// US Standards
CMMC Compliance Software
US DoD supply chain cybersecurity framework with three maturity levels.
Framework at a glance
Short name
CMMC
Version
—
Category
US Standards
Controls
110
What CMMC covers
110 controls across 61 domains — every one tracked, owned and evidenced in Cyber Horizon.
Access Control
5 controls- AC.L2-3.1.1 Authorised access control
- AC.L2-3.1.2 Transaction and function control
- AU.L2-3.3.9 Limit audit management
- MP.L2-3.8.2 Limit media access
- MP.L2-3.8.5 Control media access
Data Flow
1 controls- AC.L2-3.1.3 Control CUI flow
Separation of Duties
1 controls- AC.L2-3.1.4 Separation of duties
Least Privilege
1 controls- AC.L2-3.1.5 Least privilege
Privileged Access
2 controls- AC.L2-3.1.6 Non-privileged account use
- AC.L2-3.1.7 Privileged function monitoring
Authentication
5 controls- AC.L2-3.1.8 Unsuccessful logon attempts
- IA.L2-3.5.2 User authentication
- IA.L2-3.5.4 Replay-resistant authentication
- IA.L2-3.5.11 Obscure feedback
- SC.L2-3.13.15 Communications authenticity
Policy
1 controls- AC.L2-3.1.9 Privacy and security notices
Session Management
3 controls- AC.L2-3.1.10 Session lock
- AC.L2-3.1.11 Session termination
- SC.L2-3.13.9 Network disconnect
Remote Access
5 controls- AC.L2-3.1.12 Control remote access
- AC.L2-3.1.14 Remote access routing
- AC.L2-3.1.15 Privileged remote access
- MA.L2-3.7.5 Remote maintenance
- SC.L2-3.13.7 Split tunnelling
Cryptography
3 controls- AC.L2-3.1.13 Remote access cryptography
- IA.L2-3.5.10 Cryptographically protected passwords
- SC.L2-3.13.11 FIPS-validated cryptography
Wireless
2 controls- AC.L2-3.1.16 Wireless access authorisation
- AC.L2-3.1.17 Wireless access cryptography
Mobile
1 controls- AC.L2-3.1.18 Mobile device management
Encryption
4 controls- AC.L2-3.1.19 Encrypt CUI on mobile
- MP.L2-3.8.6 Encrypt portable storage
- SC.L2-3.13.8 Data-in-transit encryption
- SC.L2-3.13.16 Data at rest protection
Network
2 controls- AC.L2-3.1.20 External connections
- SC.L2-3.13.5 Network communications denial
Media
5 controls- AC.L2-3.1.21 Portable storage restriction
- MA.L2-3.7.4 Check media
- MP.L2-3.8.1 Protect system media
- MP.L2-3.8.7 Control removable media
- MP.L2-3.8.8 Prohibit use without identification
Data Handling
1 controls- AC.L2-3.1.22 Control public CUI posting
Training
2 controls- AT.L2-3.2.1 Security awareness training
- AT.L2-3.2.2 Role-based security training
Insider Threat
1 controls- AT.L2-3.2.3 Insider threat awareness
Logging
5 controls- AU.L2-3.3.1 System auditing
- AU.L2-3.3.2 User accountability
- AU.L2-3.3.3 Review and update logged events
- AU.L2-3.3.6 Audit reduction
- PE.L2-3.10.4 Maintain access logs
Monitoring
5 controls- AU.L2-3.3.4 Alert on audit failure
- CA.L2-3.12.3 Security control monitoring
- SI.L2-3.14.3 Security alert monitoring
- SI.L2-3.14.6 Monitor communications for attacks
- SI.L2-3.14.7 Identify unauthorised use
SIEM
1 controls- AU.L2-3.3.5 Correlate audit review
Time Sync
1 controls- AU.L2-3.3.7 Authoritative time source
Log Integrity
1 controls- AU.L2-3.3.8 Protect audit information
Baseline
1 controls- CM.L2-3.4.1 Baseline configurations
Hardening
3 controls- CM.L2-3.4.2 Establish configuration settings
- CM.L2-3.4.6 Least functionality
- CM.L2-3.4.7 Non-essential functionality
Change Management
2 controls- CM.L2-3.4.3 Track and report deviations
