This table shows the 25 compliance areas where CMMC 2.0 and NIST CSF controls overlap. When you mark a control as implemented in either framework, Venvera automatically propagates the status to the equivalent control in the other.

Compliance AreaCMMC 2.0NIST CSF
Access ControlAC.L2-3.1.1, AC.L2-3.1.2PR.AA-01, PR.AA-05
Least PrivilegeAC.L2-3.1.5, AC.L2-3.1.6PR.AA-05
Remote AccessAC.L2-3.1.12, AC.L2-3.1.14PR.AA-03, PR.IR-01
Wireless AccessAC.L2-3.1.16, AC.L2-3.1.17PR.IR-01
Authentication & MFAIA.L2-3.5.3, IA.L2-3.5.4PR.AA-03
Identifier ManagementIA.L2-3.5.1, IA.L2-3.5.2PR.AA-01, PR.AA-03
Security Awareness & TrainingAT.L2-3.2.1, AT.L2-3.2.2PR.AT-01
Insider Threat AwarenessAT.L2-3.2.3PR.AT-01, PR.AT-02
Audit LoggingAU.L2-3.3.1, AU.L2-3.3.2DE.CM-01, DE.AE-02
Audit Review & ReportingAU.L2-3.3.5, AU.L2-3.3.6DE.AE-02, DE.AE-04
Audit ProtectionAU.L2-3.3.8, AU.L2-3.3.9PR.DS-01
Configuration ManagementCM.L2-3.4.1, CM.L2-3.4.2PR.PS-01
Change ControlCM.L2-3.4.3, CM.L2-3.4.4PR.PS-01, ID.IM-02
Incident ResponseIR.L2-3.6.1, IR.L2-3.6.2RS.MA-01, RS.AN-03
Incident ReportingIR.L2-3.6.3RS.CO-02
Maintenance ControlsMA.L2-3.7.1, MA.L2-3.7.2PR.MA-01
Media ProtectionMP.L2-3.8.1, MP.L2-3.8.2PR.DS-01, PR.DS-10
Media SanitizationMP.L2-3.8.3PR.DS-10
Physical ProtectionPE.L2-3.10.1, PE.L2-3.10.2PR.AA-02
Personnel SecurityPS.L2-3.9.1, PS.L2-3.9.2PR.AA-05, PR.IP-11
Risk AssessmentRA.L2-3.11.1, RA.L2-3.11.2ID.RA-01, ID.RA-03, ID.RA-05
Vulnerability ScanningRA.L2-3.11.2, RA.L2-3.11.3ID.RA-01, PR.PS-01
Security AssessmentCA.L2-3.12.1, CA.L2-3.12.3ID.IM-02
System & Communications ProtectionSC.L2-3.13.1, SC.L2-3.13.2PR.IR-01, PR.DS-01
Encryption (CUI in Transit)SC.L2-3.13.8, SC.L2-3.13.11PR.DS-01, PR.DS-02
ℹ️
For details on how propagation works, thresholds, and the auto-mapped badge, see the Cross-Framework Control Propagation overview article.