| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.AC.1.001 | Limit information system access to authorized users, processes acting on behalf of authorized users, and devices (including other information systems). | User access lists, IAM policies, access control lists | FAR 52.204-21 |
| L1.AC.1.002 | Limit information system access to the types of transactions and functions that authorized users are permitted to exercise. | Role-based access control matrix, RBAC configuration | FAR 52.204-21 |
| L1.AC.1.003 | Verify and control/limit connections to and use of external information systems. | VPN policy, external system usage agreements | FAR 52.204-21 |
| L1.AC.1.004 | Control information posted or processed on publicly accessible information systems. | Public content review process, FCI marking procedures | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.IA.1.001 | Identify information system users and processes acting on behalf of users. | User account inventory, identity management records | FAR 52.204-21 |
| L1.IA.1.002 | Identify asset owners and confirm asset ownership before acquiring, providing, or granting access to organizational assets. | Asset ownership registry, access provisioning forms | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.MP.1.001 | Protect (e.g., physically control and securely store) information system media containing Federal Contract Information, until media is sanitized or destroyed. | Media storage logs, locked storage containers, media checkout procedures | FAR 52.204-21 |
| L1.MP.1.002 | Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. | Media sanitization certificates, disposal logs, NIST 800-88 compliant wipe records | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.PS.1.001 | Screen individuals prior to authorizing access to organizational information systems containing Federal Contract Information. | Background check records, screening policy, access authorization forms | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.PE.1.001 | Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. | Visitor logs, access badge system, physical security policies | FAR 52.204-21 |
| L1.PE.1.002 | Provide security safeguards for each designated system, equipment, and operating environment to prevent unauthorized access and use. | Locked server rooms, security cameras, alarm systems, entry logs | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.SC.1.001 | Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundary and key internal boundaries of the information systems. | Firewall rules, network diagrams, perimeter monitoring logs | FAR 52.204-21 |
| L1.SC.1.002 | Employ cryptographic mechanisms to protect organizational information in storage and in transit over any medium that is not owned, operated, or controlled by the organization. | TLS/SSL certificates, VPN configuration, encryption at rest policies | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L1.SI.1.001 | Identify, report, and correct information system flaws in a timely manner. | Patch management logs, vulnerability remediation records, SLA documentation | FAR 52.204-21 |
| L1.SI.1.002 | Provide protection from malicious code (e.g., anti-virus, anti-spyware) at appropriate locations within organizational information systems. | EDR/AV deployment records, updated definitions, scan logs | FAR 52.204-21 |
| L1.SI.1.003 | Monitor system security alerts and distribute appropriate information to appropriate personnel within the organization. | SIEM dashboards, alert routing procedures, incident response contacts | FAR 52.204-21 |
| L1.SI.1.004 | Update malicious code protection mechanisms when new releases are available. | Update schedules, version tracking, deployment records | FAR 52.204-21 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| AC.L2-3.1.1 | Limit information system access to authorized users, processes acting on behalf of authorized users, and authorized devices (including other information systems). | IAM policies, user provisioning logs, access control matrix | NIST SP 800-171 |
| AC.L2-3.1.2 | Limit information system access to the types of transactions and functions that authorized users are permitted to exercise. | RBAC configuration, application access controls | NIST SP 800-171 |
| AC.L2-3.1.3 | Control the flow of CUI in accordance with approved authorizations. | Data flow diagrams, information barrier policies, DLP configuration | NIST SP 800-171 |
| AC.L2-3.1.4 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion. | Duties segregation matrix, role assignments | NIST SP 800-171 |
| AC.L2-3.1.5 | Employ the principle of least privilege, allowing only authorized accesses necessary for users' assigned duties. | Privileged access management, minimal privilege policy | NIST SP 800-171 |
| AC.L2-3.1.6 | Use non-privileged accounts or roles when accessing nonsecurity functions. | Separated admin/user roles, privileged access workstation (PAW) usage | NIST SP 800-171 |
| AC.L2-3.1.7 | Prevent non-privileged users from executing privileged functions and audit execution of privileged functions. | Privileged function monitoring, admin action logs | NIST SP 800-171 |
| AC.L2-3.1.11 | Terminate information system connections after 15 minutes of inactivity. | Session timeout policies, idle timeout configuration | NIST SP 800-171 |
| AC.L2-3.1.12 | VPN logs, remote access policy, jump server configuration | NIST SP 800-171 | |
| AC.L2-3.1.14 | Control the flow of CUI external to the organization. Control content of CUI in transit. | Encryption in transit, approved communication channels, CUI marking | NIST SP 800-171 |
| AC.L2-3.1.15 | Implement subnetworks for publicly accessible system components that are physically/logically separated from internal networks. | DMZ architecture, network segmentation diagrams | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| AT.L2-3.2.1 | Ensure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. | Security awareness training records, completion certificates, training calendar | NIST SP 800-171 |
