Skip to content
Cyber Horizon
All frameworks

// US Standards

CMMC Compliance Software

US DoD supply chain cybersecurity framework with three maturity levels.

Framework at a glance

Short name

CMMC

Version

Category

US Standards

Controls

110

What CMMC covers

110 controls across 61 domains — every one tracked, owned and evidenced in Cyber Horizon.

Access Control

5 controls
  • AC.L2-3.1.1 Authorised access control
  • AC.L2-3.1.2 Transaction and function control
  • AU.L2-3.3.9 Limit audit management
  • MP.L2-3.8.2 Limit media access
  • MP.L2-3.8.5 Control media access

Data Flow

1 controls
  • AC.L2-3.1.3 Control CUI flow

Separation of Duties

1 controls
  • AC.L2-3.1.4 Separation of duties

Least Privilege

1 controls
  • AC.L2-3.1.5 Least privilege

Privileged Access

2 controls
  • AC.L2-3.1.6 Non-privileged account use
  • AC.L2-3.1.7 Privileged function monitoring

Authentication

5 controls
  • AC.L2-3.1.8 Unsuccessful logon attempts
  • IA.L2-3.5.2 User authentication
  • IA.L2-3.5.4 Replay-resistant authentication
  • IA.L2-3.5.11 Obscure feedback
  • SC.L2-3.13.15 Communications authenticity

Policy

1 controls
  • AC.L2-3.1.9 Privacy and security notices

Session Management

3 controls
  • AC.L2-3.1.10 Session lock
  • AC.L2-3.1.11 Session termination
  • SC.L2-3.13.9 Network disconnect

Remote Access

5 controls
  • AC.L2-3.1.12 Control remote access
  • AC.L2-3.1.14 Remote access routing
  • AC.L2-3.1.15 Privileged remote access
  • MA.L2-3.7.5 Remote maintenance
  • SC.L2-3.13.7 Split tunnelling

Cryptography

3 controls
  • AC.L2-3.1.13 Remote access cryptography
  • IA.L2-3.5.10 Cryptographically protected passwords
  • SC.L2-3.13.11 FIPS-validated cryptography

Wireless

2 controls
  • AC.L2-3.1.16 Wireless access authorisation
  • AC.L2-3.1.17 Wireless access cryptography

Mobile

1 controls
  • AC.L2-3.1.18 Mobile device management

Encryption

4 controls
  • AC.L2-3.1.19 Encrypt CUI on mobile
  • MP.L2-3.8.6 Encrypt portable storage
  • SC.L2-3.13.8 Data-in-transit encryption
  • SC.L2-3.13.16 Data at rest protection

Network

2 controls
  • AC.L2-3.1.20 External connections
  • SC.L2-3.13.5 Network communications denial

Media

5 controls
  • AC.L2-3.1.21 Portable storage restriction
  • MA.L2-3.7.4 Check media
  • MP.L2-3.8.1 Protect system media
  • MP.L2-3.8.7 Control removable media
  • MP.L2-3.8.8 Prohibit use without identification

Data Handling

1 controls
  • AC.L2-3.1.22 Control public CUI posting

Training

2 controls
  • AT.L2-3.2.1 Security awareness training
  • AT.L2-3.2.2 Role-based security training

Insider Threat

1 controls
  • AT.L2-3.2.3 Insider threat awareness

Logging

5 controls
  • AU.L2-3.3.1 System auditing
  • AU.L2-3.3.2 User accountability
  • AU.L2-3.3.3 Review and update logged events
  • AU.L2-3.3.6 Audit reduction
  • PE.L2-3.10.4 Maintain access logs

Monitoring

5 controls
  • AU.L2-3.3.4 Alert on audit failure
  • CA.L2-3.12.3 Security control monitoring
  • SI.L2-3.14.3 Security alert monitoring
  • SI.L2-3.14.6 Monitor communications for attacks
  • SI.L2-3.14.7 Identify unauthorised use

SIEM

1 controls
  • AU.L2-3.3.5 Correlate audit review

Time Sync

1 controls
  • AU.L2-3.3.7 Authoritative time source

Log Integrity

1 controls
  • AU.L2-3.3.8 Protect audit information

Baseline

1 controls
  • CM.L2-3.4.1 Baseline configurations

Hardening

3 controls
  • CM.L2-3.4.2 Establish configuration settings
  • CM.L2-3.4.6 Least functionality
  • CM.L2-3.4.7 Non-essential functionality

