CMMC 3.6.2 (Incident Tracking & Reporting): Evidence & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.6.2 · CMMC Practice: IR.L2-3.6.2 · Updated June 2026

    Plain-English answer

    3.6.2 requires you to track, document, and report incidents to designated officials and/or authorities, both internal and external. Identify who gets told (internal officials and external authorities), keep incidents tracked and documented, and actually report to those parties. For DoD contractors, the external-authority path typically includes DFARS 252.204-7012 rapid reporting to DIBNet.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment. It's the reporting half of incident response, paired with the handling capability in 3.6.1.

    Why it matters

    Unreported incidents can't be acted on by the people — internal and governmental — who need to know. Tracking and reporting is also where DFARS 7012 obligations attach. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: IR.L2-3.6.2
    • NIST 800-171 Rev. 2: §3.6.2 — track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
    • NIST 800-171A objectives: [a] incidents are tracked; [b] incidents are documented; [c] authorities to whom incidents are to be reported are identified; [d] organizational officials to whom incidents are to be reported are identified; [e] identified authorities are reported to; [f] identified organizational officials are reported to.

    What the assessor will EXAMINE

    • An incident tracking system/log where incidents are recorded and worked.
    • Incident documentation (reports/tickets) for handled incidents.
    • The list of internal officials and external authorities incidents are reported to (including the DFARS 7012/DIBNet path where applicable).
    • Evidence reports were actually sent to those parties; SSP narrative for 3.6.2.

    What the assessor will INTERVIEW & TEST

    • Interview: "When an incident occurs, who internally and externally gets notified, and how is it tracked?" — name the officials, the authorities, and the tracking tool.
    • Test: Pull a tracked incident and confirm it's documented and was reported to the identified parties.
    • Test: Confirm the external reporting path (e.g., DIBNet for DFARS 7012) is set up and known to staff.

    Evidence examples (produce these)

    • Incident tracking log/system showing tracked, documented incidents.
    • A documented incident report (sanitized) as a sample.
    • Defined list of internal officials and external authorities, with the DFARS 7012/DIBNet reporting path where applicable.
    • Evidence of an actual report/notification to those parties (or exercise record).
    • SSP section 3.6.2 referencing the above.

    Common failure patterns

    • Incidents handled informally with no tracking/documentation — objectives [a]/[b] fail.
    • Internal officials identified but external authorities not (no DFARS 7012/DIBNet path) — objective [c]/[e] fails.
    • Reporting recipients undefined, so notification is ad hoc.
    • A DFARS 7012 obligation that staff don't know how to action.

    SPRS impact & POA&M

    SPRS: 3.6.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.6.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.6.2 when incidents are tracked and documented; internal officials and external authorities are identified (including the DFARS 7012 path); reporting to them is demonstrable; and the SSP matches the practice.

    Is your external reporting path (DIBNet) actually wired up? Get an incident-reporting evidence map →

    Related: 3.6.1 Incident Handling · DFARS 7012 vs 7021 · All control pages

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.