Requirements / Risk Assessment (RA)
RA.L2-3.11.1
Risk Assessments
Official Source Material
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
Determine if:
- [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined; and
- [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Objective [a] is one sentence in a policy: write down the frequency.
An undefined frequency fails [a] before anyone looks at the assessment itself. The CMMC rule at 32 CFR 170.4 defines periodically as at least annually, so annual is the floor. State the frequency, then show assessments dated to match it for [b].
Assess the risks that come from operating a system that handles CUI, not every risk your company has.
CUI is the controlled unclassified information your contract requires you to protect. The requirement scopes itself: risk resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. The risks in scope are unauthorized access, disclosure, spills, compromised credentials, and a vendor with access it should not have. A disaster recovery annex about earthquakes is a different exercise, and padding the assessment with it does not answer [b].
A dated document is the deliverable, not a platform.
The guide's method is threats, vulnerabilities, likelihood, and impact, with NIST SP 800-30, the government's risk assessment guide, as the reference. A few pages that walk your CUI environment through that lens, signed and dated, repeated on your defined frequency, meets the requirement. Buy a risk register tool when the volume of findings demands one, not to have something to show.
Reuse the company-wide risk assessment where the infrastructure is shared.
If your CUI environment runs in the same building, on the same network, with the same staff as everything else, one assessment can serve both. Extend it with the CUI-specific risks rather than duplicating the whole exercise for the CUI environment.
This assessment is what the rest of the family points back to.
RA.L2-3.11.3 remediates vulnerabilities in accordance with risk assessments, and the plans of action under CA.L2-3.12.2 flow from what the assessment finds. Skip it and those requirements lose the document they depend on. Do it and prioritization decisions elsewhere become defensible instead of arbitrary.
What falls short
- A generic corporate risk register that never mentions CUI or the system that handles it. It does not assess the risk the requirement names, so [b] is unmet.
- A policy that says risk is assessed periodically without a number. Objective [a] asks for a defined frequency, and periodically is not one.
Edge cases
- Clearly defined system boundaries come first, and the guide calls them a prerequisite. If your CMMC scope is still moving, settle it before assessing risk, or the assessment describes a system that no longer exists by the time an assessor reads it.