What Does CMMC Continuous Monitoring Actually Require?
Continuous monitoring is not a product you buy. It is a cadence you can evidence. CMMC names it once, at CA.L2-3.12.3, and then quietly attaches it to most of the other 109 requirements through the records they depend on.
The failure mode is almost never "we were not monitoring". It is "we cannot show that we were".
What does CMMC actually require for continuous monitoring?
One requirement states it directly. CA.L2-3.12.3 requires you to monitor security controls on an ongoing basis to ensure their continued effectiveness. That is the whole text. It names no tool, no frequency and no format.
The frequency comes from you. That is the part most programs miss, and it is the reason continuous monitoring is harder to sustain than it looks.
Why does the cadence come from your own policies?
CMMC does not tell you to review privileged accounts monthly. Your access control policy does. CMMC does not set your vulnerability scan interval. Your risk assessment policy does. The requirement is that controls stay effective; the schedule that proves it is organization-defined.
So every policy you adopt silently creates recurring work, and an assessor holds you to your stated cadence, not to a standard one. A policy that says quarterly and a folder that shows one review is a finding against your own document.
How much recurring work does CMMC Level 2 actually create?
Almost nobody counts this before committing to it. We did, against a fully worked Access Control section: 22 requirements, all 70 assessment objectives, each with a named evidence artifact and a refresh interval.
54 recurring obligations, from one family out of fourteen. Access Control is the largest family, so the other thirteen will be lighter, but the shape holds: a Level 2 program in steady state is a few hundred small recurring acts, not an annual project.
Counted from the Access Control section of the CMMC Operator SSP template. The requirement set creates the obligations; writing them down only makes them visible. Your own cadences may differ, and a leaner program is legitimate if you can defend it.
Which requirements carry the monitoring load?
CA.L2-3.12.3 is the named one. In practice the recurring work clusters in a handful of places:
- Audit and Accountability. Reviewing logged events, and proving the review happened rather than the logging.
- Risk Assessment. Scanning on your stated interval, and closing what you find on your stated timeline.
- System and Information Integrity. Flaw remediation, alert handling, and detecting attacks.
- Configuration Management. Baselines drift. Detecting drift is monitoring; a baseline set once is a snapshot.
- Access Control. Account and privilege reviews, which are the most commonly skipped recurring task in small programs.
What makes continuous monitoring fail?
- The record does not exist. The check happened, nobody wrote it down. A step is complete when its output record exists, not when the action is believed to have happened.
- The cadence started late. See the three-month rule above.
- The policy over-commits. Weekly sounded rigorous when the policy was written. Nobody sustained it. Writing monthly and doing monthly beats writing weekly and doing nothing.
- Nobody owns it. A cadence without a named role is a cadence that stops the first time someone is on leave.
- It lives in the SSP and nowhere else. Obligations written one line at a time inside a long document are invisible on any given Monday.
Where should a small program start?
- Collect the obligations into one list before improving any of them. You cannot operate a schedule you have never seen in one place.
- Give each one an owner and an output record. Name the artifact, not the activity.
- Set intervals you will actually hold, then align the policy to them rather than the reverse.
- Start the clock now. Three months of ordinary records beats a perfect month assembled the week before.
This page describes a discipline, not a legal or assessment position. It is not legal advice, not an assessment finding, and not a substitute for a C3PAO. Your cadences are yours to set and to defend.
CMO-PRO-CONMON-001 turns this discipline into seven steps with an actor, a trigger and a named output record for each, tied to the maintenance and assessment policies that set the intervals. It ships with the policies those cadences come from, so the schedule and the document that mandates it stay consistent.
See what is in the suiteMac-first, one-time purchase, no subscription.
- What the records actually have to show evidence per assessment objective, with a worked example.
- Which assets carry the load scope category decides how much recurring work an asset brings.
- All 110 requirements with SPRS point values and Mac disposition.