CMMC Level 2 Controls List: All 110 Requirements
All 110 CMMC Level 2 security requirements from NIST SP 800-171 Revision 2, grouped by family, with the SPRS point weight each carries under the DoD Assessment Methodology. Requirement IDs use the official CMMC Level 2 format. Verified against 32 CFR Part 170 and the current assessment ecosystem, July 2026.
Every requirement below is identical whatever operating system you run. What changes is where you implement it and what evidence you produce. The tag on each line marks where the work usually lands on a Mac fleet built around Apple Business Manager, supervised enrollment and an approved MDM.
- macOS satisfied by a macOS platform capability
- MDM a setting or policy you push from your MDM
- Identity inherited from your identity or cloud provider
- Evidence the Mac supplies evidence, the control lives elsewhere
- Scoping the answer changes with the asset category
- Process an organizational control, no platform dimension
- Not endpoint network, facility or server scoped
These tags are planning guidance, not an assessment finding. They describe a typical architecture, and yours may move a row. The point values above are regulation; these tags are judgement.
Access Control (AC)
Limit system access to authorized users, processes, and devices, and limit the types of transactions and functions that authorized users are permitted to execute.
Mac angle: identity is the control plane - IdP-bound accounts, MDM screen-lock and session policies, and per-app VPN stand in for the GPO-era controls.
AC.L2-3.1.1 Authorized Access Control 5 ptsIdentity
AC.L2-3.1.2 Transaction & Function Control 5 ptsIdentity
AC.L2-3.1.3 Control CUI Flow 1 ptNot endpoint
AC.L2-3.1.4 Separation of Duties 1 ptProcess
AC.L2-3.1.5 Least Privilege 3 ptsMDM
AC.L2-3.1.6 Non-Privileged Account Use 1 ptMDM
AC.L2-3.1.7 Privileged Functions 1 ptMDM
AC.L2-3.1.8 Unsuccessful Logon Attempts 1 ptMDM
AC.L2-3.1.9 Privacy & Security Notices 1 ptMDM
AC.L2-3.1.10 Session Lock 1 ptMDM
AC.L2-3.1.11 Session Termination 1 ptMDM
AC.L2-3.1.12 Control Remote Access 5 ptsNot endpoint
AC.L2-3.1.13 Remote Access Confidentiality 5 ptsNot endpoint
AC.L2-3.1.14 Remote Access Routing 1 ptNot endpoint
AC.L2-3.1.15 Privileged Remote Access 1 ptNot endpoint
AC.L2-3.1.16 Wireless Access Authorization 5 ptsMDM
AC.L2-3.1.17 Wireless Access Protection 5 ptsMDM
AC.L2-3.1.18 Mobile Device Connection 5 ptsMDM
AC.L2-3.1.19 Encrypt CUI on Mobile 3 ptsmacOS
AC.L2-3.1.20 External Connections 1 ptScoping
AC.L2-3.1.21 Portable Storage Use 1 ptMDM
AC.L2-3.1.22 Control Public Information 1 ptProcess
Awareness and Training (AT)
Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems.
Mac angle: platform-neutral - training records and acknowledgments carry this family regardless of endpoint OS.
AT.L2-3.2.1 Role-Based Risk Awareness 5 ptsProcess
AT.L2-3.2.2 Role-Based Training 5 ptsProcess
AT.L2-3.2.3 Insider Threat Awareness 1 ptProcess
Audit and Accountability (AU)
Create, protect, and retain information system audit records to enable monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate system activity.
Mac angle: the unified log plus MDM/EDR forwarding cover generation; retention off-device is the usual Mac gap.
AU.L2-3.3.1 System Auditing 5 ptsmacOS
AU.L2-3.3.2 User Accountability 3 ptsmacOS
AU.L2-3.3.3 Event Review 1 ptEvidence
AU.L2-3.3.4 Audit Failure Alerting 1 ptNot endpoint
AU.L2-3.3.5 Audit Correlation 5 ptsNot endpoint
AU.L2-3.3.6 Reduction & Reporting 1 ptNot endpoint
AU.L2-3.3.7 Authoritative Time Source 1 ptMDM
AU.L2-3.3.8 Audit Protection 1 ptmacOS
AU.L2-3.3.9 Audit Management 1 ptIdentity
Configuration Management (CM)
Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles.
Mac angle: MDM configuration profiles and mSCP baselines are the enforcement mechanism; declarative management is the audit trail.
