The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · Maintenance controls, maintenance evidence, and MSP scope

CMMC Maintenance Requirements: 6 Controls, 10 Objectives, 18 Points

Last updated:

Last verified: against 32 CFR Part 170, NIST SP 800-171 Revision 2, NIST SP 800-171A, NIST SP 800-88 Revision 2, DFARS, the CMMC Assessment Guide, The Cyber AB, and DOJ materials.

The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Primary sources last verified: August 20, 2026

Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a CMMC Registered Practitioner (RP) or another qualified advisor before acting.

Status note — verified August 20, 2026. On July 13, 2026, the Department of War suspended the transition to CMMC Phase II. During the suspension, requiring activities may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC). Phase I remains in effect. CMMC Level 2 still maps to all 110 requirements in NIST SP 800-171 Revision 2, including all six Maintenance requirements. The six requirements and their scoring treatment did not change. More on what the suspension changed →


CMMC maintenance requirements are the six Maintenance (MA) controls inside CMMC Level 2 — MA.L2-3.7.1 through MA.L2-3.7.6, taken directly from NIST SP 800-171 Revision 2. They break into 10 assessment objectives and create 18 possible point deductions from the 110-point maximum. Four of the six cannot be deferred to a Plan of Action and Milestones (POA&M): 3.7.1 (3 points), 3.7.2 (5 points), 3.7.4 (3 points), and 3.7.5 (5 points). Only the two 1-point requirements — 3.7.3 and 3.7.6 — are eligible for a Level 2 POA&M, assuming the assessment meets the rule's other POA&M conditions.

Now here's the part that surprises people, and it's the reason this family fails assessments that everything else survives.

In the contractor-MSP model, four of those six controls often depend on work or records controlled by someone who doesn't work for you. The technician who remotes in. The vendor who plugs in a diagnostic drive. The depot that repairs your laptop. Both 5-point requirements in this family can live inside that relationship — and 16 of the family's 18 possible deductions can't go on a POA&M.

We read 32 CFR Part 170 at the eCFR on August 20, 2026 to pull every point value in this article directly from the regulation rather than from a secondary summary. The rest of this page turns those six requirements into something you can actually operate: what triggers each one, what an assessor examines, what evidence should exist afterward, and who owns it when your managed service provider is holding half the answer.

The Maintenance family at a glance

Control — What it covers — Objectives — Points — Level 2 POA&M-eligible?
ControlWhat it coversObjectivesPointsLevel 2 POA&M-eligible?
MA.L2-3.7.1Performing maintenance on your systems13No
MA.L2-3.7.2Controlling maintenance tools, techniques, mechanisms, and personnel45No
MA.L2-3.7.3Sanitizing CUI from equipment before off-site maintenance11Yes
MA.L2-3.7.4Checking diagnostic and test media for malicious code13No
MA.L2-3.7.5MFA for nonlocal maintenance and terminating the connection25No
MA.L2-3.7.6Supervising maintainers without required access authorization11Yes
TotalSix requirements1018Two

Point values: 32 CFR 170.24(c)(2)(i)(B), read in full August 20, 2026. POA&M eligibility: 32 CFR 170.21(a)(2).

Jump to a requirement: 3.7.1 Perform Maintenance · 3.7.2 System Maintenance Control · 3.7.3 Equipment Sanitization · 3.7.4 Media Inspection · 3.7.5 Nonlocal Maintenance · 3.7.6 Maintenance Personnel


Are you on the right page?

This page covers the six Maintenance (MA) controls — the security requirements about servicing systems, remote support sessions, equipment repair, and maintenance personnel.

Looking for something else? If you searched "maintenance" meaning how do I keep my CMMC status alive — annual affirmations, the three-year reassessment cycle, POA&M closeout deadlines, what happens after you achieve a status — that's a different subject with different rules. Start with our CMMC Level 2 checklist, which covers the assess-every-three-years, affirm-every-year cadence.

Who this page is for

  • Level 2 contractors implementing NIST SP 800-171 Revision 2
  • IT directors, CISOs, and compliance managers preparing for a Level 2 self-assessment
  • Managed service provider and MSSP teams performing maintenance for Defense Industrial Base (DIB) clients
  • Registered Practitioners (RPs) and implementation consultants building an evidence system
  • Anyone who just got asked for "maintenance records" and realized patch reports aren't going to cover it

Who should read something else instead

We'd rather lose you to the right page than keep you on the wrong one.


The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation for regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with The Cyber AB, the Department of War (formerly the Department of Defense), DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP), a Registered Provider Organization (RPO), or a qualified federal-contracts attorney.

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation, contract, or flow-down states the required status and assessment type; the requiring activity sets prime-contract requirements, and the prime or next-higher-tier contractor sets subcontract requirements. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


What are the six CMMC maintenance requirements?

Answer capsule. CMMC Level 2 contains six Maintenance requirements: perform maintenance (MA.L2-3.7.1), control maintenance tools, techniques, mechanisms, and personnel (3.7.2), sanitize CUI from equipment before off-site maintenance (3.7.3), check diagnostic and test media for malicious code (3.7.4), require multifactor authentication for nonlocal maintenance and terminate the connection when finished (3.7.5), and supervise maintenance personnel without required access authorization (3.7.6). Together they contain 10 assessment objectives and create 18 possible deductions from the 110-point maximum in the CMMC Level 2 scoring methodology.

Level 2's requirements come straight from NIST SP 800-171 Revision 2. That mapping is stated in the program rule itself: 32 CFR 170.14(c)(3) says the CMMC Level 2 security requirements are identical to NIST SP 800-171 Rev. 2. Maintenance is section 3.7 of that publication — one of the 14 control families.

Here is the full family with our plain-language labels, the Basic/Derived split NIST uses, the point value the regulation assigns, and whether the requirement can be deferred.

ID — What it requires, in plain terms — Basic or Derived — Points — Level 2 POA&M — Who usually performs the work
IDWhat it requires, in plain termsBasic or DerivedPointsLevel 2 POA&MWho usually performs the work
MA.L2-3.7.1Actually perform maintenance on the systems in your assessment scopeBasic3NoInternal IT or your MSP
MA.L2-3.7.2Control the tools, techniques, mechanisms, and people involved in maintenanceBasic5NoWhoever grants access — often the contractor and MSP together
MA.L2-3.7.3Sanitize CUI from equipment before it leaves for off-site maintenanceDerived1YesIT plus facilities or shipping
MA.L2-3.7.4Check diagnostic and test media for malicious code before useDerived3NoInternal IT or the visiting technician under your process
MA.L2-3.7.5Require MFA to establish nonlocal maintenance sessions and terminate the connection when doneDerived5NoYour internal IT, MSP, or remote support vendor
MA.L2-3.7.6Supervise maintenance personnel who lack required access authorizationDerived1YesWhoever escorts or monitors them

These are our plain-language labels, not the official requirement text. For exact wording, read NIST SP 800-171 Revision 2 section 3.7 directly. Point values: 32 CFR 170.24(c)(2)(i)(B). Basic/Derived designations: NIST SP 800-171 Rev. 2.