| AT.L2-3.2.2 | Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. | Training completion records, role-specific curricula, skills assessments | NIST SP 800-171 |
| AT.L2-3.2.3 | Provide security awareness training on recognizing and reporting potential and actual security incidents. | Incident reporting procedure, phishing simulation results, training materials | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| AU.L2-3.3.1 | Create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity. | SIEM configuration, log retention policy, audit log storage | NIST SP 800-171 |
| AU.L2-3.3.2 | Ensure that the actions of individual information system users can be uniquely traced to those users so that they can be held accountable for their actions. | Unique user IDs, authentication logs, audit trail integrity | NIST SP 800-171 |
| AU.L2-3.3.3 | Review and update logged events. Alert appropriate personnel of audit processing failures. | Log review schedule, alerting rules, escalation procedures | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| CM.L2-3.4.1 | Establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. | System inventory, configuration baseline documents, asset management system | NIST SP 800-171 |
| CM.L2-3.4.2 | Establish and enforce security configuration settings for information technology products employed on organizational information systems. | STIGs/benchmarks applied, CIS benchmarks, configuration baselines | NIST SP 800-171 |
| CM.L2-3.4.3 | Track, review, approve/disapprove, and audit changes to organizational information systems. | Change management process, CAB meeting records, change tickets | NIST SP 800-171 |
| CM.L2-3.4.5 | Define, implement, and evaluate security safeguards/countermeasures as part of a configuration management process. | Security controls documentation, SSP, remediation records | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| IA.L2-3.5.1 | Identify information system users, processes acting on behalf of users, and devices. | Identity management system, user account inventory | NIST SP 800-171 |
| IA.L2-3.5.2 | Authenticate (or verify) the identity of those users, processes, or devices as a prerequisite to allowing access to organizational information systems. | MFA enforcement, password policy, authentication logs | NIST SP 800-171 |
| IA.L2-3.5.3 | Use multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. | MFA coverage reports, conditional access policies, authentication methods used | NIST SP 800-171 |
| IA.L2-3.5.4 | Prevent reuse of identifiers. Prohibit the reuse of the same identifier across the organization's information systems. | Unique identifier policy, deprovisioning procedures | NIST SP 800-171 |
| IA.L2-3.5.5 | Prevent the use of expired passwords. Disable identifiers after 35 days of inactivity. | Account lifecycle policy, automated deactivation schedules | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| IR.L2-3.6.1 | Establish an operational incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, eradication, and recovery. | IR plan, incident response team contacts, runbooks | NIST SP 800-171 |
| IR.L2-3.6.2 | Track, document, and report incidents to designated organizational officials and/or authorities. | Incident reporting procedures, DoDreporting requirements, CUI incident chain of custody | NIST SP 800-171 |
| IR.L2-3.6.3 | Test the organizational incident response capability. | Incident response exercises, tabletop test results, after-action reports | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| MA.L2-3.7.1 | Perform periodic and on-demand maintenance on organizational information systems, and provide maintenance support. | Maintenance schedule, maintenance logs, vendor support agreements | NIST SP 800-171 |
| MA.L2-3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance. | Maintenance accounts, remote access controls for vendors | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| MP.L2-3.8.1 | Protect (i.e., physically control and securely store) information system media containing CUI, both paper and digital. | Locked storage, media accountability logs, CUI handling procedures | NIST SP 800-171 |
| MP.L2-3.8.2 | Sanitize or destroy information system media containing CUI before disposal or release for reuse. | NIST SP 800-88 compliant sanitization, disposal certificates | NIST SP 800-171 |
| MP.L2-3.8.3 | Control access to media containing CUI, and maintain accountability for media during transport. | Media transport logs, chain of custody forms, escort procedures | NIST SP 800-171 |
| MP.L2-3.8.4 | Mark media with CUI distribution restrictions and applicable CUI markings. | CUI labeling standard (DFARS 252.204-7012), media marking templates | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| PS.L2-3.9.1 | Screen individuals prior to authorizing access to information systems containing CUI. | Background investigation records, NISPOM compliance, screening policy | NIST SP 800-171 |
| PS.L2-3.9.2 | Ensure that organizational information systems containing CUI are protected during personnel actions such as terminations and transfers. | Offboarding checklists, access revocation procedures, exit interviews | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| PE.L2-3.10.1 | Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. | Access badge system, visitor logs, alarm systems, mantrap entries | NIST SP 800-171 |
| PE.L2-3.10.2 | Provide security safeguards to protect against and limit the effects of environmental threats. | Environmental controls (fire suppression, HVAC), DR location considerations | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| RA.L2-3.11.1 | Periodically assess the risk to organizational operations, assets, and individuals, using the results of the security assessment. | Annual risk assessment, SSP updates, risk register | NIST SP 800-171 |
