CMMCpedia Download

Requirements / Configuration Management (CM)

CM.L2-3.4.6

Least Functionality

Official Source Material

Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

Determine if:

  1. [a] essential system capabilities are defined based on the principle of least functionality; and
  2. [b] the system is configured to provide only the defined essential capabilities.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Define essential first, or nothing else in this requirement works.

Objective [a] asks what each system needs to do for its role: workstations edit documents and handle email, the file server serves files. Write those definitions down. Objective [b] is the configuration work of disabling what falls outside them.

The justification column turns your software inventory into evidence.

Add a column to the CM.L2-3.4.1 inventory stating why each application is present. Software with no reason gets removed. That one artifact answers [a] for software and shows the review behind [b].

Provisioning is where least functionality happens.

IT builds the machine from the baseline, strips what the role does not need, and delivers it. State that in the system security plan, the document that describes how your system meets each requirement. Name the tools that enforce it, such as Group Policy, Intune, or AppLocker. Do not paste every setting into the plan. The plan references the baseline, and the baseline holds the detail.

Factory defaults are your responsibility the moment the device is yours.

Preinstalled vendor utilities, trial software, and default-enabled services do not become acceptable by arriving preinstalled. Keep what has a documented purpose, such as a recovery tool, and remove the rest.

Combining roles on one server is allowed. Document what it does and disable what it does not.

A small company running DNS and domain services on one box is within the requirement, provided the combined role is defined and the unused capabilities are off. Keep high-exposure roles, especially anything internet-facing, on their own component where feasible.

What falls short

  • Systems deployed as shipped. A default install enables services and applications no one defined as essential, so neither [a] nor [b] is met.

Edge cases

  • Preinstalled OEM tools such as recovery utilities and runtime frameworks stay when you write down why they are needed. Keeping them without the justification is the same gap as installing them without approval.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.