The arithmetic that changes your priorities

Run the numbers and the family reorganizes itself.

  • 6 requirements. 10 assessment objectives. 18 possible point deductions.
  • 16 of those 18 points — four of the six requirements — cannot go on a POA&M.
  • Only 2 points across 2 requirements are potentially deferrable.
  • Maintenance is 5.5% of the 110 requirements but holds 2 of the 42 five-point requirements in the entire Level 2 control set.
  • The 88-point Conditional threshold creates up to 22 points of score headroom, but POA&M eligibility is narrower than that. Maintenance can account for at most 2 of those open points.

That last point deserves a second read. Under 32 CFR 170.21(a)(2), you reach Conditional Level 2 status only if your score divided by 110 is at least 0.8 — a score of 88. Most requirements worth more than 1 point cannot appear on the POA&M, six named 1-point requirements are also barred, and SC.L2-3.13.11 has one narrow FIPS-validation exception. None of those exceptions changes the Maintenance result: only 3.7.3 and 3.7.6 are eligible, so this family gives you almost none of that headroom.

Why the regulation weights them this way

The scoring tiers aren't arbitrary, and the regulation explains its own logic. Under 32 CFR 170.24(c)(2)(i)(B), a requirement is worth 5 points when failing to implement it "could lead to significant exploitation of the network, or exfiltration of CUI." It's worth 3 points when the failure has a "specific and confined effect." Everything else derived is 1 point.

So the government's own position is that an uncontrolled maintenance technician (3.7.2) and an unauthenticated remote maintenance session (3.7.5) sit in the same risk tier as boundary protection and access control. That's a useful thing to quote when someone in your organization wants to treat Maintenance as a paperwork family.

Two cautions before you go further

"POA&M-eligible" does not mean "optional." An eligible POA&M can support a Conditional status only when the rule's other conditions are met, and it carries a hard 180-day closeout clock under 32 CFR 170.21(b). Miss the closeout and the Conditional status expires. It is a limited-duration bridge, not permission to leave a requirement unresolved.

Three-point Maintenance requirements can't be deferred either. The claim that only 5-point requirements must be fully implemented is wrong for this family. Under 32 CFR 170.21(a)(2)(ii), the narrow SC.L2-3.13.11 FIPS exception does not apply to Maintenance. That means 3.7.1 and 3.7.4 must be MET before you can hold Conditional Level 2 status. If you planned around them, replan.

One related error pattern is worth knowing about. Seventeen families belongs to NIST SP 800-171 Revision 3. CMMC Level 2 currently runs on Revision 2, which has 14 families and 110 requirements. NIST has published Revision 3 and marked Revision 2 as superseded in its catalog — but NIST publishes, and DoD regulates. Until 32 CFR Part 170 is amended, Revision 2 is what CMMC Level 2 assesses. Don't let a Revision 3 family count wander into your gap analysis.


The uncomfortable part

In a contractor-MSP model, four of these six controls often depend on things your IT provider does or records — and you're the one scored on them. If your managed service provider can't produce a record showing that a remote session used multifactor authentication and was closed afterward, you can't fix that with a policy you write this afternoon. That gap lives in someone else's ticketing system, governed by someone else's contract.

Here's why that's better news than it sounds. Maintenance is usually a workflow and contract problem, not a six-figure engineering problem. You may not need new infrastructure to close this family. You need a defined process, assigned owners, direct provider questions, and a trace after each maintenance event. Maintenance can close faster than other high-point families once you stop looking only in your own systems and start looking in your vendor's.


Which maintenance controls does your situation trigger?

Answer capsule. The CMMC Maintenance family is easiest to implement as an event-driven workflow. A remote support session, an off-site equipment repair, the use of vendor diagnostic media, and work performed by a technician without required access authorization can each bring a different combination of the six MA requirements into play. Identifying the event first is more reliable than working down the list of six controls in order.

This is the reframe that makes the family manageable. Reading 3.7.1 through 3.7.6 as an isolated checklist encourages a generic "maintenance program." Start with the event instead.

The event — Controls in play — The thing people miss
The eventControls in playThe thing people miss
Your MSP remotes in to fix a server3.7.1, 3.7.2, 3.7.5, and 3.7.6 if the technician lacks required authorizationNobody can show the session was terminated
A laptop with CUI ships to the manufacturer for repair3.7.1, 3.7.2, 3.7.3, and 3.7.6 if the repair personnel lack required authorizationEncryption gets treated as a substitute for sanitization
A vendor technician arrives with a diagnostic USB drive3.7.1, 3.7.2, 3.7.4, and 3.7.6 if the technician lacks required authorizationTrusted-vendor media skips the malicious-code check
An authorized internal admin does local maintenance3.7.1, 3.7.2, and 3.7.4 if diagnostic media is usedThe work happens but leaves no traceable record
You patch a fleet of workstationsSupports 3.7.1; 3.7.2 applies to the deployment tooling and personnelThe team assumes this covers the whole family

This trigger map is our framework, built from the requirement text in NIST SP 800-171 Rev. 2 and the assessment structure in NIST SP 800-171A. It is editorial organization applied to verified requirements, not a mapping published by DoD or NIST. Use it to scope your workflow; confirm applicability against your own environment.

▶ Put your highest-risk event on paper now

Pick the most complicated maintenance event from the last 90 days. Mark whether it was local or nonlocal, whether an external network was used, whether equipment left your control, whether CUI could be retained, whether diagnostic media was introduced, whether a third party was involved, and whether the technician held the required access authorization. The trigger table above tells you which MA requirements to trace.

Then use the CMMC Level 2 readiness checklist to place that event inside the rest of your Level 2 evidence system. Do not enter or send CUI, system names, IP addresses, credentials, or contract details.


MA.L2-3.7.1: What does "perform maintenance" actually require?

Answer capsule. MA.L2-3.7.1 requires an organization to perform maintenance on the systems within its CMMC assessment scope. It carries 3 points and cannot be placed on a POA&M. Patching supports this requirement but does not satisfy it by itself. The DoD CMMC Assessment Guide – Level 2 describes corrective, preventive, adaptive, and perfective maintenance, while NIST SP 800-171 Revision 2 applies maintenance across hardware, firmware, and software — not software updates alone.

[Regulatory requirement] Perform maintenance on organizational systems.

That's it. One sentence, one assessment objective, three points. Which is exactly why it gets skipped.

What counts as maintenance

Broader than most teams assume:

  • Corrective — fixing something that broke
  • Preventive — scheduled work to stop something from breaking
  • Adaptive — changes to keep a system working in a changed environment
  • Perfective — improvements to performance or maintainability
  • Hardware servicing, component replacement, firmware updates
  • Software and configuration maintenance
  • Work performed by outside vendors on your behalf

The minimum defensible process

[Editorial best practice] You need a repeatable path from "something needs work" to "we can show what happened":

  1. The need is identified
  2. The work is authorized
  3. The work is scheduled or initiated
  4. The work is performed
  5. The result is validated
  6. The event is closed and recorded

If you cannot walk an assessor through those six steps for a real recent event, you do not yet have strong evidence for 3.7.1 — you have a maintenance habit.