- CM.L2-3.4.4 Analyse security impact of changes
Software Control
2 controls- CM.L2-3.4.5 Define user-installed software
- CM.L2-3.4.9 User-installed software control
Application Control
1 controls- CM.L2-3.4.8 Application execution policy
Identity
2 controls- IA.L2-3.5.1 User identification
- IA.L2-3.5.5 Identifier management
MFA
1 controls- IA.L2-3.5.3 Multi-factor authentication
Passwords
4 controls- IA.L2-3.5.6 Password management
- IA.L2-3.5.7 Password complexity
- IA.L2-3.5.8 Password reuse
- IA.L2-3.5.9 Temporary passwords
IR Plan
1 controls- IR.L2-3.6.1 Incident handling capability
Reporting
1 controls- IR.L2-3.6.2 Incident reporting
Testing
1 controls- IR.L2-3.6.3 Incident response testing
Asset Management
2 controls- MA.L2-3.7.1 Perform maintenance
- MA.L2-3.7.2 Provide controls on tools
Media Sanitisation
1 controls- MA.L2-3.7.3 Equipment sanitisation
Physical
1 controls- MA.L2-3.7.6 Maintenance personnel supervision
Disposal
1 controls- MP.L2-3.8.3 Sanitise or destroy media
Classification
1 controls- MP.L2-3.8.4 Mark media
Backup
1 controls- MP.L2-3.8.9 Protect backups
Physical Access
2 controls- PE.L2-3.10.1 Limit physical access
- PE.L2-3.10.5 Manage physical access devices
Physical Security
1 controls- PE.L2-3.10.2 Protect and monitor physical facility
Visitors
1 controls- PE.L2-3.10.3 Escort visitors
Remote Work
1 controls- PE.L2-3.10.6 Enforce safeguarding at alternate work sites
HR
2 controls- PS.L2-3.9.1 Screen individuals
- PS.L2-3.9.2 Termination and transfer actions
Risk Management
1 controls- RA.L2-3.11.1 Risk assessment
Vulnerability Management
2 controls- RA.L2-3.11.2 Vulnerability scan
- RA.L2-3.11.3 Remediate vulnerabilities
Assessment
1 controls- CA.L2-3.12.1 Security control assessment
Remediation
1 controls- CA.L2-3.12.2 Plan of action
Documentation
1 controls- CA.L2-3.12.4 System security plan
Network Security
1 controls- SC.L2-3.13.1 Boundary protection
Network Segmentation
1 controls- SC.L2-3.13.2 Public-access system separation
Privilege Separation
1 controls- SC.L2-3.13.3 Role separation
Data Protection
1 controls- SC.L2-3.13.4 Shared resource protection
Firewall
1 controls- SC.L2-3.13.6 Network communication by exception
Key Management
1 controls- SC.L2-3.13.10 Cryptographic key management
Privacy
1 controls- SC.L2-3.13.12 Collaborative device prohibition
Application Security
1 controls- SC.L2-3.13.13 Mobile code control
Communications
1 controls- SC.L2-3.13.14 VoIP technologies
Patch Management
1 controls- SI.L2-3.14.1 System flaw remediation
Malware
3 controls- SI.L2-3.14.2 Malicious code protection
- SI.L2-3.14.4 Update malicious code protection
- SI.L2-3.14.5 System and file scanning
How Cyber Horizon automates CMMC
Every CMMC control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is CMMC?
US DoD supply chain cybersecurity framework with three maturity levels.
How many controls does CMMC have?
CMMC has 110 controls in Cyber Horizon's catalogue, organised across 61 domains.
How does Cyber Horizon help with CMMC?
Cyber Horizon maps CMMC into a shared control library alongside every other framework you run, so evidence collected once counts towards CMMC and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More US Standards frameworks
See CMMC mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of CMMC in Cyber Horizon.