| RA.L2-3.11.2 | Scan for vulnerabilities in organizational information systems and remediate those vulnerabilities according to an assessed level of risk. | Vulnerability scan reports, patch cadence records, remediation tracking | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| CA.L2-3.12.1 | Develop, document, and periodically update system security plans describing the security controls and the process to implement those controls. | System Security Plan (SSP), POA&M, plan review schedule | NIST SP 800-171 |
| CA.L2-3.12.2 | Develop, document, and implement processes to monitor and respond to findings from security assessments, audits, and reviews. | Audit response procedures, remediation tracking, SSP updates | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| SC.L2-3.13.1 | Monitor, control, and protect communications (i.e., information transmitted or received by organizational information systems) at the external boundary and at key internal boundaries of organizational information systems. | Firewall rules, IDS/IPS, segmentation architecture | NIST SP 800-171 |
| SC.L2-3.13.3 | Use cryptographic mechanisms to prevent unauthorized disclosure and modification of CUI during transmission. | TLS 1.2+, FIPS 140-2 validated crypto modules, VPN for all CUI transmission | NIST SP 800-171 |
| SC.L2-3.13.5 | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | DMZ configuration, web server isolation, perimeter security | NIST SP 800-171 |
| SC.L2-3.13.6 | Deny network communications traffic by default. Allow only exception-based communications on a per-port/protocol basis. | Default-deny firewall policy, whitelisted ports and protocols | NIST SP 800-171 |
| SC.L2-3.13.15 | Use controlled releases (e.g., formal change control, security impact analysis, testing) to manage roll-out of new functionality to operational environments. | Staged deployment process, change management, security testing in staging | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| SI.L2-3.14.1 | Identify, report, and correct system flaws in a timely manner. | Patch management policy, SLA compliance records, CVSS scoring process | NIST SP 800-171 |
| SI.L2-3.14.2 | Provide protection from malicious code at appropriate locations within organizational information systems. | EDR/AV deployed and updated, endpoint protection coverage reports | NIST SP 800-171 |
| SI.L2-3.14.3 | SIEM configuration, alert routing matrix, CISA AIS notifications | NIST SP 800-171 | |
| SI.L2-3.14.4 | Verify the integrity of information system software and firmware using cryptographic mechanisms (e.g., code signing, hash comparison). | Code signing infrastructure, firmware hash verification, SBOM for supplied software | NIST SP 800-171 |
| SI.L2-3.14.6 | Monitor organizational information systems, including traffic and communications, for attacks and indicators of potential attacks. | Network monitoring, intrusion detection, threat intelligence feeds | NIST SP 800-171 |
| SI.L2-3.14.7 | Identify unauthorized use of organizational information systems. | User behavior analytics, anomaly detection, security monitoring | NIST SP 800-171 |
| # | Requirement | Evidence / Artifact | Ref |
|---|---|---|---|
| L3.AC.3.001 | Implement advanced access controls including security policy enforcement mechanisms, metadata completeness checks, and cross-domain solutions for CUI flows. | Cross-domain solution (CDS) implementation, metadata tagging for CUI, data loss prevention architecture | NIST SP 800-172 |
| L3.AC.3.002 | Implement cryptographic protection using NIST-approved cryptography in all organizational systems and communications where CUI is stored, processed, or transmitted. | FIPS 140-2 Level 2+ validated crypto modules, HSM key management | NIST SP 800-172 |
| L3.AT.3.001 | Implement advanced cybersecurity workforce development including threat-hunting, incident response, and adversarial tactics training aligned to current threat intelligence. | Adversary simulation exercises, threat-hunting curriculum, CTF participation records | NIST SP 800-172 |
| L3.SC.3.001 | Implement advanced boundary protection including specialized malware analysis, dynamic analysis, and behavioral analytics at system entry and exit points. | Sandboxing solutions, malware detonation chambers, behavior-based intrusion prevention | NIST SP 800-172 |
| L3.IR.3.001 | Develop advanced cyber incident response plan aligned to DoD Cyber Crime Center (DC3) reporting requirements and sector-specific threat intelligence. | IR plan with DC3 contacts, threat-intelligence-driven playbooks, sector-specific CTI | NIST SP 800-172 |
| L3.SI.3.001 | Implement advanced system integrity monitoring including host-based intrusion detection, file integrity monitoring, and behavioral analytics to detect sophisticated APT activity. | HIDS/HIPS deployment, FIM configuration, UEBA platform, YARA rule sets | NIST SP 800-172 |
| L3.RA.3.001 | Conduct threat-hunting activities based on cyber threat intelligence to proactively identify indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs). | Threat-hunting reports, MITRE ATT&CK mapping, IOC indicator database | NIST SP 800-172 |
| L3.AU.3.001 | Implement advanced audit capabilities including automated audit log synthesis, correlation, and real-time alerting for anomalous activity consistent with APT indicators. | SIEM with advanced correlation rules, real-time alerting, audit trail preservation | NIST SP 800-172 |
| L3.IA.3.001 | Implement phishing-resistant MFA (PIV/CAC or FIDO2) for all access to CUI systems, with continuous re-authentication risk assessment. | PIV/CAC deployment, FIDO2 authenticators, continuous authentication risk scoring | NIST SP 800-172 |