CMMC 2.0 organises security requirements into practices grouped across 14 domains. Each practice corresponds to a specific security requirement from NIST SP 800-171 (Level 2) or FAR 52.204-21 (Level 1).

The 14 CMMC Domains

Domain IDDomain NameL1L2Focus Area
ACAccess Control422Limit system access to authorised users
ATAwareness & Training03Ensure personnel are aware of security risks
AUAudit & Accountability09Create, protect, and retain audit records
CMConfiguration Management09Establish and maintain baseline configurations
IAIdentification & Authentication211Identify and authenticate users and devices
IRIncident Response03Establish incident-handling capability
MAMaintenance06Perform timely system maintenance
MPMedia Protection19Protect and sanitise media containing CUI
PEPhysical Protection46Limit physical access to systems
PSPersonnel Security02Screen individuals prior to access
RARisk Assessment03Assess organisational risk
CASecurity Assessment04Assess and monitor security controls
SCSystem & Communications Protection216Monitor and protect communications
SISystem & Information Integrity47Identify and correct system flaws

Practice Statuses

Not StartedPractice has not been addressed yet
In ProgressImplementation is underway but not complete
ImplementedPractice is fully implemented and operational
Not ApplicablePractice does not apply (requires justification)
On POA&MPractice has a known gap with a plan to remediate