CM.L2-3.4.1 System Baselining 5 ptsMDM
CM.L2-3.4.2 Security Configuration Enforcement 5 ptsMDM
CM.L2-3.4.3 System Change Management 1 ptProcess
CM.L2-3.4.4 Security Impact Analysis 1 ptProcess
CM.L2-3.4.5 Access Restrictions for Change 5 ptsMDM
CM.L2-3.4.6 Least Functionality 5 ptsMDM
CM.L2-3.4.7 Nonessential Functionality 5 ptsMDM
CM.L2-3.4.8 Application Execution Policy 5 ptsMDM
CM.L2-3.4.9 User-Installed Software 1 ptMDM
Identification and Authentication (IA)
Identify information system users, processes acting on behalf of users, or devices and authenticate the identities of those users, processes, or devices as a prerequisite to allowing access.
Mac angle: Platform SSO and IdP-backed MFA retire the old Macs-cant-do-modern-auth objection.
IA.L2-3.5.1 Identification 5 ptsIdentity
IA.L2-3.5.2 Authentication 5 ptsIdentity
IA.L2-3.5.3 Multifactor Authentication 5 ptsIdentity
IA.L2-3.5.4 Replay-Resistant Authentication 1 ptIdentity
IA.L2-3.5.5 Identifier Reuse 1 ptIdentity
IA.L2-3.5.6 Identifier Handling 1 ptIdentity
IA.L2-3.5.7 Password Complexity 1 ptMDM
IA.L2-3.5.8 Password Reuse 1 ptMDM
IA.L2-3.5.9 Temporary Passwords 1 ptIdentity
IA.L2-3.5.10 Cryptographically-Protected Passwords 5 ptsmacOS
IA.L2-3.5.11 Obscure Feedback 1 ptmacOS
Incident Response (IR)
Establish an operational incident-handling capability for organizational systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.
Mac angle: process-heavy family; macOS EDR telemetry feeds detection and the incident record trail.
IR.L2-3.6.1 Incident Handling 5 ptsProcess
IR.L2-3.6.2 Incident Reporting 5 ptsProcess
IR.L2-3.6.3 Incident Response Testing 1 ptProcess
Maintenance (MA)
Perform timely maintenance on organizational systems and provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.
Mac angle: thin on Macs by design - document vendor service, remote-support rules, and sanitization before repair.
MA.L2-3.7.1 Perform Maintenance 3 ptsProcess
MA.L2-3.7.2 System Maintenance Control 5 ptsProcess
MA.L2-3.7.3 Equipment Sanitization 1 ptmacOS
MA.L2-3.7.4 Media Inspection 3 ptsProcess
MA.L2-3.7.5 Nonlocal Maintenance 5 ptsMDM
MA.L2-3.7.6 Maintenance Personnel 1 ptProcess
Media Protection (MP)
Protect system media containing CUI, both paper and digital, limit access to CUI on system media to authorized users, and sanitize or destroy system media before disposal or reuse.
Mac angle: FileVault at rest, encrypted externals, and MDM policy over AirDrop/USB media.
MP.L2-3.8.1 Media Protection 3 ptsProcess
MP.L2-3.8.2 Media Access 3 ptsMDM
MP.L2-3.8.3 Media Disposal 5 ptsmacOS
MP.L2-3.8.4 Media Markings 1 ptProcess
MP.L2-3.8.5 Media Accountability 1 ptProcess
MP.L2-3.8.6 Portable Storage Encryption 1 ptmacOS
MP.L2-3.8.7 Removable Media 5 ptsMDM
MP.L2-3.8.8 Shared Media 3 ptsMDM
MP.L2-3.8.9 Protect Backups 1 ptNot endpoint
Physical Protection (PE)
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
Mac angle: platform-neutral - facility controls, visitor records, and physical media handling.
PE.L2-3.10.1 Limit Physical Access 5 ptsNot endpoint
PE.L2-3.10.2 Monitor Facility 5 ptsNot endpoint
PE.L2-3.10.3 Escort Visitors 1 ptNot endpoint
PE.L2-3.10.4 Physical Access Logs 1 ptNot endpoint
PE.L2-3.10.5 Manage Physical Access 1 ptNot endpoint
PE.L2-3.10.6 Alternative Work Sites 1 ptProcess
Personnel Security (PS)
Screen individuals prior to authorizing access to organizational systems containing CUI and ensure that such systems are protected during and after personnel actions.
Mac angle: onboarding/offboarding ties directly to ABM assignment and MDM device lifecycle.
