CMMC Level 2 Controls List: All 110 Requirements

Reference

All 110 CMMC Level 2 security requirements from NIST SP 800-171 Revision 2, grouped by family, with the SPRS point weight each carries under the DoD Assessment Methodology. Requirement IDs use the official CMMC Level 2 format. Verified against 32 CFR Part 170 and the current assessment ecosystem, July 2026.

Companion references: the acronym glossary, the key dates timeline, the ecosystem map, and the DFARS clause guide - or browse the full reference shelf. For how each family translates to Apple hardware, start with CMMC for macOS.
Where each requirement is settled on a Mac fleet

Every requirement below is identical whatever operating system you run. What changes is where you implement it and what evidence you produce. The tag on each line marks where the work usually lands on a Mac fleet built around Apple Business Manager, supervised enrollment and an approved MDM.

  • macOS satisfied by a macOS platform capability
  • MDM a setting or policy you push from your MDM
  • Identity inherited from your identity or cloud provider
  • Evidence the Mac supplies evidence, the control lives elsewhere
  • Scoping the answer changes with the asset category
  • Process an organizational control, no platform dimension
  • Not endpoint network, facility or server scoped

These tags are planning guidance, not an assessment finding. They describe a typical architecture, and yours may move a row. The point values above are regulation; these tags are judgement.

Access Control (AC)

Limit system access to authorized users, processes, and devices, and limit the types of transactions and functions that authorized users are permitted to execute.

Mac angle: identity is the control plane - IdP-bound accounts, MDM screen-lock and session policies, and per-app VPN stand in for the GPO-era controls.

AC.L2-3.1.1 Authorized Access Control 5 ptsIdentity

AC.L2-3.1.2 Transaction & Function Control 5 ptsIdentity

AC.L2-3.1.3 Control CUI Flow 1 ptNot endpoint

AC.L2-3.1.4 Separation of Duties 1 ptProcess

AC.L2-3.1.5 Least Privilege 3 ptsMDM

AC.L2-3.1.6 Non-Privileged Account Use 1 ptMDM

AC.L2-3.1.7 Privileged Functions 1 ptMDM

AC.L2-3.1.8 Unsuccessful Logon Attempts 1 ptMDM

AC.L2-3.1.9 Privacy & Security Notices 1 ptMDM

AC.L2-3.1.10 Session Lock 1 ptMDM

AC.L2-3.1.11 Session Termination 1 ptMDM

AC.L2-3.1.12 Control Remote Access 5 ptsNot endpoint

AC.L2-3.1.13 Remote Access Confidentiality 5 ptsNot endpoint

AC.L2-3.1.14 Remote Access Routing 1 ptNot endpoint

AC.L2-3.1.15 Privileged Remote Access 1 ptNot endpoint

AC.L2-3.1.16 Wireless Access Authorization 5 ptsMDM

AC.L2-3.1.17 Wireless Access Protection 5 ptsMDM

AC.L2-3.1.18 Mobile Device Connection 5 ptsMDM

AC.L2-3.1.19 Encrypt CUI on Mobile 3 ptsmacOS

AC.L2-3.1.20 External Connections 1 ptScoping

AC.L2-3.1.21 Portable Storage Use 1 ptMDM

AC.L2-3.1.22 Control Public Information 1 ptProcess

Awareness and Training (AT)

Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems.

Mac angle: platform-neutral - training records and acknowledgments carry this family regardless of endpoint OS.

AT.L2-3.2.1 Role-Based Risk Awareness 5 ptsProcess

AT.L2-3.2.2 Role-Based Training 5 ptsProcess

AT.L2-3.2.3 Insider Threat Awareness 1 ptProcess

Audit and Accountability (AU)

Create, protect, and retain information system audit records to enable monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate system activity.

Mac angle: the unified log plus MDM/EDR forwarding cover generation; retention off-device is the usual Mac gap.

AU.L2-3.3.1 System Auditing 5 ptsmacOS

AU.L2-3.3.2 User Accountability 3 ptsmacOS

AU.L2-3.3.3 Event Review 1 ptEvidence

AU.L2-3.3.4 Audit Failure Alerting 1 ptNot endpoint

AU.L2-3.3.5 Audit Correlation 5 ptsNot endpoint

AU.L2-3.3.6 Reduction & Reporting 1 ptNot endpoint

AU.L2-3.3.7 Authoritative Time Source 1 ptMDM

AU.L2-3.3.8 Audit Protection 1 ptmacOS

AU.L2-3.3.9 Audit Management 1 ptIdentity

Configuration Management (CM)

Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles.

Mac angle: MDM configuration profiles and mSCP baselines are the enforcement mechanism; declarative management is the audit trail.

