The Controls page is where you define, implement, and track the operational controls that satisfy CMMC practices. While practices describe what must be achieved, controls describe how your organisation achieves it.

Control Types

TypeDescriptionExamples
TechnicalImplemented through technologyFirewall rules, encryption, MFA, SIEM, EDR
AdministrativeImplemented through policies and governanceSecurity policies, training programmes, incident response plans
PhysicalImplemented through physical mechanismsBadge readers, security cameras, locked server rooms

Control Statuses

PlannedIdentified and designed but not yet deployed
In ProgressDeployment or configuration is underway
ImplementedDeployed and operational
EffectiveTested and confirmed operating as intended
IneffectiveTested and found inadequate

Control Testing

CMMC assessors evaluate practices using three methods: Examine (review documents/configurations), Interview (discuss with personnel), and Test (exercise mechanisms). Structure your controls and evidence to support all three methods.