PS.L2-3.9.1 Screen Individuals 3 ptsProcess
PS.L2-3.9.2 Personnel Actions 5 ptsProcess
Risk Assessment (RA)
Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems and the processing, storage, or transmission of CUI.
Mac angle: macOS vulnerability agents exist - document scan cadence and how findings reach the POA&M.
RA.L2-3.11.1 Risk Assessments 3 ptsProcess
RA.L2-3.11.2 Vulnerability Scan 5 ptsMDM
RA.L2-3.11.3 Vulnerability Remediation 1 ptMDM
Security Assessment (CA)
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application and develop and implement plans of action to correct deficiencies.
Mac angle: the SSP, POA&M, and periodic self-assessment layer - where the whole system gets written down.
CA.L2-3.12.1 Security Control Assessment 5 ptsProcess
CA.L2-3.12.2 Plan of Action 3 ptsProcess
CA.L2-3.12.3 Security Control Monitoring 5 ptsEvidence
CA.L2-3.12.4 System Security Plan not scoredProcess
System and Communications Protection (SC)
Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of organizational systems.
Mac angle: boundary work - per-app VPN, DNS filtering, TLS in transit, FileVault at rest.
SC.L2-3.13.1 Boundary Protection 5 ptsNot endpoint
SC.L2-3.13.2 Security Engineering 5 ptsProcess
SC.L2-3.13.3 Role Separation 1 ptNot endpoint
SC.L2-3.13.4 Shared Resource Control 1 ptmacOS
SC.L2-3.13.5 Public-Access System Separation 5 ptsNot endpoint
SC.L2-3.13.6 Network Communication by Exception 5 ptsMDM
SC.L2-3.13.7 Split Tunneling 1 ptMDM
SC.L2-3.13.8 Data in Transit 3 ptsNot endpoint
SC.L2-3.13.9 Connections Termination 1 ptMDM
SC.L2-3.13.10 Key Management 1 ptmacOS
SC.L2-3.13.11 CUI Encryption 5 ptsmacOS
SC.L2-3.13.12 Collaborative Device Control 1 ptMDM
SC.L2-3.13.13 Mobile Code 1 ptMDM
SC.L2-3.13.14 Voice over Internet Protocol 1 ptNot endpoint
SC.L2-3.13.15 Communications Authenticity 5 ptsNot endpoint
SC.L2-3.13.16 Data at Rest 1 ptmacOS
System and Information Integrity (SI)
Identify, report, and correct information and information system flaws in a timely manner; provide protection from malicious code; and monitor information system security alerts and advisories.
Mac angle: Gatekeeper, notarization, and XProtect are built in; EDR plus enforced updates complete the family.
SI.L2-3.14.1 Flaw Remediation 5 ptsMDM
SI.L2-3.14.2 Malicious Code Protection 5 ptsmacOS
SI.L2-3.14.3 Security Alerts & Advisories 5 ptsProcess
SI.L2-3.14.4 Update Malicious Code Protection 5 ptsmacOS
SI.L2-3.14.5 System & File Scanning 3 ptsmacOS
SI.L2-3.14.6 Monitor Communications for Attacks 5 ptsNot endpoint
SI.L2-3.14.7 Identify Unauthorized Use 3 ptsEvidence
Scoring starts at 110. Each unmet requirement subtracts its point value. The values are codified at 32 CFR 170.24: 44 requirements are worth 5 points, 14 are worth 3, and 51 are worth 1. CA.L2-3.12.4, the system security plan, is not scored, because 32 CFR 170.24 treats an absent SSP as a finding that the assessment could not be completed rather than as a deduction.
The maximum total deduction is therefore 44x5 + 14x3 + 51x1 = 313, and the lowest possible score is 110 - 313 = -203. That -203 figure is arithmetic, not a published number: no DoD document states a floor. Vendors repeat it without a citation because there is no DoD source to cite.
Corrected 2026-08-03. An earlier version of this page carried point values from a superseded dataset, weighting 74 of the 110 requirements incorrectly and implying a floor of -238. Every value above has been rechecked against 32 CFR 170.24 and now reconciles to 313 and -203.
Correction, 2026-08-03. Six practice short names on this page previously read as paraphrases rather than the names published in the CMMC Level 2 Assessment Guide. AC.L2-3.1.19 is Encrypt CUI on Mobile, CM.L2-3.4.4 is Security Impact Analysis, PE.L2-3.10.2 is Monitor Facility, SC.L2-3.13.3 is Role Separation, SC.L2-3.13.9 is Connections Termination, and SC.L2-3.13.10 is Key Management. Point values and requirement text were not affected.