Requirements / Security Assessment (CA)
CA.L2-3.12.1
Security Control Assessment
Official Source Material
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
Determine if:
- [a] the frequency of security control assessments is defined; and
- [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Define the frequency in writing, and treat annual as the floor.
Objective [a] is a stated frequency, and the CMMC rule at 32 CFR 170.4 defines periodically as at least annually. An annual self-assessment of your implemented controls, documented and dated, satisfies the letter of both objectives. This is a five-point requirement under 32 CFR 170.24. Its point value keeps it off any POA&M, the plan of action and milestones that defers unmet requirements, under 32 CFR 170.21. Build the habit before the assessment year.
Assess effectiveness, not existence.
The requirement says determine if the controls are effective in their application. That is a harder question than whether you are doing what your system security plan, the document that says how each requirement is met, claims. For each control, ask whether the implementation actually mitigates the risk it is there for. The log review that never finds anything may be looking at the wrong logs. The visitor badge process nobody follows is a control on paper only. Record the judgment, not just a met checkbox.
The outputs are documents that feed other requirements.
The guide lists them: documented assessment results, proposed new or updated controls, remediation plans, and newly identified risks. The deficiencies you find become the CA.L2-3.12.2 plan of action, and the risks feed RA.L2-3.11.1. An assessment that produces findings and follow-up work is self-evidently real. One that produces a clean sheet every year invites the question of how hard anyone looked.
Keep CA.L2-3.12.1 and CA.L2-3.12.3 distinct in your program.
This requirement is the scheduled, deliberate look at whether controls are effective as designed. CA.L2-3.12.3 is the ongoing monitoring between those looks. One annual assessment plus a recurring monitoring rhythm covers both. A single activity labeled with both identifiers covers neither, because the evidence for a periodic deep review and for continuous monitoring look different.
An exercise can be a control assessment.
Testing the incident response plan, restoring from backup, or failing over a system assesses those controls in their application. Fold the results into your assessment record. Planning to evaluate the plan only when a real incident arrives is not an assessment method. It is the absence of one.
What falls short
- A system security plan review that asks only whether each control is still being done. It never determines effectiveness, so [b] is unmet.
- Assessments that happen when someone remembers. Without a defined frequency, [a] is unmet no matter how good the individual assessments are.