractors to satisfy MA requirements. During your C3PAO assessment, you’ll document exactly which tools satisfy each control.
Assessors will look for maintenance logs, check whether remote maintenance sessions are monitored and controlled, and verify that tools used for maintenance are inspected for malicious code. They’ll ask about procedures for authorizing maintenance personnel and handling maintenance-related media.
Maintenance windows are security windows. Every technician, every tool, every remote session is a potential vector into your CUI boundary.
1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.
Request a Demo