Periodically assess, monitor, and remediate security controls — 4 requirements covering 13 total SPRS points.
The Security Assessment domain requires organizations to periodically assess their security controls, develop and implement plans of action, monitor system security on an ongoing basis, and manage the development and implementation of security plans. Security is not a one-time event. Controls that worked last year may be misconfigured, outdated, or bypassed today. Periodic assessment closes the gap between documented intent and operational reality.
Every NIST SP 800-171 Rev 2 requirement in the CA family, with SPRS point weight and POA&M eligibility.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| CA.L2-3.12.1 | Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. | 5 | Conditional |
| CA.L2-3.12.2 | Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. | 3 | Yes |
| CA.L2-3.12.3 | Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. | 5 | Conditional |
| CA.L2-3.12.4 | Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. (Not point-scored — a missing SSP invalidates the entire assessment rather than deducting points.) | 0 | N/A |
Systematically evaluate every security control against NIST SP 800-171 objectives. The engine walks assessors through each determination, captures findings, and generates assessment reports that satisfy 3.12.1.
Create, assign, and track plans of action and milestones with due dates, responsible parties, and completion evidence. Deficiencies flow directly from assessments into actionable POA&M items, covering 3.12.2 end-to-end.
Track control effectiveness in real time with automated status indicators, trend analysis, and alerting. The dashboard provides the ongoing visibility 3.12.3 requires without manual spreadsheet updates.
Build and maintain your SSP with guided templates covering system boundaries, operating environments, control implementations, and interconnections. Version history ensures you can demonstrate periodic updates for 3.12.4.
Schedule periodic assessments, assign assessment teams, and track completion across all control families. Automated reminders ensure assessments happen on cadence and nothing falls through the cracks.
These tools are commonly used by defense contractors to satisfy CA requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.
Assessors will review your SSP for completeness and accuracy, verify your POA&M has credible timelines and owners, and ask about your internal assessment cadence. They expect to see evidence that you're continuously monitoring your security posture — not just documenting it once.
Your SSP is the single document that defines your compliance posture. If it doesn't match your actual environment, your C3PAO will find the gap before you do.
1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.
Request a Demo