DKDavid Koran& Associates
Home The CMMC Guide Part III · Security Assessment CA.L2-3.12.3
The CMMC Guide · Security Assessment Family

CA.L2-3.12.3  Monitor Security Controls

Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Family
Security AssessmentCA, 4 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
OnePer NIST SP 800-171A

1Overview

CA.L2-3.12.3 is the family's second five-point requirement and it makes control oversight continuous. It requires that security controls be monitored on an ongoing basis to ensure their continued effectiveness, so that controls are watched between assessments rather than only checked at intervals. It is a five-point requirement that cannot be deferred on a plan of action.

Periodic assessment verifies controls at points in time, but effectiveness can lapse between those points, as configurations drift, systems change, and controls quietly stop working. This control requires ongoing monitoring of security controls to ensure their continued effectiveness, so the program has continuous awareness of whether its controls are still doing their job. It complements the periodic assessment of the family's first control by covering the intervals between assessments. Its five-point weight reflects that a control that lapses unnoticed is as good as absent until the next check.

The requirement · NIST SP 800-171 Rev 2, 3.12.3

Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

The requirement is ongoing monitoring of security controls for continued effectiveness. In practice this means continuous or frequent oversight, often through automated monitoring, alerting, and review, that surfaces when a control is failing or has drifted rather than waiting for a scheduled assessment. The single assessment objective is that controls are monitored on an ongoing basis to ensure they remain effective.

2The Assessment Objective

NIST SP 800-171A frames 3.12.3 as a single objective: monitor controls on an ongoing basis for continued effectiveness.

Security controls are monitored on an ongoing basis to ensure the continued effectiveness of the controls. Controls are watched continuously, not only at intervals.

MeetsControls are monitored on an ongoing basis, so lapses in effectiveness are surfaced between assessments.
FailsControls are only checked at periodic assessments, with no monitoring in between.

The single objective is ongoing monitoring for continued effectiveness. The common failure is relying solely on periodic assessment, so a control that lapses between checks goes unnoticed. The assessor looks for continuous or frequent monitoring that surfaces control failures as they occur.

3Failure Patterns

The failures are about controls watched only at intervals.

Point-in-time checks only

Relying only on periodic assessment leaves the intervals between unmonitored, so a control that fails after an assessment goes unnoticed until the next one. Ongoing monitoring covers those intervals.

Monitoring not reviewed

Monitoring that generates data or alerts no one reviews does not surface lapses. The monitoring has to be acted on to ensure continued effectiveness.

Partial coverage

Monitoring some controls while leaving others watched only at assessment leaves gaps. Ongoing monitoring should cover the controls whose continued effectiveness matters.

The common root
This control fails when oversight is treated as an event rather than a state. Assessments are snapshots, and controls drift and fail between them, so a program that only checks periodically is blind in the intervals. Ongoing monitoring is what makes control effectiveness a continuously known quantity.

4Ownership

This is a security and IT-owned control tied to continuous monitoring.

RoleResponsibility for this control
IT and securityMonitors security controls on an ongoing basis and responds to lapses. Owns the monitoring evidence.
Security or compliance leadConfirms monitoring covers the relevant controls and is acted on.
Program leadReviews monitoring output and retains the records.
See also: This control complements the periodic assessment of CA.L2-3.12.1 and draws on the monitoring practices of the audit and accountability and system and information integrity families.

5Tooling

The control is delivered by continuous or frequent monitoring of control effectiveness.

ObjectiveToolingWhat it provides
monitorAutomated monitoring and alertingOngoing awareness of control status.
respondReview and response to monitoringAction on lapses to ensure continued effectiveness.

The caveat is that monitoring has to be ongoing and acted on, covering the controls that matter. Monitoring data no one reviews, or coverage limited to a few controls, does not ensure continued effectiveness. The assessor examines whether controls are monitored on an ongoing basis, so the monitoring has to be continuous and responsive.

6Evidence

The satisfied version of 3.12.3 shows controls monitored continuously.

EvidenceWhat it demonstrates
Monitoring configurationThe objective. Controls monitored on an ongoing basis.
Monitoring review and response recordsThe objective. Lapses surfaced and acted on.

The evidence should show security controls monitored on an ongoing basis and the monitoring reviewed and acted on. The monitoring configuration together with the review records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

Between assessments, a lapsed control is a blind spot

Controls drift and fail between periodic checks, so this five-point control asks for ongoing monitoring that surfaces lapses as they happen. Building continuous control monitoring that is actually reviewed is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.12.3. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.3 among the five-point basic security requirements. ecfr.gov
← Previous in Security Assessment
CA.L2-3.12.2 · Plans of Action
Next in Security Assessment →
CA.L2-3.12.4 · System Security Plan
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CA.L2-3.12.3 · Edition 2026.1 · Last reviewed July 12, 2026