Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
SECURITY ASSESSMENT

CMMC Security Assessment and Continuous Monitoring: Beyond the POA&M (3.12.x)

CMMC 3.12.x requires recurring assessment, POA&M management, ongoing control monitoring, and an accurate SSP—not just a remediation list.

Papercraft SSP binder beside a monitoring dial and a recurring loop icon, illustrating continuous assessment and monitoring beyond a static POA&M list.

The 3.12 family is the management loop around the other controls: assess them, correct deficiencies, monitor them over time, and maintain a system security plan that accurately describes the environment and implementation.

For most small defense contractors, the requirement is only as real as the evidence behind it — so the useful test is whether it can be traced to a specific system inside the FCI/CUI boundary, an owner, and a current artifact.

The rule in plain English

3.12.1 calls for periodic assessment, 3.12.2 for plans of action, 3.12.3 for ongoing monitoring, and 3.12.4 for the SSP. These are related but not interchangeable.

A polished SSP with no recurring validation can drift out of compliance; a pile of tickets with no current SSP can be equally difficult to assess.

How to implement it without overbuilding

Build a control calendar identifying which evidence or control is reviewed monthly, quarterly, annually, or after defined events. Choose cadence based on the control and risk rather than forcing one interval onto everything.

Feed findings into remediation where appropriate, but keep CMMC POA&M eligibility rules separate from the broader internal remediation backlog.

What evidence to keep

Keep internal-assessment records, monitoring reports, POA&M entries, closure evidence, SSP revisions, and approvals.

Show that the SSP changes when architecture, scope, providers, or implementation changes.

Where teams get into trouble

The biggest mistake is treating assessment preparation as a one-time document sprint. Another is allowing old POA&M items to remain open without owners, dates, or credible closure evidence.

Small-contractor walkthrough

The SSP was updated during assessment preparation, but firewall rules, user access, and provider responsibilities keep changing afterward. A control-monitoring calendar gives owners a way to detect drift and feed real deficiencies into remediation rather than waiting for the next certification cycle.

For readiness, choose a normal business example rather than a perfect demonstration environment.

That forces the organization to account for exceptions and handoffs between people, systems, and providers—the places where otherwise reasonable control designs most often break.

  • Schedule internal control checks.
  • Tie findings to remediation.
  • Update SSP after changes.
  • Track POA&M eligibility separately.

Decisions to document before assessment

Before marking this topic ready, make four decisions explicit: schedule internal control checks; tie findings to remediation; update ssp after changes; and track poa&m eligibility separately. Assign an owner and an evidence location to each decision.

Manual deep review

Treat 3.12.1 through 3.12.4 as one management loop: assess controls, identify deficiencies, remediate, monitor continuing effectiveness, update the SSP, and assess again. A polished SSP with no recurring validation breaks the loop; a remediation tracker with a stale SSP breaks it too.

Build a control-health calendar using evidence that naturally drifts. Identity groups, privileged access, endpoint coverage, vulnerability findings, backups, firewall changes, training, physical access, and provider relationships do not need the same review frequency. For each area, record owner, evidence source, expected condition, cadence or trigger, and action if the condition is not met.

Continuous monitoring in 3.12.3 is broader than 24/7 SOC monitoring. Existing operations such as access reviews, vulnerability reports, patch/change tickets, backup tests, configuration reports, training rosters, incident exercises, and provider reviews can all demonstrate continued control effectiveness when they are owned and acted upon.

Keep ordinary internal remediation separate from formal CMMC conditional-status POA&M eligibility. An internal backlog can contain any weakness; CMMC POA&M rules have scoring and eligibility limits. Record requirement/objective, root cause, affected systems, owner, target action, closure evidence, and any SSP update for each finding.

Before assessment, sample controls across identity, configuration, logging, vulnerability management, physical security, training, remote access, backup, and incident response. Use examine, interview, and test-style validation. Pick one recently changed control and trace it through monitoring, finding, remediation, closure, and SSP update to prove the loop closes.

Turn the control-health register into an operating review

Once the monitoring calendar exists, use it in a short recurring review with the owners who can actually change the environment. The review should answer: which evidence sources are healthy, which controls changed, which findings remain open, which exceptions are expiring, and which SSP statements are now stale. This keeps 3.12 from becoming a compliance-team spreadsheet disconnected from IT operations.

Use trend evidence, not only point-in-time screenshots. For example, review whether endpoint coverage dropped after a device migration, whether privileged groups grew after a project launch, whether backup test failures recur, or whether vulnerability age is increasing. A control can technically exist while its effectiveness is degrading, and 3.12.3 is designed to catch that condition before the next formal assessment.

Close the loop after material changes

When a cloud tenant, identity provider, firewall architecture, MSP service, or CUI workflow changes, identify the 3.12 records affected: control-monitoring plan, internal assessment result, open remediation, and SSP description. Assign one owner to confirm the new implementation is operating and that evidence can still be retrieved.

Keep one before-and-after example for assessment. A reviewer should be able to see the original condition, approved change, post-change validation, updated SSP language, and evidence that ongoing monitoring now watches the new state. That is stronger than a policy saying the organization 'continuously monitors controls' without showing how change is absorbed.

Final operating detail

Assign a backup owner for every recurring control-health check. Small contractors often have one administrator who knows how to retrieve a log, run a review, or explain an exception; if that person is unavailable during assessment or an incident, the monitoring process can fail even though the technology is healthy. Record the backup evidence path and rehearse it once.

Continuity check

Document who performs the review when the primary control owner is unavailable.

WORKING CHECKLIST

Before assessment week

  • Schedule internal control checks.
  • Tie findings to remediation.
  • Update SSP after changes.
  • Track POA&M eligibility separately.
  • Retain closure evidence.
  • Review scope before assessment cycles.

Common questions

Is continuous monitoring the same as a 24/7 SOC?

Not necessarily. In 3.12.3 it is broader ongoing monitoring of security controls for continued effectiveness.

Does every finding go on a CMMC POA&M?

No. CMMC has specific rules for what can be deferred.

How often should the SSP be updated?

Whenever relevant facts change and often enough to remain accurate.

Can internal assessment evidence help?

Yes. It shows how the organization validates controls, although a formal assessor still applies the required methodology.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.