What Does CMMC Continuous Monitoring Actually Require?

The short version

Continuous monitoring is not a product you buy. It is a cadence you can evidence. CMMC names it once, at CA.L2-3.12.3, and then quietly attaches it to most of the other 109 requirements through the records they depend on.

The failure mode is almost never "we were not monitoring". It is "we cannot show that we were".

What does CMMC actually require for continuous monitoring?

One requirement states it directly. CA.L2-3.12.3 requires you to monitor security controls on an ongoing basis to ensure their continued effectiveness. That is the whole text. It names no tool, no frequency and no format.

The frequency comes from you. That is the part most programs miss, and it is the reason continuous monitoring is harder to sustain than it looks.

Why does the cadence come from your own policies?

CMMC does not tell you to review privileged accounts monthly. Your access control policy does. CMMC does not set your vulnerability scan interval. Your risk assessment policy does. The requirement is that controls stay effective; the schedule that proves it is organization-defined.

So every policy you adopt silently creates recurring work, and an assessor holds you to your stated cadence, not to a standard one. A policy that says quarterly and a folder that shows one review is a finding against your own document.

The rule that catches peopleAn assessor asks for the last three months of records, not the last one. A single recent record with nothing behind it dates the start of your cadence to the day the assessment was scheduled. That is itself the finding.

How much recurring work does CMMC Level 2 actually create?

Almost nobody counts this before committing to it. We did, against a fully worked Access Control section: 22 requirements, all 70 assessment objectives, each with a named evidence artifact and a refresh interval.

26
quarterly
17
annual
11
monthly
16
on change or per event
54
recurring in total

54 recurring obligations, from one family out of fourteen. Access Control is the largest family, so the other thirteen will be lighter, but the shape holds: a Level 2 program in steady state is a few hundred small recurring acts, not an annual project.

Counted from the Access Control section of the CMMC Operator SSP template. The requirement set creates the obligations; writing them down only makes them visible. Your own cadences may differ, and a leaner program is legitimate if you can defend it.

Which requirements carry the monitoring load?

CA.L2-3.12.3 is the named one. In practice the recurring work clusters in a handful of places:

  • Audit and Accountability. Reviewing logged events, and proving the review happened rather than the logging.
  • Risk Assessment. Scanning on your stated interval, and closing what you find on your stated timeline.
  • System and Information Integrity. Flaw remediation, alert handling, and detecting attacks.
  • Configuration Management. Baselines drift. Detecting drift is monitoring; a baseline set once is a snapshot.
  • Access Control. Account and privilege reviews, which are the most commonly skipped recurring task in small programs.

What makes continuous monitoring fail?

  • The record does not exist. The check happened, nobody wrote it down. A step is complete when its output record exists, not when the action is believed to have happened.
  • The cadence started late. See the three-month rule above.
  • The policy over-commits. Weekly sounded rigorous when the policy was written. Nobody sustained it. Writing monthly and doing monthly beats writing weekly and doing nothing.
  • Nobody owns it. A cadence without a named role is a cadence that stops the first time someone is on leave.
  • It lives in the SSP and nowhere else. Obligations written one line at a time inside a long document are invisible on any given Monday.

Where should a small program start?

  • Collect the obligations into one list before improving any of them. You cannot operate a schedule you have never seen in one place.
  • Give each one an owner and an output record. Name the artifact, not the activity.
  • Set intervals you will actually hold, then align the policy to them rather than the reverse.
  • Start the clock now. Three months of ordinary records beats a perfect month assembled the week before.
Planning use only

This page describes a discipline, not a legal or assessment position. It is not legal advice, not an assessment finding, and not a substitute for a C3PAO. Your cadences are yours to set and to defend.

The cadence, written down as a procedure

CMO-PRO-CONMON-001 turns this discipline into seven steps with an actor, a trigger and a named output record for each, tied to the maintenance and assessment policies that set the intervals. It ships with the policies those cadences come from, so the schedule and the document that mandates it stay consistent.

See what is in the suite

Mac-first, one-time purchase, no subscription.

Where this fits