What an assessor will do

NIST SP 800-171A — incorporated into the CMMC program at 32 CFR 170.14(d), and the version the rule points to is the June 2018 edition — uses three assessment methods: examine, interview, and test. For 3.7.1, the official DoD Level 2 Assessment Guide lists maintenance policies, procedures, records, system documentation, responsible personnel, and maintenance processes as potential assessment objects. Tracing one completed event end to end is our practical way to test whether those pieces connect.

[Common evidence] Maintenance policy and procedure · maintenance schedule · completed tickets · vendor service records · asset maintenance history · post-maintenance validation results · the description of the process in your System Security Plan (SSP).

How it fails

"We patch every month." Then the assessor asks to see the record of the firewall firmware update from March, and the answer is a Slack thread.

The assessment problem in this example is not that the work never happened. It's that the work cannot be traced.

Related: for how patching, flaw remediation, and vulnerability scanning are handled separately in the control set, see the NIST 800-171 requirements checklist.


MA.L2-3.7.2: How do you control maintenance tools, techniques, mechanisms, and personnel?

Answer capsule. MA.L2-3.7.2 requires control over four distinct elements: the tools used for maintenance, the techniques applied, the mechanisms that enable it, and the personnel who perform it. It contains four assessment objectives and carries 5 points, the highest weight in the Maintenance family alongside MA.L2-3.7.5. Because a requirement is scored MET only when every applicable objective is satisfied, controlling personnel while leaving vendor tools unmanaged still produces a NOT MET finding.

This is the requirement that quietly decides your Maintenance score, and the reason is structural.

Four nouns, four objectives

[Assessment objective] Most summaries collapse this into "approve your tools and people." The requirement text has four separate elements, and NIST SP 800-171A treats each as its own objective:

  1. Maintenance tools are controlled
  2. Maintenance techniques are controlled
  3. Maintenance mechanisms are controlled
  4. Maintenance personnel are controlled

Miss one, lose all five points. There is no partial credit here. The CMMC scoring methodology at 32 CFR 170.24(a) allows partial implementation credit "only in limited cases," and the regulation names exactly two requirements that get it: multifactor authentication (IA.L2-3.5.3) and FIPS-validated cryptography (SC.L2-3.13.11). Neither is in this family. Maintenance is all-or-nothing, requirement by requirement.

What "tools" can include

USB media · bootable diagnostic media · vendor utilities · firmware flashing tools · remote support agents · remote monitoring and management (RMM) platforms · hardware diagnostic devices · privileged scripts and administrative tooling.

What "techniques and mechanisms" can include

Remote versus local servicing · the privileged access method used · temporary account issuance · defined maintenance windows · isolation or staging environments · approved transfer processes · the connection method itself · how tools enter and leave your environment.

What personnel control means in practice

[Editorial best practice] Define, and be able to show:

  • Who may request maintenance
  • Who may approve it
  • Who may perform it
  • What authorization is required for which systems
  • How external personnel are identified and verified
  • When supervision is triggered (that's 3.7.6, and the two work together)
  • How temporary access is removed when the work ends

A five-minute self-test

Pick one maintenance event from the last 90 days. Without reconstructing it from memory, can you name the tool used, the method, the person, the approval, the affected system, and the closure record?

If four of those six answers require you to email your MSP, you've found your gap — and you've also found where your evidence lives.


MA.L2-3.7.3: What has to happen before equipment leaves for off-site maintenance?

Answer capsule. MA.L2-3.7.3 requires that equipment removed for off-site maintenance be sanitized of any Controlled Unclassified Information before it leaves. It carries 1 point and is one of only two Maintenance requirements eligible for a POA&M. Encryption is a meaningful safeguard but does not by itself demonstrate that CUI was removed, and the requirement is framed around sanitization rather than encryption.

Low points. Routine business event. This one is easy for small manufacturers to miss because equipment leaving the building is rarely treated as a compliance event.

What equipment can trigger it

Laptops · workstations · servers · storage devices and drives · network appliances · multifunction printers and copiers · industrial or operational technology components · anything else capable of retaining CUI. The multifunction printer is the one that gets forgotten — many models contain internal storage, and leased units eventually leave your control.

The decision path

[Editorial best practice] Before any device leaves an organization-controlled location:

  1. Does this equipment contain or potentially retain CUI?
  2. Can the CUI-bearing media be removed and retained instead?
  3. Can the repair happen inside a controlled environment instead?
  4. If it must leave, can the CUI be sanitized using an appropriate method?
  5. Can the sanitization result be verified and recorded?
  6. Who approves the release?
  7. What gets checked when it comes back?

The shortcut that fails

"The drive was encrypted, so we shipped it."

[Regulatory requirement] The requirement addresses sanitizing CUI from equipment removed for off-site maintenance. Encryption may reduce risk substantially and may matter for other requirements in the control set, but presenting encryption alone as satisfying 3.7.3 does not meet the requirement on its face. If encryption is part of your control strategy here, document the reasoning — and still show how CUI was sanitized before the equipment left.

[Editorial best practice] For sanitization method selection, NIST SP 800-88 Revision 2 is the current NIST media-sanitization guidance as of August 20, 2026; NIST published it in September 2025. The appropriate method depends on media type, sensitivity, reuse plans, and how you verify the result — so we're not going to publish one method and call it compliant.

[Common evidence] Asset identifier · reason for removal · the CUI determination · sanitization method and verification · who performed and who verified · date and time · destination and custody · release approval · post-return validation.


MA.L2-3.7.4: How must diagnostic and test media be checked?

Answer capsule. MA.L2-3.7.4 requires that media containing diagnostic and test programs be checked for malicious code before being used on an organizational system. It carries 3 points and cannot be placed on a POA&M. The requirement applies regardless of the vendor's reputation; treating trust as a substitute for the pre-use check is the failure pattern to eliminate.

Three points for a pre-use malicious-code check. That's the whole control, and it's worth more than either of the two 1-pointers combined.

What can count as diagnostic or test media

USB drives · bootable media · portable drives · firmware packages · diagnostic images · vendor-downloaded tools · test utilities · recovery media.

We say "can include" deliberately. Whether a cloud-delivered diagnostic package counts as "media" in your environment depends on how you've defined and controlled your process. [Editorial best practice] The defensible position is to bring vendor-supplied diagnostic software inside your intake process regardless of delivery method, rather than arguing about the definition of media during an assessment.

When the check happens

Before the media or package is used on the affected system. Not after. Not "we scan everything nightly."

[Common evidence] Source of the media · file or media identifier · date obtained · the scanning mechanism used · date and result of the check · the technician involved · the affected system · any approval or exception · and what happened if something was found.

How it fails

The vendor is a household name, so the technician's drive goes straight into the server. Or: the company has enterprise antivirus deployed everywhere and assumes that covers it — but cannot show that this specific medium was checked before use.

If malicious code is found, that event connects to your malicious code protection and incident handling requirements. Have that handoff defined before you need it.


MA.L2-3.7.5: What are the CMMC requirements for remote and nonlocal maintenance?

