CMMC 3.11.2 (Vulnerability Scanning): Evidence Examples & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.11.2 · CMMC Practice: RA.L2-3.11.2 · Updated June 2026
Plain-English answer
3.11.2 requires you to scan for vulnerabilities in your systems and applications on a defined frequency, and again when new vulnerabilities affecting them are identified. Three things an assessor checks: you defined a cadence, you actually scan on it (systems and apps), and you scan on new-vulnerability events — not just once a year.
Who this applies to
Every organization seeking CMMC Level 2 for a CUI environment.
Why it matters
You can't fix what you don't find. Scanning is how known vulnerabilities surface before an adversary uses them. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).
Control lineage
- CMMC Practice: RA.L2-3.11.2
- NIST 800-171 Rev. 2: §3.11.2 — scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting them are identified.
- NIST 800-171A objectives: [a] the scan frequency is defined; [b] systems are scanned on that frequency; [c] applications are scanned on that frequency; [d] systems are scanned when new vulnerabilities are identified; [e] applications are scanned when new vulnerabilities are identified.
What the assessor will EXAMINE
- The vulnerability-management policy defining scan frequency for systems and applications.
- Scan reports over time showing the cadence is met (authenticated scans preferred).
- Coverage — that scans hit the in-scope assets, not a subset.
- Evidence of event-driven scans when major vulnerabilities emerged.
- SSP narrative for 3.11.2.
What the assessor will INTERVIEW & TEST
- Interview: "How often do you scan, what's covered, and what triggers an off-cycle scan?" — point to the policy + the scan history.
- Test: Review recent scan reports for cadence, coverage, and that they're authenticated (not just unauthenticated network scans).
- Test: Confirm a sampled in-scope asset appears in the scan results.
Evidence examples (produce these)
- Vulnerability-management policy with defined scan frequency.
- A series of dated scan reports (systems and applications) showing the cadence.
- Asset coverage proof — scan targets reconciled to your inventory.
- An example off-cycle scan tied to a new vulnerability.
- SSP section 3.11.2 referencing the above.
Common failure patterns
- Scanning happens but no defined frequency is documented — objective [a] fails.
- Only unauthenticated scans, which miss most host-level vulnerabilities.
- Systems scanned but applications aren't — objectives [c]/[e] fail.
- Coverage gaps — assets that never get scanned.
SPRS impact & POA&M
SPRS: 3.11.2 carries a weighted deduction (verify the exact value). POA&M: confirm 3.11.2's POA&M eligibility against current CMMC rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.11.2 when a scan frequency is defined and met for both systems and applications; scans are authenticated and cover the in-scope inventory; off-cycle scans run on new vulnerabilities; and the SSP matches the practice. (Finding vulnerabilities is only half — remediating them is flaw remediation, 3.14.1.)
Can you show a clean scan history with full coverage? Get a vulnerability-management evidence map →
Related: 3.14.2 Malicious Code · All control pages · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.