Change Management

2 controls
  • CM.L2-3.4.3 Track and report deviations
  • CM.L2-3.4.4 Analyse security impact of changes

Software Control

2 controls
  • CM.L2-3.4.5 Define user-installed software
  • CM.L2-3.4.9 User-installed software control

Application Control

1 controls
  • CM.L2-3.4.8 Application execution policy

Identity

2 controls
  • IA.L2-3.5.1 User identification
  • IA.L2-3.5.5 Identifier management

MFA

1 controls
  • IA.L2-3.5.3 Multi-factor authentication

Passwords

4 controls
  • IA.L2-3.5.6 Password management
  • IA.L2-3.5.7 Password complexity
  • IA.L2-3.5.8 Password reuse
  • IA.L2-3.5.9 Temporary passwords

IR Plan

1 controls
  • IR.L2-3.6.1 Incident handling capability

Reporting

1 controls
  • IR.L2-3.6.2 Incident reporting

Testing

1 controls
  • IR.L2-3.6.3 Incident response testing

Asset Management

2 controls
  • MA.L2-3.7.1 Perform maintenance
  • MA.L2-3.7.2 Provide controls on tools

Media Sanitisation

1 controls
  • MA.L2-3.7.3 Equipment sanitisation

Physical

1 controls
  • MA.L2-3.7.6 Maintenance personnel supervision

Disposal

1 controls
  • MP.L2-3.8.3 Sanitise or destroy media

Classification

1 controls
  • MP.L2-3.8.4 Mark media

Backup

1 controls
  • MP.L2-3.8.9 Protect backups

Physical Access

2 controls
  • PE.L2-3.10.1 Limit physical access
  • PE.L2-3.10.5 Manage physical access devices

Physical Security

1 controls
  • PE.L2-3.10.2 Protect and monitor physical facility

Visitors

1 controls
  • PE.L2-3.10.3 Escort visitors

Remote Work

1 controls
  • PE.L2-3.10.6 Enforce safeguarding at alternate work sites

HR

2 controls
  • PS.L2-3.9.1 Screen individuals
  • PS.L2-3.9.2 Termination and transfer actions

Risk Management

1 controls
  • RA.L2-3.11.1 Risk assessment

Vulnerability Management

2 controls
  • RA.L2-3.11.2 Vulnerability scan
  • RA.L2-3.11.3 Remediate vulnerabilities

Assessment

1 controls
  • CA.L2-3.12.1 Security control assessment

Remediation

1 controls
  • CA.L2-3.12.2 Plan of action

Documentation

1 controls
  • CA.L2-3.12.4 System security plan

Network Security

1 controls
  • SC.L2-3.13.1 Boundary protection

Network Segmentation

1 controls
  • SC.L2-3.13.2 Public-access system separation

Privilege Separation

1 controls
  • SC.L2-3.13.3 Role separation

Data Protection

1 controls
  • SC.L2-3.13.4 Shared resource protection

Firewall

1 controls
  • SC.L2-3.13.6 Network communication by exception

Key Management

1 controls
  • SC.L2-3.13.10 Cryptographic key management

Privacy

1 controls
  • SC.L2-3.13.12 Collaborative device prohibition

Application Security

1 controls
  • SC.L2-3.13.13 Mobile code control

Communications

1 controls
  • SC.L2-3.13.14 VoIP technologies

Patch Management

1 controls
  • SI.L2-3.14.1 System flaw remediation

Malware

3 controls
  • SI.L2-3.14.2 Malicious code protection
  • SI.L2-3.14.4 Update malicious code protection
  • SI.L2-3.14.5 System and file scanning

How Cyber Horizon automates CMMC

Every CMMC control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is CMMC?

US DoD supply chain cybersecurity framework with three maturity levels.

How many controls does CMMC have?

CMMC has 110 controls in Cyber Horizon's catalogue, organised across 61 domains.

How does Cyber Horizon help with CMMC?

Cyber Horizon maps CMMC into a shared control library alongside every other framework you run, so evidence collected once counts towards CMMC and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See CMMC mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of CMMC in Cyber Horizon.