CMMC 3.6.2 (Incident Tracking & Reporting): Evidence & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.6.2 · CMMC Practice: IR.L2-3.6.2 · Updated June 2026
Plain-English answer
3.6.2 requires you to track, document, and report incidents to designated officials and/or authorities, both internal and external. Identify who gets told (internal officials and external authorities), keep incidents tracked and documented, and actually report to those parties. For DoD contractors, the external-authority path typically includes DFARS 252.204-7012 rapid reporting to DIBNet.
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment. It's the reporting half of incident response, paired with the handling capability in 3.6.1.
Why it matters
Unreported incidents can't be acted on by the people — internal and governmental — who need to know. Tracking and reporting is also where DFARS 7012 obligations attach. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).
Control lineage
- CMMC Practice: IR.L2-3.6.2
- NIST 800-171 Rev. 2: §3.6.2 — track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
- NIST 800-171A objectives: [a] incidents are tracked; [b] incidents are documented; [c] authorities to whom incidents are to be reported are identified; [d] organizational officials to whom incidents are to be reported are identified; [e] identified authorities are reported to; [f] identified organizational officials are reported to.
What the assessor will EXAMINE
- An incident tracking system/log where incidents are recorded and worked.
- Incident documentation (reports/tickets) for handled incidents.
- The list of internal officials and external authorities incidents are reported to (including the DFARS 7012/DIBNet path where applicable).
- Evidence reports were actually sent to those parties; SSP narrative for 3.6.2.
What the assessor will INTERVIEW & TEST
- Interview: "When an incident occurs, who internally and externally gets notified, and how is it tracked?" — name the officials, the authorities, and the tracking tool.
- Test: Pull a tracked incident and confirm it's documented and was reported to the identified parties.
- Test: Confirm the external reporting path (e.g., DIBNet for DFARS 7012) is set up and known to staff.
Evidence examples (produce these)
- Incident tracking log/system showing tracked, documented incidents.
- A documented incident report (sanitized) as a sample.
- Defined list of internal officials and external authorities, with the DFARS 7012/DIBNet reporting path where applicable.
- Evidence of an actual report/notification to those parties (or exercise record).
- SSP section 3.6.2 referencing the above.
Common failure patterns
- Incidents handled informally with no tracking/documentation — objectives [a]/[b] fail.
- Internal officials identified but external authorities not (no DFARS 7012/DIBNet path) — objective [c]/[e] fails.
- Reporting recipients undefined, so notification is ad hoc.
- A DFARS 7012 obligation that staff don't know how to action.
SPRS impact & POA&M
SPRS: 3.6.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.6.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.6.2 when incidents are tracked and documented; internal officials and external authorities are identified (including the DFARS 7012 path); reporting to them is demonstrable; and the SSP matches the practice.
Is your external reporting path (DIBNet) actually wired up? Get an incident-reporting evidence map →
Related: 3.6.1 Incident Handling · DFARS 7012 vs 7021 · All control pages
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.