CM.L2-3.4.1 System Baselining 5 ptsMDM

CM.L2-3.4.2 Security Configuration Enforcement 5 ptsMDM

CM.L2-3.4.3 System Change Management 1 ptProcess

CM.L2-3.4.4 Security Impact Analysis 1 ptProcess

CM.L2-3.4.5 Access Restrictions for Change 5 ptsMDM

CM.L2-3.4.6 Least Functionality 5 ptsMDM

CM.L2-3.4.7 Nonessential Functionality 5 ptsMDM

CM.L2-3.4.8 Application Execution Policy 5 ptsMDM

CM.L2-3.4.9 User-Installed Software 1 ptMDM

Identification and Authentication (IA)

Identify information system users, processes acting on behalf of users, or devices and authenticate the identities of those users, processes, or devices as a prerequisite to allowing access.

Mac angle: Platform SSO and IdP-backed MFA retire the old Macs-cant-do-modern-auth objection.

IA.L2-3.5.1 Identification 5 ptsIdentity

IA.L2-3.5.2 Authentication 5 ptsIdentity

IA.L2-3.5.3 Multifactor Authentication 5 ptsIdentity

IA.L2-3.5.4 Replay-Resistant Authentication 1 ptIdentity

IA.L2-3.5.5 Identifier Reuse 1 ptIdentity

IA.L2-3.5.6 Identifier Handling 1 ptIdentity

IA.L2-3.5.7 Password Complexity 1 ptMDM

IA.L2-3.5.8 Password Reuse 1 ptMDM

IA.L2-3.5.9 Temporary Passwords 1 ptIdentity

IA.L2-3.5.10 Cryptographically-Protected Passwords 5 ptsmacOS

IA.L2-3.5.11 Obscure Feedback 1 ptmacOS

Incident Response (IR)

Establish an operational incident-handling capability for organizational systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.

Mac angle: process-heavy family; macOS EDR telemetry feeds detection and the incident record trail.

IR.L2-3.6.1 Incident Handling 5 ptsProcess

IR.L2-3.6.2 Incident Reporting 5 ptsProcess

IR.L2-3.6.3 Incident Response Testing 1 ptProcess

Maintenance (MA)

Perform timely maintenance on organizational systems and provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

Mac angle: thin on Macs by design - document vendor service, remote-support rules, and sanitization before repair.

MA.L2-3.7.1 Perform Maintenance 3 ptsProcess

MA.L2-3.7.2 System Maintenance Control 5 ptsProcess

MA.L2-3.7.3 Equipment Sanitization 1 ptmacOS

MA.L2-3.7.4 Media Inspection 3 ptsProcess

MA.L2-3.7.5 Nonlocal Maintenance 5 ptsMDM

MA.L2-3.7.6 Maintenance Personnel 1 ptProcess

Media Protection (MP)

Protect system media containing CUI, both paper and digital, limit access to CUI on system media to authorized users, and sanitize or destroy system media before disposal or reuse.

Mac angle: FileVault at rest, encrypted externals, and MDM policy over AirDrop/USB media.

MP.L2-3.8.1 Media Protection 3 ptsProcess

MP.L2-3.8.2 Media Access 3 ptsMDM

MP.L2-3.8.3 Media Disposal 5 ptsmacOS

MP.L2-3.8.4 Media Markings 1 ptProcess

MP.L2-3.8.5 Media Accountability 1 ptProcess

MP.L2-3.8.6 Portable Storage Encryption 1 ptmacOS

MP.L2-3.8.7 Removable Media 5 ptsMDM

MP.L2-3.8.8 Shared Media 3 ptsMDM

MP.L2-3.8.9 Protect Backups 1 ptNot endpoint

Physical Protection (PE)

Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

Mac angle: platform-neutral - facility controls, visitor records, and physical media handling.

PE.L2-3.10.1 Limit Physical Access 5 ptsNot endpoint

PE.L2-3.10.2 Monitor Facility 5 ptsNot endpoint

PE.L2-3.10.3 Escort Visitors 1 ptNot endpoint

PE.L2-3.10.4 Physical Access Logs 1 ptNot endpoint

PE.L2-3.10.5 Manage Physical Access 1 ptNot endpoint

PE.L2-3.10.6 Alternative Work Sites 1 ptProcess

Personnel Security (PS)

Screen individuals prior to authorizing access to organizational systems containing CUI and ensure that such systems are protected during and after personnel actions.

Mac angle: onboarding/offboarding ties directly to ABM assignment and MDM device lifecycle.

PS.L2-3.9.1 Screen Individuals 3 ptsProcess

PS.L2-3.9.2 Personnel Actions 5 ptsProcess

Risk Assessment (RA)

Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems and the processing, storage, or transmission of CUI.

