CMMC 3.6.1 (Incident Handling): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.6.1 · CMMC Practice: IR.L2-3.6.1 · Updated June 2026

    Plain-English answer

    3.6.1 requires an operational incident-handling capability that includes preparation, detection, analysis, containment, recovery, and user response. Two things matter: the capability is genuinely operational (not a binder on a shelf), and it covers all six phases. Detection leans on your monitoring (3.14.6) and logging (3.3.1).

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment.

    Why it matters

    Incidents are a question of when, not if. A capability that can detect, contain, and recover limits the damage to CUI — and a tested one proves it works before it's needed. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: IR.L2-3.6.1
    • NIST 800-171 Rev. 2: §3.6.1 — establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
    • NIST 800-171A objectives: [a] an operational incident-handling capability is established; [b] the capability includes preparation; [c] the capability includes detection; [d] the capability includes analysis; [e] the capability includes containment; [f] the capability includes recovery; [g] the capability includes user response activities.

    What the assessor will EXAMINE

    • The incident response plan covering all six phases, with defined roles and contacts.
    • Detection inputs — monitoring/SIEM alerts feeding the capability.
    • Evidence of an exercise or real incident handled end to end (after-action report, ticket trail).
    • SSP narrative for 3.6.1.

    What the assessor will INTERVIEW & TEST

    • Interview: "Walk me through what happens from the moment something suspicious is detected." — the answer should hit detection → analysis → containment → recovery → user response.
    • Test: Review a tabletop/test or real-incident record showing the phases were actually exercised.
    • Test: Confirm detection is wired to real monitoring, not assumed.

    Evidence examples (produce these)

    • Incident response plan/playbooks covering preparation through user response.
    • Defined IR roles, on-call/contact list, and escalation path.
    • Tabletop exercise or incident after-action report with dates.
    • Detection evidence (SIEM/monitoring alerts) that feeds incident handling.
    • SSP section 3.6.1 referencing the above.

    Common failure patterns

    • An IR plan exists but was never exercised — "operational" can't be demonstrated (objective [a]).
    • Plan covers detection/containment but omits user response — objective [g] fails.
    • No real detection capability feeding the process — detection is theoretical.
    • Roles undefined, so no one owns containment or recovery.

    SPRS impact & POA&M

    SPRS: 3.6.1 carries a weighted deduction (verify the exact value). POA&M: confirm 3.6.1's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.6.1 when an operational capability covers all six phases, roles and detection inputs are defined, you've exercised it (tabletop or real incident) with documentation, and the SSP matches the practice.

    Could you prove your IR plan actually works under pressure? Get an incident-response evidence map →

    Related: 3.6.2 Incident Reporting · 3.14.6 System Monitoring · All control pages

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.