Requirements / Risk Assessment (RA)
RA.L2-3.11.2
Vulnerability Scan
Official Source Material
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
Determine if:
- [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined;
- [b] vulnerability scans are performed on organizational systems with the defined frequency;
- [c] vulnerability scans are performed on applications with the defined frequency;
- [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified; and
- [e] vulnerability scans are performed on applications when new vulnerabilities are identified.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Define a frequency you will never miss, then scan more often than it.
Objective [a] wants a number and [b] and [c] want scans dated to match it. Write the frequency you can hold through vacations, outages, and the laptop that stayed in a trunk for a month. Then run your actual scans more often. A quarterly commitment executed weekly never produces a gap between policy and record.
Scan the whole environment the CUI lives in, not just the machines that touch CUI.
CUI is the controlled unclassified information your contract requires you to protect. The guide sweeps in servers, workstations, laptops, virtual machines, network gear, and printers. It says directly that everything in the CMMC assessment scope gets scanned, including laptops that rarely see the office network. A scanner installed on each machine as an agent reaches the remote machines a network scanner never will. Have a plan for one hundred percent of assets, wherever they sit.
Applications hold their own objective letters, so scan them on purpose.
Objectives [c] and [e] exist because an operating-system scan does not see the web application or the database running on the box. A credentialed scan, one that logs in to the machine it examines, reaches the installed software. A web application needs a scan aimed at it. If you build custom software, the guide expects analysis of it, with source code scanning as the accessible starting point.
A scanner you triage beats a platform you ignore.
A free or modest tool run on schedule, with findings reviewed and fed into remediation, is a working vulnerability management program. A subscription generating reports nobody opens is a shelf ornament that fails [b] through [e] the first time an assessor asks what you did about a finding. Pick the tool you will actually operate. This is a five-point requirement under 32 CFR 170.24. Under 32 CFR 170.21, its point value keeps it off any POA&M, the plan of action that buys time for unfinished requirements. A modest working program now outranks a grand plan for later.
Objectives [d] and [e] ask what happens when the world changes between scans.
Two mechanisms cover it: a scanner that updates its vulnerability feed before every scan, and the demonstrated ability to run an off-cycle scan when a severe vulnerability breaks. Keep the report from the last time a headline vulnerability sent you scanning. It is the cleanest evidence [d] and [e] can have.
What falls short
- A patching cadence offered instead of scan results. Patching is SI.L2-3.14.1, and without scan reports there is no evidence for [b] through [e], because updating software is not the same as verifying what remains vulnerable.
- Scans that cover the office subnet while remote laptops are never scanned. In-scope assets went unscanned, so [b] is unmet.
- Operating-system scans with no application coverage. Objectives [c] and [e] are separate letters, and they are the ones left open.
Edge cases
- A device that cannot accept credentialed scanning, like a firewall whose FIPS mode blocks the access, gets an uncredentialed scan, a manual firmware check against vendor advisories, and a documented limitation. State what you do everywhere it is supported rather than listing what one device cannot do.
- Phones and tablets under mobile device management are not what scanners scan in practice. Enforce minimum OS versions and rapid updates through management policy, and document that treatment so the exclusion from scanning is a decision rather than an oversight.