Answer capsule. MA.L2-3.7.5 requires multifactor authentication to establish nonlocal maintenance sessions through external network connections, and termination of those connections when the maintenance is complete. It contains two assessment objectives, carries 5 points, and cannot be placed on a POA&M. Multifactor authentication protecting one component of the environment does not satisfy the requirement if the actual maintenance path is not the authenticated path.

If you fix one control on this page, fix this one. It is one of the family's two 5-point requirements, and it sits directly on top of the relationship most contractors have with their IT provider.

We are not publishing a failure-rate percentage for 3.7.5. The structural risk is enough: the requirement has two objectives, while an MFA record by itself says nothing about whether the connection was terminated.

Nonlocal maintenance, defined

[Regulatory requirement] Nonlocal maintenance is maintenance conducted by individuals communicating through an external network connection. In practice that can include:

  • RMM sessions from your managed service provider
  • VPN-based administrative access
  • Remote desktop and remote shell sessions
  • Cloud management consoles used to maintain an in-scope resource
  • Vendor support tunnels
  • Out-of-band management interfaces

The two objectives, and why the second one fails

[Assessment objective]

  1. Multifactor authentication is used to establish the nonlocal maintenance session through an external network connection.
  2. The connection is terminated when the maintenance is complete.

Many organizations can demonstrate the first. The second is where evidence disappears — because "the technician stopped typing" is not the same as "the connection was closed and we can show it."

Map the authentication path, not the login screen

Draw the actual chain:

Technician identity → authentication system → remote access gateway or support platform → maintenance session → in-scope system

Then answer one question: does the MFA event actually gate the establishment of the maintenance connection, or does it gate something adjacent?

The MSP's own portal may require MFA. That can satisfy the first objective if the portal's MFA actually gates each nonlocal maintenance session to your in-scope system. It does not satisfy the objective if a technician can bypass that MFA, reuse an already-open connection, or reach the maintenance path through a persistent access channel that is not gated by the demonstrated MFA event. Your screenshot can be real and still prove the wrong path.

Is encryption required by 3.7.5?

[Regulatory requirement] No — not by the text of this requirement. MA.L2-3.7.5 addresses multifactor authentication and connection termination. Cryptographic protection of remote sessions, authorization of remote access, monitoring, and privileged command control are addressed by adjacent requirements in the Access Control and Identification and Authentication families. Those may well apply to your remote maintenance architecture. But we see them quoted as though they were extra words inside 3.7.5, and that imprecision makes it harder for you to scope the control correctly.

Get the requirement right, then handle the adjacent controls as adjacent controls.

What "terminate the connection" should produce

[Editorial best practice] Depending on your design, closure evidence might include a session logoff, a disconnected tunnel, or a support-platform record showing the active session ended. Disabling a temporary account, expiring a token, closing a ticket, or removing an agent can support the record only when that action also terminates the active maintenance connection. What matters is that a start time, an end time, and a retrievable termination event exist.

There is no universal session timeout in this requirement. Don't let a vendor tell you there is, and don't invent one for your SSP.

Can an MSP keep persistent, unattended access?

This is the question contractors ask when a vendor wants unattended access, repeatedly, over a period of weeks: what do we actually have to show?

[Editorial judgment] Separate the installed agent from the active connection. MA.L2-3.7.5 does not prohibit a support agent from remaining installed, but each nonlocal maintenance session through an external network must be established with MFA and the connection must be terminated when maintenance is complete. An always-open maintenance connection is difficult to reconcile with that text. Just-in-time access is one common design; a persistent agent with per-session MFA, authorization, logging, and termination is another. Neither works by accident.

Related: CMMC MFA requirements across the control set · CMMC MSP guide


MA.L2-3.7.6: When must maintenance personnel be supervised?

Answer capsule. MA.L2-3.7.6 requires supervision of maintenance personnel who do not possess the required access authorization for the system being maintained. It carries 1 point and is POA&M-eligible. The trigger is the individual's authorization status for that specific system and information — not their employer, their contract, their vendor's certifications, or a signed nondisclosure agreement.

One point. And still the control that exposes how loosely a contractor has defined "authorized."

What "required access authorization" means

[Regulatory requirement] The organization defines the authorization appropriate to the system, the information, and the maintenance task. Then it applies it consistently.

[Editorial judgment] What it is not — and we see all five of these treated as equivalents:

  • Employment status
  • A security clearance by itself
  • Vendor trust or a long relationship
  • A signed NDA
  • The provider's own CMMC status or Cyber AB Marketplace listing

Any of those may be relevant inputs. None of them is the determination.

What supervision can look like

[Editorial best practice] Supervision can include an in-person escort, an attended remote session, direct observation, activity monitoring, or pairing the technician with an authorized employee. A restricted temporary account and a constrained maintenance environment can support that supervision, but they are not substitutes for supervising the maintenance activity when 3.7.6 is triggered.

We are deliberately not telling you that every compliant implementation requires full keystroke logging or continuous video. It doesn't. The requirement is supervision of the activity, and how you achieve it is an architecture decision you have to be able to explain.

Temporary accounts

Short-lived, purpose-built accounts are one common implementation path, and the official DoD Level 2 Assessment Guide recognizes temporary credentials for one-time use or very limited periods. [Editorial best practice] If you use them, you still owe authorization, privilege limits, duration limits, supervision when required, and a termination record. A temporary account that never gets disabled creates a second, documented access-control gap.

How it fails

"Our MSP handles that."

And then neither party can show who determined the technician's authorization, who supervised the session, or how access ended. Which brings us to the section that resolves this for good.


Does patch management satisfy the CMMC Maintenance family?

Answer capsule. No. Installing patches supports MA.L2-3.7.1, but patching by itself does not satisfy the six-requirement Maintenance family. A controlled patch-management process may also produce evidence for MA.L2-3.7.2 and, when it establishes a nonlocal maintenance session through an external network, MA.L2-3.7.5. It still does not by itself resolve off-site equipment sanitization, diagnostic media, or supervision. Flaw remediation and vulnerability scanning are addressed separately in other NIST SP 800-171 families.

This assumption can leave up to 15 possible deductions exposed, so it gets its own section.

What you're doing — Maintenance connection — Why it isn't the whole answer
What you're doingMaintenance connectionWhy it isn't the whole answer
Operating system patchingSupports 3.7.1Says nothing about off-site repair, diagnostic media, nonlocal sessions, or unauthorized technicians
Vulnerability scanningMay identify maintenance needsIdentifying work is not performing it and proves no event controls
Firmware updates3.7.1, 3.7.2, possibly 3.7.4Tools, personnel, media, and validation still apply
Remote patch deployment3.7.1, 3.7.2, and 3.7.5 if it establishes a nonlocal maintenance session through an external networkThe path may need MFA and termination evidence
OEM hardware repair3.7.1 through 3.7.3, and 3.7.6 if personnel lack required authorizationEquipment movement, CUI sanitization, and technician authorization all engage

The math version: patching can support the 3-point 3.7.1 requirement. By itself, it does not establish the other 15 possible deductions, 13 of which cannot be deferred to a POA&M.

