CMMC ANSWER ENGINE

What does CMMC require for vulnerability scanning and patching?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-16
Quick answer. Three NIST 800-171 practices interact: RA.L2-3.11.2 (periodic scans plus scans when new vulnerabilities are identified), RA.L2-3.11.3 (remediation per risk assessment), and SI.L2-3.14.1 (correct system flaws in a timely manner). The rule does not prescribe a scan cadence or a patch timeline. The OSA picks them, documents them in the SSP and procedures, and the assessor compares operational evidence to what the SSP says.

Vulnerability management is one of the most operationally-loaded CMMC topics because three practices interact and the OSA defines the cadence parameters.

The three governing practices

PracticeRequirement
RA.L2-3.11.2Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
RA.L2-3.11.3Remediate vulnerabilities in accordance with risk assessments.
SI.L2-3.14.1Identify, report, and correct information and information system flaws in a timely manner.

Scan frequency is OSA-defined

"Periodically" in 3.11.2 is OSA-defined. The OSA's risk-based policy sets the cadence and the SSP documents it. Common patterns range from continuous (CSPM tools, EDR vulnerability assessment) to monthly (traditional vulnerability scanners). The right cadence depends on the assets, the criticality of the data, and the OSA's risk tolerance. The rule sets no minimum.

What the assessor evaluates

  • The OSA's documented scan cadence (in SSP, in configuration or vulnerability management procedure).
  • Evidence that scans run at the documented cadence (scan reports with dates).
  • Evidence of scans triggered by new vulnerability disclosures (for example, CVE announcements that prompted ad-hoc scans).
  • Evidence of remediation actions tied to scan findings.
  • The risk-assessment basis for prioritizing remediation (3.11.3).
  • The defined timeliness for flaw correction (3.14.1) and evidence the operations meet that timeline.

Tools and coverage

Common patterns:

  • Authenticated network scans. Nessus, Qualys, Rapid7. Privileged credentials let the scanner see installed software, missing patches, and configuration weaknesses.
  • Endpoint vulnerability assessment integrated with EDR. Defender Vulnerability Management, CrowdStrike Spotlight. Continuous, agent-based.
  • Container and image scanning for any in-scope containerized workloads.
  • Cloud Security Posture Management (CSPM) for cloud configuration vulnerabilities.

Coverage must include all in-scope assets (CUI Assets, SPAs, and Specialized Assets where applicable). Assets the scanner cannot reach are gaps the assessor will probe.

Patch and remediation linkage

3.11.3 (remediate per risk assessment) and 3.14.1 (correct flaws in a timely manner) require the OSA to tie scan output to remediation action. The patch management procedure should describe:

  • How vulnerabilities and missing patches are tracked from discovery to closure.
  • The risk-based prioritization (criticality and exposure inform the timeline).
  • The timeliness target (OSA-defined) for each criticality tier.
  • The exception process for vulnerabilities that cannot be remediated.

Common errors

  • SSP says 'monthly' but scans actually run quarterly. The assessor checks operational evidence against the documented cadence.
  • Unauthenticated scans only. Authenticated scans see far more. Missing-patch lists from external scans alone are inadequate for 3.11.2.
  • Scan reports with no remediation linkage. Reports without a remediation tracker do not satisfy 3.11.3.
  • Coverage gaps. Assets the scanner cannot reach (subnetted environments, isolated dev networks) are vulnerabilities of their own.
  • Specialized Assets unscanned. Even though Specialized Assets receive different assessment treatment, the OSA's risk-based policy must address how they are managed for vulnerabilities. Ignoring them entirely is a finding.

Sources

  • NIST SP 800-171 Rev 2, § 3.11.2, § 3.11.3, § 3.14.1. link
  • NIST SP 800-171A, Assessment Objectives. link
Rulebook version: NIST SP 800-171 Rev 2; NIST SP 800-171A

Stand up vulnerability management that holds at assessment.

The CMMC Compliance Engine includes the POL-VM-01_Vulnerability_Management_Policy, the PRO-VM-01_Vulnerability_Scanning_Procedure, the PRO-VM-02_Patch_Management_Procedure, and the VM-TRK-01_Vulnerability_Tracker for tying scan findings to remediation action and the SSP-defined cadence.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.