DKDavid Koran& Associates
Home The CMMC Guide Part III · Security Assessment CA.L2-3.12.1
The CMMC Guide · Security Assessment Family

CA.L2-3.12.1  Assess Security Controls

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

Family
Security AssessmentCA, 4 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

CA.L2-3.12.1 opens the Security Assessment family with the requirement to check that controls actually work. It requires that the organization periodically assess the security controls in its systems to determine whether they are effective in their application, so that the program is verified rather than assumed. It is a five-point requirement that cannot be deferred on a plan of action.

Implementing a control and knowing it works are two different things. Controls can be misconfigured, drift out of effectiveness, or fail to do what was intended, and a program that never checks its own controls does not know which of them are actually protecting anything. This control requires periodic assessment of the security controls to determine their effectiveness in application, on a defined frequency, so the organization has current evidence that its controls do what they are supposed to. Its five-point weight reflects that unverified controls may be protecting nothing.

The requirement · NIST SP 800-171 Rev 2, 3.12.1

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

The requirement pairs a defined frequency with the assessment itself. The two assessment objectives are that the frequency of control assessments is defined, and that controls are assessed at that frequency to determine effectiveness in their application. Assessing effectiveness in application means checking not just that a control exists but that it works as intended in the actual environment. Doing so periodically keeps the verification current as the environment changes.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.12.1 into two objectives: define the frequency and assess controls at that frequency for effectiveness.

[a]

The frequency of security control assessments is defined. How often controls are assessed is set.

MeetsA frequency for assessing security controls is defined.
FailsNo frequency for control assessment is defined.
[b]

Security controls are assessed with the defined frequency to determine if the controls are effective in their application. Controls are checked for effectiveness on schedule.

MeetsControls are assessed at the defined frequency to determine effectiveness in application.
FailsControls are never assessed for effectiveness, or only once.

The two objectives are the frequency and the effectiveness assessment. The common gap is at objective [b], where controls are assumed effective because they were implemented, without any check that they still work. The assessor looks for a defined frequency and evidence of periodic effectiveness assessment.

3Failure Patterns

The failures are about controls assumed effective but never verified.

Controls assumed rather than checked

Treating a control as effective because it was implemented ignores misconfiguration and drift. Assessing effectiveness in application verifies the control actually works.

One-time or no assessment

Assessing controls once and never again lets effectiveness erode unseen. Periodic assessment at the defined frequency keeps the verification current.

No defined frequency

Without a defined frequency, control assessment has no cadence and tends to lapse. Defining the frequency anchors the periodic assessment.

The common root
This control fails when implementation is mistaken for effectiveness. A control that exists on paper or was set up once may be misconfigured or drifted, and without periodic assessment the organization cannot tell working controls from broken ones. Assessing effectiveness is what replaces assumption with evidence.

4Ownership

This is a security and compliance-owned control.

RoleResponsibility for this control
Security or compliance leadDefines the frequency and assesses controls for effectiveness in application. Owns the assessment records.
IT and system administratorSupports the assessment with the technical detail of how controls are applied.
Program leadConfirms assessment recurs at the defined frequency and retains the records.
See also: This control feeds the plans of action of CA.L2-3.12.2 and is complemented by the ongoing monitoring of CA.L2-3.12.3.

5Tooling

The control is delivered by a defined, recurring control assessment.

ObjectivesToolingWhat it provides
[a]Defined assessment frequencyA set cadence for control assessments.
[b]Control effectiveness assessmentVerification that controls work in their application, at that cadence.

The caveat is that the assessment has to check effectiveness in application, not mere existence, and recur on the defined frequency. A checklist that confirms controls are present without testing whether they work does not meet the objective. The assessor examines the frequency and the effectiveness assessment, so both objectives have to hold.

6Evidence

The satisfied version of 3.12.1 shows a defined frequency and recurring effectiveness assessments.

EvidenceWhat it demonstrates
Defined assessment frequencyObjective [a]. How often controls are assessed.
Control assessment recordsObjective [b]. Controls assessed for effectiveness at that cadence.

The evidence should show a defined frequency and control assessments performed at that cadence to determine effectiveness in application. The defined frequency together with the assessment records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

An implemented control is not necessarily a working one

Controls can be misconfigured or drift, so this five-point control asks for periodic assessment of whether they are effective in application. Building a real, recurring control assessment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.12.1[a] and 3.12.1[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.1 among the five-point basic security requirements. ecfr.gov
← Previous: Risk Assessment
RA.L2-3.11.3 · Remediate Vulnerabilities
Next in Security Assessment →
CA.L2-3.12.2 · Plans of Action
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CA.L2-3.12.1 · Edition 2026.1 · Last reviewed July 12, 2026