If your gap analysis currently shows Maintenance as "mostly covered — we patch," it may be understating the family's exposure by as much as 15 points.


What evidence will a CMMC assessor examine, interview, and test?

Answer capsule. CMMC assessments use three methods drawn from NIST SP 800-171A: examining artifacts, interviewing personnel, and testing implementations. Under 32 CFR 170.24(b)(1), a requirement is scored MET only when all applicable objectives are satisfied by evidence in final form — the regulation explicitly excludes working papers, drafts, and unofficial or unapproved policies as acceptable evidence.

That sentence in the regulation is the most useful thing on this page for anyone building an evidence system, and it deserves to be quoted directly.

[Regulatory requirement] 32 CFR 170.24(b)(1) defines MET as all applicable objectives satisfied based on evidence, and states that all evidence must be in final form and not draft. It then names what doesn't count: working papers, drafts, and unofficial or unapproved policies.

So the draft maintenance policy sitting in review since April is not evidence. The procedure your consultant wrote but your organization never approved under its own process is not evidence. This is a low bar, and it still fails on assessment day.

The Maintenance Requirement-to-Evidence Matrix

Our evidence map, built from the requirement text and the examine/interview/test structure. [Editorial best practice] — this is a map of what commonly demonstrates each objective, not a list of artifacts DoD requires by name.

Requirement — Records that commonly demonstrate it — Likely interview subjects — What a test looks like — The usual failure
RequirementRecords that commonly demonstrate itLikely interview subjectsWhat a test looks likeThe usual failure
3.7.1Maintenance policy and procedure; schedule; completed tickets; vendor service records; asset history; SSP descriptionIT administrator; system owner; maintenance leadPick an in-scope asset and trace one completed event request-to-closureWork happens informally and cannot be traced
3.7.2Approved tool inventory; tool-control procedure; personnel authorization list; maintenance contracts; tool-intake recordsSystem administrator; security lead; vendor managerShow how a tool or technician gets approved, controlled, monitored, and removedVendor tools and privileged maintainers are uncontrolled
3.7.3Asset ticket; CUI determination; sanitization record and verification; custody record; release approval; return validationAsset custodian; IT lead; security officerWalk the decision used before equipment leavesEncryption substituted for sanitization
3.7.4Scan logs; media-intake record; approved-media list; utility-source record; incident ticket if malware is foundSecurity administrator; technician; help deskIntroduce a test medium and show the pre-use checkTrusted vendor media is exempted
3.7.5MFA configuration on the maintenance path; remote-access approval; session logs with start and end times; termination evidenceNetwork administrator; MSP contact; system ownerEstablish a session, authenticate, complete work, and show terminationMFA exists somewhere; termination cannot be shown
3.7.6Authorization definition; technician identity and employer; authorization determination; temporary-access record; supervision log; session recordSecurity officer; system owner; supervising technicianShow how a technician without required authorization is identified and supervision is invoked"The vendor is trusted" is treated as authorization

The one event trace your evidence system should support

[Editorial best practice] Pick your most complex recent maintenance event and confirm you can walk it:

  1. Need identified → 2. Work authorized → 3. Personnel and tools verified → 4. Access provisioned → 5. Diagnostic media checked → 6. CUI sanitized if equipment left → 7. Remote session authenticated if applicable → 8. Work performed → 9. Connection or temporary access terminated → 10. Result validated → 11. Evidence retained

If that trace holds for your hardest event, you have a defensible structure for the easier ones.

One more thing about retention

[Regulatory requirement] The artifacts used as evidence for a CMMC assessment must be retained for six years from the CMMC Status Date — 32 CFR 170.16(c)(4) for the self-assessment path, 170.17(c)(4) for the certification path.

There is a material difference between the two paths. On the certification path, 170.17(c)(4) additionally requires that the artifacts be hashed using a NIST-approved hashing algorithm, with the artifact names, hash values, and algorithm provided to the C3PAO (CMMC Third-Party Assessment Organization — the authorized firm that performs Level 2 certification assessments) for upload into the CMMC instance of eMASS. The self-assessment path at 170.16(c)(4) requires retention but does not impose the hashing step.

If you are on the certification path, retain the hashed artifacts and the corresponding artifact names, hash values, and algorithm so integrity can be checked throughout the six-year retention period. Design the repository accordingly before six years of records accumulate in a shared drive.

▶ Build the evidence system around what the rule actually requires

The CMMC Level 2 documentation checklist separates documents named by the requirements from common supporting evidence, including the SSP, POA&M, scope records, final policies, tickets, logs, and provider responsibility records.

Use it to build your Maintenance folder without pretending the government mandates a named template pack.

Open the CMMC Level 2 documentation checklist →


How do MSPs, MSSPs, and repair vendors change your Maintenance scope?

Answer capsule. A maintenance vendor is an External Service Provider (ESP) for CMMC only when CUI or Security Protection Data is processed, stored, or transmitted on the provider's assets. An ESP does not automatically need its own CMMC status simply because it performs maintenance. Under 32 CFR 170.19(c)(2), a non-cloud ESP that handles CUI is assessed as part of the organization's assessment, while an ESP that handles Security Protection Data without CUI is assessed as a Security Protection Asset against the requirements relevant to the capabilities it provides. The relationship, services, service description, and Customer Responsibility Matrix belong in the SSP.

Read that last clause again, because it is the whole ballgame when the provider is an in-scope ESP: the applicable provider services are assessed inside your assessment scope. CUI-handling services are assessed as part of the organization's assessment; SPD-only services are assessed as Security Protection Assets. Neither is erased by a marketing claim or satisfied by a Marketplace badge.

Stack that against the ownership column from our first table — in an outsourced IT model, four of six MA requirements, including both 5-pointers, often depend on an outside technician or the provider's records — and the conclusion is unavoidable. When those services are in scope, your provider's implementation is part of your result, and 16 of the family's 18 possible deductions cannot be deferred if the evidence or implementation fails.

That is not a reason to panic. It's a reason to have one specific conversation.

Who owns what

[DCR responsibility map] This table allocates practical ownership; it is not a regulatory responsibility matrix published by DoD. Your actual division of work belongs in the SSP and CRM.

Responsibility — Contractor — Provider — Must be written down?
ResponsibilityContractorProviderMust be written down?
Approve maintenanceUsuallySometimes delegatedYes
Approve tools and methodsYesMay propose or operateYes
Verify technician authorizationYesSupplies the personnel factsYes
Configure MFA on the maintenance pathEitherEitherYes
Terminate the nonlocal maintenance connectionEitherEitherYes
Sanitize equipment before shipmentUsuallyMay assistYes
Check vendor media and toolsEitherEitherYes
Retain assessment evidenceAccountability stays with the contractorMay generate or store recordsYes
Supervise personnel without required authorizationYesMay participateYes
Keep the SSP and responsibility matrix accurateAccountability stays with the contractorSupplies service detailsYes

Two rows are bolded on purpose. A provider can generate or store the record, but accountability for retaining assessment evidence and keeping the SSP accurate stays with the contractor. You are the one who has to produce it.