Mac angle: macOS vulnerability agents exist - document scan cadence and how findings reach the POA&M.

RA.L2-3.11.1 Risk Assessments 3 ptsProcess

RA.L2-3.11.2 Vulnerability Scan 5 ptsMDM

RA.L2-3.11.3 Vulnerability Remediation 1 ptMDM

Security Assessment (CA)

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application and develop and implement plans of action to correct deficiencies.

Mac angle: the SSP, POA&M, and periodic self-assessment layer - where the whole system gets written down.

CA.L2-3.12.1 Security Control Assessment 5 ptsProcess

CA.L2-3.12.2 Plan of Action 3 ptsProcess

CA.L2-3.12.3 Security Control Monitoring 5 ptsEvidence

CA.L2-3.12.4 System Security Plan not scoredProcess

System and Communications Protection (SC)

Monitor, control, and protect organizational communications at the external boundaries and key internal boundaries of organizational systems.

Mac angle: boundary work - per-app VPN, DNS filtering, TLS in transit, FileVault at rest.

SC.L2-3.13.1 Boundary Protection 5 ptsNot endpoint

SC.L2-3.13.2 Security Engineering 5 ptsProcess

SC.L2-3.13.3 Role Separation 1 ptNot endpoint

SC.L2-3.13.4 Shared Resource Control 1 ptmacOS

SC.L2-3.13.5 Public-Access System Separation 5 ptsNot endpoint

SC.L2-3.13.6 Network Communication by Exception 5 ptsMDM

SC.L2-3.13.7 Split Tunneling 1 ptMDM

SC.L2-3.13.8 Data in Transit 3 ptsNot endpoint

SC.L2-3.13.9 Connections Termination 1 ptMDM

SC.L2-3.13.10 Key Management 1 ptmacOS

SC.L2-3.13.11 CUI Encryption 5 ptsmacOS

SC.L2-3.13.12 Collaborative Device Control 1 ptMDM

SC.L2-3.13.13 Mobile Code 1 ptMDM

SC.L2-3.13.14 Voice over Internet Protocol 1 ptNot endpoint

SC.L2-3.13.15 Communications Authenticity 5 ptsNot endpoint

SC.L2-3.13.16 Data at Rest 1 ptmacOS

System and Information Integrity (SI)

Identify, report, and correct information and information system flaws in a timely manner; provide protection from malicious code; and monitor information system security alerts and advisories.

Mac angle: Gatekeeper, notarization, and XProtect are built in; EDR plus enforced updates complete the family.

SI.L2-3.14.1 Flaw Remediation 5 ptsMDM

SI.L2-3.14.2 Malicious Code Protection 5 ptsmacOS

SI.L2-3.14.3 Security Alerts & Advisories 5 ptsProcess

SI.L2-3.14.4 Update Malicious Code Protection 5 ptsmacOS

SI.L2-3.14.5 System & File Scanning 3 ptsmacOS

SI.L2-3.14.6 Monitor Communications for Attacks 5 ptsNot endpoint

SI.L2-3.14.7 Identify Unauthorized Use 3 ptsEvidence

Every requirement above maps to a policy, procedure, or workbook in the CMMC Operator Suite - written Mac-first, cross-referenced by artifact ID. The guides behind each family live in the library.
How these point values work, and a correction

Scoring starts at 110. Each unmet requirement subtracts its point value. The values are codified at 32 CFR 170.24: 44 requirements are worth 5 points, 14 are worth 3, and 51 are worth 1. CA.L2-3.12.4, the system security plan, is not scored, because 32 CFR 170.24 treats an absent SSP as a finding that the assessment could not be completed rather than as a deduction.

The maximum total deduction is therefore 44x5 + 14x3 + 51x1 = 313, and the lowest possible score is 110 - 313 = -203. That -203 figure is arithmetic, not a published number: no DoD document states a floor. Vendors repeat it without a citation because there is no DoD source to cite.

Corrected 2026-08-03. An earlier version of this page carried point values from a superseded dataset, weighting 74 of the 110 requirements incorrectly and implying a floor of -238. Every value above has been rechecked against 32 CFR 170.24 and now reconciles to 313 and -203.

Correction, 2026-08-03. Six practice short names on this page previously read as paraphrases rather than the names published in the CMMC Level 2 Assessment Guide. AC.L2-3.1.19 is Encrypt CUI on Mobile, CM.L2-3.4.4 is Security Impact Analysis, PE.L2-3.10.2 is Monitor Facility, SC.L2-3.13.3 is Role Separation, SC.L2-3.13.9 is Connections Termination, and SC.L2-3.13.10 is Key Management. Point values and requirement text were not affected.