CMMC 3.4.2 (Security Configuration Enforcement): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.4.2 · CMMC Practice: CM.L2-3.4.2 · Updated June 2026

    Plain-English answer

    3.4.2 requires you to establish security configuration settings for your IT products and enforce them. Establishing usually means adopting a hardening baseline (CIS Benchmarks or DISA STIGs). Enforcing means pushing those settings centrally and detecting drift — not hoping each machine was set up correctly. It builds directly on the baseline from 3.4.1.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment.

    Why it matters

    Misconfiguration is one of the most common ways systems get compromised. Hardened, enforced settings shrink the attack surface. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: CM.L2-3.4.2
    • NIST 800-171 Rev. 2: §3.4.2 — establish and enforce security configuration settings for information technology products employed in organizational systems.
    • NIST 800-171A objectives: [a] security configuration settings for IT products are established and included in the baseline configuration; [b] those security configuration settings are enforced.

    What the assessor will EXAMINE

    • The documented secure configuration settings (the hardening standard adopted, e.g., CIS/STIG).
    • The enforcement mechanism — group policy / Intune configuration profiles / MDM / config management tooling.
    • Compliance/drift reports showing systems match the settings.
    • Configuration-management policy and the SSP narrative for 3.4.2.

    What the assessor will INTERVIEW & TEST

    • Interview: "What hardening standard do you use, and how is it enforced and monitored for drift?" — name the benchmark + the enforcement + the drift report.
    • Test: Inspect a sampled endpoint/server against the documented settings.
    • Test: Review a compliance report to confirm enforcement holds across the fleet, not just one machine.

    Evidence examples (produce these)

    • Documented secure-configuration standard (CIS Benchmark / STIG profile adopted).
    • Enforcement configuration export (GPO / Intune profile / config-management policy).
    • Compliance/drift report per system, dated, showing conformance.
    • SSP section 3.4.2 referencing the above.

    Platform-specific

    • Microsoft GCC High: Intune security baselines / configuration profiles + compliance reporting; Defender for Cloud secure-config recommendations.
    • Endpoints generally: MDM/RMM-enforced CIS settings with a conformance report.

    Common failure patterns

    • Settings are "documented" but not centrally enforced — objective [b] fails.
    • No recognized hardening baseline; settings are ad hoc and undefendable.
    • Enforced on workstations but not servers (or vice versa) — partial coverage.
    • No drift detection, so machines silently fall out of compliance.

    SPRS impact & POA&M

    SPRS: 3.4.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.4.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.4.2 when a recognized hardening standard is documented and included in your baseline; settings are centrally enforced across in-scope systems; drift is detected and reported; and the SSP matches the enforcement.

    Are your hardened settings actually enforced — and can you prove it fleet-wide? Get a configuration-enforcement evidence map →

    Related: 3.4.1 Baseline Configuration · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. CIS Benchmarks and DISA STIGs are the property of their respective owners. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.