The twelve questions to ask your provider

[Editorial best practice] Send these and ask for written answers. A focused provider response can expose the operational and evidence gaps that another round of policy writing will not:

  1. How are your maintenance technicians uniquely identified in our environment?
  2. What authorization does each technician hold, and who determined it?
  3. Where exactly is MFA enforced on the path that establishes a maintenance session to our systems?
  4. What record proves a session ended?
  5. Can you produce session-level logs with start and end times, on request, for the past 12 months?
  6. Who approves new maintenance tools or agents before they're installed?
  7. How are diagnostic packages checked for malicious code before use in our environment?
  8. Do you process, store, or transmit our CUI, or Security Protection Data related to our environment?
  9. Which party retains the evidence for each maintenance control, and for how long?
  10. How is persistent or unattended access governed and reviewed?
  11. How are personnel changes on our account communicated to us?
  12. What is your process when our equipment must leave our facility for repair?

[DCR decision rule] If your provider can answer all twelve in writing and produce the referenced records, you likely have a documentation exercise ahead of you. If four or more answers are missing, you have a provider-scope or provider-category decision to make.

What we will not tell you

The Cyber AB's CMMC Assessment Process (CAP) governs how a Level 2 certification assessment is conducted. It does not turn a consultant, MSP, software vendor, or Marketplace listing into proof that your Maintenance requirements are MET — and during the Phase II suspension, new Level 2 (C3PAO) procurement designations are paused.

[Editorial judgment] Because we see all five of these claimed, and none of them is supportable:

  • That every MSP performing maintenance must be a C3PAO. It must not — and under the CMMC program rule, an ecosystem member that consulted to prepare an organization for a CMMC assessment within the previous three years cannot participate in that organization's Level 2 certification assessment.
  • That every MSP must hold its own Level 2 status merely because it touches your systems.
  • That a provider's Cyber AB Marketplace listing proves your MA implementation. A listing shows the ecosystem role and status displayed in the Marketplace when you check it; it does not prove your requirement implementation or your evidence.
  • That a compliant cloud platform or RMM tool makes your maintenance process compliant. Tools don't hold requirements. Processes do.
  • That software alone satisfies CMMC. A GRC (governance, risk, and compliance) platform organizes your evidence. It does not perform maintenance, authorize a technician, or terminate a session.

▶ Match the gap to the right category — not to a vendor list

Maintenance gaps split cleanly into four categories, and each one routes somewhere different:

  • Process and documentation gaps — no defined workflow, no SSP description, no authorization definition → an RPO or independent Registered Practitioner (RP)
  • Operational gaps — sessions, tooling, access control, termination evidence → MSP or MSSP (Managed Security Service Provider) territory
  • Evidence and workflow gaps — records exist but are scattered and unprovable → a GRC platform as a supporting layer, never as the whole answer
  • Scope gaps — CUI is in more places than your maintenance process covers → CUI enclave territory

We are not publishing provider rankings, endorsements, or "best of" awards on this page, and we're not naming vendors here — this is an implementation article, and forcing provider names into it would serve us rather than you. What we will do is route you to the right category before you start requesting quotes.

Compare CMMC provider categories → or map your situation with Find My CMMC Path →

Do not submit CUI, drawings, credentials, or sensitive contract details.


What happens if a maintenance control breaks between assessments?

Answer capsule. Under DFARS 252.204-7021, a CMMC status is only "current" if there have been no changes in compliance with 32 CFR Part 170 since the CMMC Status Date. However, 32 CFR 170.24(b)(1) provides two mechanisms that preserve a MET finding: enduring exceptions documented with mitigations in the System Security Plan, and temporary deficiencies addressed in operational plans of action — which the rule defines as distinct from a POA&M.

This is the question every IT director asks about ten minutes after they finish reading the six controls. Your MSP switches RMM platforms in month fourteen. Are you broken?

[Regulatory requirement] DFARS 252.204-7021 — the contract clause that carries CMMC into your contract, effective November 10, 2025 — defines "Current" to require, among other things, "no changes in compliance with the requirements at 32 CFR part 170" since your status date. The definition does not state a grace period for that condition.

But the program rule anticipated drift, and it gave you two instruments.

32 CFR 170.24(b)(1)(i): enduring exceptions, when described along with any mitigations in the SSP, are assessed as MET.

32 CFR 170.24(b)(1)(ii): temporary deficiencies that are appropriately addressed in operational plans of action — including deficiency reviews and demonstrated progress toward corrections — are assessed as MET.

An operational plan of action is not a POA&M

This distinction is written into the definitions at 32 CFR 170.4, and it gives you the right instrument once a temporary deficiency appears:

— CMMC POA&M — Operational plan of action
CMMC POA&MOperational plan of action
When it appliesAt assessmentAfter implementation, when a temporary vulnerability or temporary deficiency arises
Clock180 hard daysThe CMMC definition does not prescribe a remediation timeline
What can go on itOnly eligible assessment findings; 3- and 5-point items are generally barred, six named 1-point requirements are barred, and SC.L2-3.13.11 has one narrow exceptionTemporary vulnerabilities or deficiencies with a known fix available or in process; not initial incomplete implementation
The requirement is scoredNOT METMET, when appropriately addressed with deficiency review and demonstrated progress
What it gets youConditional statusA governed path for temporary drift between assessments
Where it is defined32 CFR 170.2132 CFR 170.4 and 170.24(b)(1)(ii); tied to CA.L2-3.12.2

[Editorial judgment] So when an implemented control develops a temporary deficiency — an MFA service outage, a short-lived logging failure, or a tool change with a known correction underway — the rule gives you an operational plan of action with a documented deficiency review and demonstrated progress. It does not convert an initially unimplemented requirement into MET. Not a POA&M. Not silence. Not a frantic call to your assessor.

Two practical consequences worth building into your maintenance workflow:

  • New systems are scope and change-control decisions. DFARS 252.204-7021(d)(2) permits FCI or CUI to be processed, stored, or transmitted only on contractor information systems with the current CMMC Status required by the contract. Spinning up a new server that will handle FCI or CUI means confirming that it is inside the applicable assessment scope and that the change does not break current compliance — not merely adding it to the patch schedule.
  • CMMC UID changes get reported. DFARS 252.204-7021(e)(1)(ii) requires you to submit changes in CMMC unique identifiers to the Contracting Officer throughout the life of the contract. CMMC Status and UIDs are recorded in SPRS; Level 2 certification results move through the CMMC instance of eMASS before reaching SPRS.

Do not blur the two SPRS records. Where DFARS 252.204-7019/-7020 appear in the applicable instrument, the NIST SP 800-171 DoD Assessment score under those clauses and the CMMC Status record under 32 CFR Part 170/DFARS 252.204-7021 are separate records that can both exist in SPRS. A 110 NIST DoD Assessment score is not, by itself, a CMMC Status.

▶ Build the routine before you need it

The 32-point CMMC Readiness Checklist covers scope, SSP and POA&M governance, SPRS, tooling, provider alignment, pre-assessment evidence, supply chain, and governance. Pair it with the Maintenance event trace on this page and run that trace on a regular cadence — not as a one-time cleanup.

