CMMC 3.4.2 (Security Configuration Enforcement): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.4.2 · CMMC Practice: CM.L2-3.4.2 · Updated June 2026
Plain-English answer
3.4.2 requires you to establish security configuration settings for your IT products and enforce them. Establishing usually means adopting a hardening baseline (CIS Benchmarks or DISA STIGs). Enforcing means pushing those settings centrally and detecting drift — not hoping each machine was set up correctly. It builds directly on the baseline from 3.4.1.
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment.
Why it matters
Misconfiguration is one of the most common ways systems get compromised. Hardened, enforced settings shrink the attack surface. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).
Control lineage
- CMMC Practice: CM.L2-3.4.2
- NIST 800-171 Rev. 2: §3.4.2 — establish and enforce security configuration settings for information technology products employed in organizational systems.
- NIST 800-171A objectives: [a] security configuration settings for IT products are established and included in the baseline configuration; [b] those security configuration settings are enforced.
What the assessor will EXAMINE
- The documented secure configuration settings (the hardening standard adopted, e.g., CIS/STIG).
- The enforcement mechanism — group policy / Intune configuration profiles / MDM / config management tooling.
- Compliance/drift reports showing systems match the settings.
- Configuration-management policy and the SSP narrative for 3.4.2.
What the assessor will INTERVIEW & TEST
- Interview: "What hardening standard do you use, and how is it enforced and monitored for drift?" — name the benchmark + the enforcement + the drift report.
- Test: Inspect a sampled endpoint/server against the documented settings.
- Test: Review a compliance report to confirm enforcement holds across the fleet, not just one machine.
Evidence examples (produce these)
- Documented secure-configuration standard (CIS Benchmark / STIG profile adopted).
- Enforcement configuration export (GPO / Intune profile / config-management policy).
- Compliance/drift report per system, dated, showing conformance.
- SSP section 3.4.2 referencing the above.
Platform-specific
- Microsoft GCC High: Intune security baselines / configuration profiles + compliance reporting; Defender for Cloud secure-config recommendations.
- Endpoints generally: MDM/RMM-enforced CIS settings with a conformance report.
Common failure patterns
- Settings are "documented" but not centrally enforced — objective [b] fails.
- No recognized hardening baseline; settings are ad hoc and undefendable.
- Enforced on workstations but not servers (or vice versa) — partial coverage.
- No drift detection, so machines silently fall out of compliance.
SPRS impact & POA&M
SPRS: 3.4.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.4.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.4.2 when a recognized hardening standard is documented and included in your baseline; settings are centrally enforced across in-scope systems; drift is detected and reported; and the SSP matches the enforcement.
Are your hardened settings actually enforced — and can you prove it fleet-wide? Get a configuration-enforcement evidence map →
Related: 3.4.1 Baseline Configuration · All control pages · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. CIS Benchmarks and DISA STIGs are the property of their respective owners. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.