CMMC 3.11.2 (Vulnerability Scanning): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.11.2 · CMMC Practice: RA.L2-3.11.2 · Updated June 2026

    Plain-English answer

    3.11.2 requires you to scan for vulnerabilities in your systems and applications on a defined frequency, and again when new vulnerabilities affecting them are identified. Three things an assessor checks: you defined a cadence, you actually scan on it (systems and apps), and you scan on new-vulnerability events — not just once a year.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment.

    Why it matters

    You can't fix what you don't find. Scanning is how known vulnerabilities surface before an adversary uses them. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: RA.L2-3.11.2
    • NIST 800-171 Rev. 2: §3.11.2 — scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting them are identified.
    • NIST 800-171A objectives: [a] the scan frequency is defined; [b] systems are scanned on that frequency; [c] applications are scanned on that frequency; [d] systems are scanned when new vulnerabilities are identified; [e] applications are scanned when new vulnerabilities are identified.

    What the assessor will EXAMINE

    • The vulnerability-management policy defining scan frequency for systems and applications.
    • Scan reports over time showing the cadence is met (authenticated scans preferred).
    • Coverage — that scans hit the in-scope assets, not a subset.
    • Evidence of event-driven scans when major vulnerabilities emerged.
    • SSP narrative for 3.11.2.

    What the assessor will INTERVIEW & TEST

    • Interview: "How often do you scan, what's covered, and what triggers an off-cycle scan?" — point to the policy + the scan history.
    • Test: Review recent scan reports for cadence, coverage, and that they're authenticated (not just unauthenticated network scans).
    • Test: Confirm a sampled in-scope asset appears in the scan results.

    Evidence examples (produce these)

    • Vulnerability-management policy with defined scan frequency.
    • A series of dated scan reports (systems and applications) showing the cadence.
    • Asset coverage proof — scan targets reconciled to your inventory.
    • An example off-cycle scan tied to a new vulnerability.
    • SSP section 3.11.2 referencing the above.

    Common failure patterns

    • Scanning happens but no defined frequency is documented — objective [a] fails.
    • Only unauthenticated scans, which miss most host-level vulnerabilities.
    • Systems scanned but applications aren't — objectives [c]/[e] fail.
    • Coverage gaps — assets that never get scanned.

    SPRS impact & POA&M

    SPRS: 3.11.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.11.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.11.2 when a scan frequency is defined and met for both systems and applications; scans are authenticated and cover the in-scope inventory; off-cycle scans run on new vulnerabilities; and the SSP matches the practice. (Finding vulnerabilities is only half — remediating them is flaw remediation, 3.14.1.)

    Can you show a clean scan history with full coverage? Get a vulnerability-management evidence map →

    Related: 3.14.2 Malicious Code · All control pages · Calculate your SPRS score

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.