Get the readiness checklist →


Did the July 2026 CMMC Phase II suspension change any of this?

Answer capsule. No. The July 13, 2026 suspension paused Phase II implementation, meaning requiring activities may currently designate only CMMC Level 1 (Self) or Level 2 (Self) assessments rather than Level 2 (C3PAO) or Level 3 (DIBCAC). It did not amend 32 CFR Part 170 or DFARS 252.204-7021, so all six Maintenance requirements remain part of the 110 Level 2 requirements assessed in a self-assessment.

Under the original four-phase schedule, Phase I was November 10, 2025 through November 9, 2026. Phase II was scheduled to begin November 10, 2026 before the Department suspended that transition on July 13, 2026; Phase I self-assessment requirements now remain in effect during the suspension.

What changed — What did not
What changedWhat did not
New Level 2 (C3PAO) and Level 3 (DIBCAC) procurement designations are pausedLevel 1 and Level 2 self-assessment requirements remain in effect
The scheduled November 10, 2026 transition to Phase II and later milestones are suspended pending further guidanceThe six MA requirements remain part of the 110
Unqualified pre-July rollout-date language is staleDFARS 252.204-7012 safeguarding duties remain in force where the clause applies
A CMMC Reform Task Force is reviewing the programLevel 2 still maps to NIST SP 800-171 Revision 2

[Editorial judgment] Here's the version worth internalizing: the suspension paused Level 2 (C3PAO) and Level 3 (DIBCAC) procurement designations during the review. It did not pause a required Level 2 self-assessment or the affirmation a senior official signs. An unexamined self-assessment raises the stakes on evidence quality, because there is no C3PAO between your score and your contract.

The July 13 implementing memorandum says further guidance will follow the Department CIO's 60-day review, placing the expected review point around mid-September 2026. It does not promise a public report on that date. Last verified August 20, 2026. Full coverage of what the suspension changed →


What are the most common CMMC Maintenance failures?

Answer capsule. The failure mode to design against is a documented policy that cannot be connected to an actual maintenance event — a specific person, a controlled tool, a sanitization decision, a malicious-code check, an authenticated session, a termination record, or a supervision record.

The failure — Why it fails — What fixes it
The failureWhy it failsWhat fixes it
Policy exists, events are informalPolicy shows intent; assessment requires implemented evidenceTrace real events and retain final records
"Patching covers Maintenance"Leaves up to 15 possible deductions unaddressedBuild the event-trigger map across all six
Persistent agent, but no per-session closure recordThe second objective of 3.7.5 cannot be demonstratedDefine session closure and retain start/end evidence
MFA exists somewhere in the vendor stackIt does not prove the maintenance path is gated by MFAMap the authentication chain end to end
Equipment shipped because it was encryptedIt does not establish that CUI was sanitizedDocument the sanitization decision and verification
Trusted vendor media not scannedReputation is not a malicious-code checkBuild a pre-use intake process
Vendor employee presumed authorizedEmployment is not authorizationDefine authorization; invoke supervision when it is absent
In-scope ESP responsibilities missing from the SSPYou cannot explain who implements the objectiveDocument ownership and evidence flow in the SSP and CRM
Ticket closed with no validationCompletion is not verificationAdd a post-maintenance validation step
Draft procedure offered as evidence32 CFR 170.24(b)(1) excludes drafts and unapproved policiesApprove and operate the process before relying on it

Several are workflow and evidence-access fixes rather than infrastructure rebuilds. [Editorial judgment] The expensive version is discovering during an assessment that you and your provider each assumed the other owned the evidence — or that the provider's tooling cannot produce it at all.

What an inaccurate score can cost

We're not going to manufacture urgency about the Maintenance family. But it's worth knowing what sits at the end of the road when a score can't be supported.

On June 18, 2026, the Department of Justice announced a $507,144 settlement with LOGZONE, Inc., resolving False Claims Act allegations related to cybersecurity requirements on Navy contracts. The DOJ press release states that a DCMA assessment produced a score of −170. The published settlement agreement states that LOGZONE had submitted a perfect self-assessment score of 110 in SPRS on October 13, 2021. The claims were allegations, and there was no determination of liability.

[Editorial judgment] We cite it here for one narrow reason: the government compared a contractor-posted score with a later DIBCAC assessment and alleged the required controls were not fully implemented. Evidence does not substitute for implementation, but a score you cannot support with final, retrievable evidence is a score you should not post. That principle applies to the 18 possible Maintenance deductions exactly as it applies to the rest of the Level 2 score.


What we actually verified

We build these pages by reading the source documents, not by summarizing other summaries. Here's what that meant for this one.

Read at the eCFR on August 20, 2026:

  • 32 CFR Part 170 — especially §§ 170.14, 170.16, 170.17, 170.19, 170.21, and 170.24. We pulled every Maintenance point value from § 170.24(c)(2)(i)(B), checked the MET/NOT MET evidence rules, verified the narrow partial-credit cases, confirmed the six-year retention and certification-path hashing requirements, and checked the ESP/CRM scoping language.
  • 32 CFR 170.4 — the CMMC definitions of External Service Provider, operational plan of action, CMMC Status, and related terms.

Read at Acquisition.gov on August 20, 2026:

Read in the official NIST and CMMC libraries:

  • NIST SP 800-171 Revision 2, section 3.7 — the six controlling Maintenance requirements. NIST's catalog marks Revision 2 superseded, but 32 CFR Part 170 still incorporates it for CMMC Level 2.
  • NIST SP 800-171A, June 2018 — the 10 Maintenance assessment objectives and the examine, interview, and test methods incorporated by the rule.
  • DoD CMMC Assessment Guide – Level 2, Version 2.13 — the current official assessment guidance listed in the DoD CMMC resource library, including the corrective/preventive/adaptive/perfective maintenance discussion and potential assessment objects.
  • NIST SP 800-172, February 2021 and the selected Level 3 requirements in § 170.14. NIST superseded the publication in May 2026, but the current CMMC rule still incorporates the February 2021 version.
  • NIST SP 800-88 Revision 2 — the current media-sanitization guidance, published September 2025.

Checked current implementation and assessment-process sources:

  • The July 13, 2026 CMMC suspension materials — Phase I remains in effect; the Phase II transition and Level 2 (C3PAO)/Level 3 procurement designations are suspended pending further guidance.
  • The Cyber AB CMMC Assessment Process (CAP), Version 2.0, December 2024 — the Level 2 certification-assessment process, Marketplace selection language, impartiality and conflict-of-interest controls, and the prohibition on guarantees tied to assessment results. The CAP governs Level 2 certification assessments; it does not replace 32 CFR Part 170 or the NIST requirements.
  • The DOJ LOGZONE press release and the linked settlement agreement — the $507,144 amount, the −170 DIBCAC score, the previously posted 110 self-assessment score, and the no-determination-of-liability language.

What we did not verify, stated plainly:

  • Per-control CMMC failure rates. DoD does not publish them, so this page does not present one.
  • A universal evidence-retention rule beyond the six-year CMMC artifact requirement. Other contractual, litigation-hold, export-control, tax, or records-management duties may apply; this page does not catalog them.
  • Any employee-count claim. This article makes none.

Byline: The Defense Compliance Report Editorial Team. We publish editorial standards, an editorial methodology, and a corrections policy. If you find an error on this page, tell us and we'll fix it with a dated note.


CMMC maintenance requirements: frequently asked questions

Answer capsule. The questions below cover the implementation edge cases that most often send readers back to search after reading a control list — scope, scoring, POA&M treatment, provider responsibility, and the boundaries between MA requirements and adjacent controls.

How many CMMC maintenance requirements are there? Six, containing 10 assessment objectives. They are MA.L2-3.7.1 through MA.L2-3.7.6, drawn from NIST SP 800-171 Revision 2 section 3.7.

How many points are the CMMC Maintenance controls worth? Together they create 18 possible deductions from the 110-point maximum: 3.7.1 is 3 points, 3.7.2 is 5, 3.7.3 is 1, 3.7.4 is 3, 3.7.5 is 5, and 3.7.6 is 1. Source: 32 CFR 170.24(c)(2)(i)(B).

Which CMMC Maintenance requirements can go on a POA&M? Only the two 1-point requirements — MA.L2-3.7.3 and MA.L2-3.7.6. Under 32 CFR 170.21(a)(2)(ii), Maintenance requirements worth more than one point cannot be placed on a Level 2 POA&M, which rules out 3.7.1, 3.7.2, 3.7.4, and 3.7.5. The rule's narrow SC.L2-3.13.11 FIPS-validation exception is outside this family.

Do the Maintenance requirements apply at CMMC Level 1? No. Level 1 consists of the 15 basic safeguarding requirements from FAR 52.204-21, which contain no Maintenance-family requirement. The MA controls are entirely a Level 2 addition.

Does CMMC Level 3 add more Maintenance requirements? No. The 24 selected requirements from the February 2021 version of NIST SP 800-172 that the current rule adds at Level 3 do not include a Maintenance-domain requirement. But Level 3 is stricter on this family, not looser: 32 CFR 170.24(c)(3) requires a maximum Level 2 certification-assessment score before Level 3 may begin — which means no Maintenance deferral at all, including the two 1-pointers.

Is patching enough to satisfy the Maintenance family? No. Installing patches can support MA.L2-3.7.1, the 3-point requirement. A controlled or remote patching process may also produce evidence for 3.7.2 or 3.7.5, but patch installation by itself leaves the rest of the family unproven.

What is nonlocal maintenance? Maintenance conducted by individuals communicating through an external network connection — for example, RMM sessions, VPN administration, remote desktop, vendor support tunnels, and cloud management consoles used to maintain an in-scope resource.

Is MFA alone enough for remote maintenance? No. MA.L2-3.7.5 has two objectives: multifactor authentication to establish the session, and termination of the connection when maintenance is complete. Both must be demonstrated.

Does MA.L2-3.7.5 require encryption? Not by its own text. The requirement addresses multifactor authentication and connection termination. Cryptographic protection of remote sessions is addressed by adjacent requirements in other families, which may also apply to your architecture.

Must remote maintenance sessions be recorded on video? No. Nothing in the requirement mandates keystroke or video recording. What you need is retrievable evidence that the session was authenticated on the correct path and terminated when the work ended.

Can a vendor keep an unattended RMM agent installed on our systems? The installed agent is not the same thing as an active connection. Each nonlocal maintenance session through an external network still must be established with MFA and terminated when maintenance is complete. A persistent agent can be consistent with MA.L2-3.7.5 when it cannot create a maintenance session without per-session MFA and each connection terminates when the work ends; an always-open maintenance connection is difficult to reconcile with the requirement.

Does our MSP need its own CMMC status? Not automatically, and not merely because it performs maintenance. First determine whether it is an ESP under the CMMC definition — CUI or Security Protection Data must be processed, stored, or transmitted on the provider's assets. If it is in scope, document the services in the SSP, service description, and Customer Responsibility Matrix and assess the applicable responsibilities inside your assessment.

Is an NDA enough to authorize a repair technician? No. A nondisclosure agreement is a confidentiality instrument. It does not establish the system and information access authorization that MA.L2-3.7.6 turns on.

Can a technician without authorization perform maintenance at all? Yes, provided you implement the supervision required by MA.L2-3.7.6 and satisfy the other applicable access and maintenance requirements.

Is encryption enough before we send equipment out for repair? It should not be presented as satisfying MA.L2-3.7.3, which is framed around sanitizing CUI from equipment before off-site maintenance.

Do vendor diagnostic downloads need to be checked for malicious code? MA.L2-3.7.4 requires checking media containing diagnostic and test programs before use. The defensible approach is to bring vendor-supplied diagnostic software into your intake process regardless of how it was delivered.

How long do we keep maintenance evidence? Assessment artifacts are retained six years from the CMMC Status Date under 32 CFR 170.16(c)(4) and 170.17(c)(4). On the certification path, 170.17(c)(4) also requires the artifacts to be hashed with a NIST-approved algorithm.

Does NIST SP 800-171 Revision 3 replace Revision 2 for CMMC? Not under the current program rule. NIST has published Revision 3 and marked Revision 2 as superseded in its own catalog, but 32 CFR 170.14(c)(3) still maps CMMC Level 2 to Revision 2. Build to Revision 2 until the CMMC rule is amended.

Did the July 2026 Phase II suspension remove the Maintenance requirements? No. It suspended Level 2 (C3PAO) and Level 3 (DIBCAC) procurement designations during the review and directed changes to affected active solicitations and contracts. It did not amend 32 CFR Part 170, and all six MA requirements remain part of the 110 Level 2 requirements.

What happens if a Maintenance control breaks between assessments? 32 CFR 170.24(b)(1)(ii) provides that temporary deficiencies appropriately addressed in operational plans of action — with deficiency reviews and demonstrated progress — are assessed as MET. The CMMC definition treats an operational plan of action as distinct from a POA&M and prescribes no remediation timeline, but it is for temporary post-implementation deficiencies, not for an initially unimplemented requirement.


The bottom line

Six requirements. Ten objectives. Eighteen possible deductions. Sixteen of them non-deferrable — and, in an outsourced IT model, four of the six often depend on work or records controlled by someone who doesn't work for you.

That's the whole problem, and it's also the whole solution. Maintenance is usually not a technology gap. It is a workflow gap and a vendor-accountability gap, and both can close faster than many other high-point gaps once ownership and evidence access are clear.

Start with the event, not the control list. Trace one real maintenance event end to end. Send your provider the twelve questions. Then decide whether what's missing is process, operations, evidence, or scope — because that answer, not a vendor's sales page, tells you what kind of help you actually need.

Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Request scoped CMMC provider quotes →

Do not submit CUI, drawings, credentials, system diagrams, sensitive contract details, or other protected information.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

This page is educational research, not legal, contractual, or compliance advice. The solicitation, contract, or flow-down states the required CMMC Status; your FCI/CUI handling and assessment scope determine where it applies. Confirm scope and applicability with a CMMC Registered Practitioner (RP), a Registered Provider Organization (RPO), or a qualified federal-contracts attorney.