DKDavid Koran& Associates
Home The CMMC Guide Part III · Configuration Management CM.L2-3.4.7
The CMMC Guide · Configuration Management Family

CM.L2-3.4.7  Nonessential Functionality

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

Family
Configuration ManagementCM, 9 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FifteenPer NIST SP 800-171A

1Overview

CM.L2-3.4.7 is the most granular expression of least functionality, and the largest requirement in the guide by objective count. It requires that the organization restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services, so that each of those five categories is reduced to what the work actually needs. It is a five-point requirement that cannot be deferred on a plan of action.

Where 3.4.6 sets the principle of least functionality, this control applies it concretely across five specific categories. Every program installed, function enabled, port open, protocol allowed, and service running is a potential path for an attacker, and most systems carry many of each that no one needs. The control asks the organization to decide, for each category, what is essential and what is not, and to restrict, disable, or prevent the nonessential. Its fifteen assessment objectives come from applying three steps, define essential, define nonessential, and restrict the nonessential, to each of the five categories.

The requirement · NIST SP 800-171 Rev 2, 3.4.7

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

The five categories are worth naming because each is a distinct surface: programs are installed applications, functions are capabilities within systems and applications, ports are network endpoints, protocols are the languages of communication, and services are background processes. For each, the organization identifies what is essential and what is not, and then restricts, disables, or prevents the nonessential. The fifteen objectives are simply this pattern applied five times, and the five-point weight reflects how much attack surface these categories carry when left unmanaged.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.4.7 into fifteen objectives, applying three steps, define essential, define nonessential, and restrict, disable, or prevent, to each of programs, functions, ports, protocols, and services.

[a]

Essential programs are defined. The organization has identified the programs that are needed.

MeetsA defined set of essential programs for each system.
FailsEssential programs are not identified.
[b]

The use of nonessential programs is defined. The organization has identified the programs that are not needed.

MeetsNonessential programs are identified as candidates for removal.
FailsNonessential programs are never identified.
[c]

The use of nonessential programs is restricted, disabled, or prevented. Those nonessential programs are actually removed or blocked.

MeetsNonessential programs are removed, disabled, or prevented from running.
FailsNonessential programs remain installed and usable.
[d]

Essential functions are defined. The organization has identified the functions that are needed.

MeetsA defined set of essential system functions.
FailsEssential functions are not identified.
[e]

The use of nonessential functions is defined. The organization has identified the functions that are not needed.

MeetsNonessential functions are identified.
FailsNonessential functions are never identified.
[f]

The use of nonessential functions is restricted, disabled, or prevented. Those nonessential functions are actually disabled or blocked.

MeetsNonessential functions are disabled or prevented.
FailsNonessential functions remain enabled.
[g]

Essential ports are defined. The organization has identified the network ports that are needed.

MeetsA defined set of essential ports.
FailsEssential ports are not identified.
[h]

The use of nonessential ports is defined. The organization has identified the ports that are not needed.

MeetsNonessential ports are identified.
FailsNonessential ports are never identified.
[i]

The use of nonessential ports is restricted, disabled, or prevented. Those nonessential ports are actually closed or blocked.

MeetsNonessential ports are closed or blocked.
FailsNonessential ports remain open.
[j]

Essential protocols are defined. The organization has identified the protocols that are needed.

MeetsA defined set of essential protocols.
FailsEssential protocols are not identified.
[k]

The use of nonessential protocols is defined. The organization has identified the protocols that are not needed.

MeetsNonessential protocols are identified.
FailsNonessential protocols are never identified.
[l]

The use of nonessential protocols is restricted, disabled, or prevented. Those nonessential protocols are actually disabled or blocked.

MeetsNonessential protocols are disabled or blocked.
FailsNonessential protocols remain in use.
[m]

Essential services are defined. The organization has identified the services that are needed.

MeetsA defined set of essential services.
FailsEssential services are not identified.
[n]

The use of nonessential services is defined. The organization has identified the services that are not needed.

MeetsNonessential services are identified.
FailsNonessential services are never identified.
[o]

The use of nonessential services is restricted, disabled, or prevented. Those nonessential services are actually disabled or blocked.

MeetsNonessential services are disabled or blocked.
FailsNonessential services remain running.

The fifteen objectives are the same three-step pattern across five categories. The common gap is at the restriction objectives, [c], [f], [i], [l], and [o], where essential and nonessential are identified but the nonessential is not actually restricted, so open ports, running services, and installed programs that no one needs remain in place. The assessor looks for the nonessential in each category to be genuinely restricted, disabled, or prevented.

3Failure Patterns

The failures are about unmanaged categories and identification without restriction.

Open ports and running services no one needs

Systems commonly run services and expose ports that no one uses but an attacker can reach. Identifying and closing or disabling the nonessential ones removes a large part of the network attack surface, and leaving them fails the restriction objectives.

Legacy protocols left enabled

Outdated or insecure protocols left enabled for convenience are a frequent weakness, since they are often the easiest thing for an attacker to exploit. Disabling the nonessential protocols is part of the control.

Extra programs and functions installed

Systems loaded with applications and features beyond what the work needs carry programs and functions an attacker can use. Removing or disabling the nonessential ones reduces that surface.

Identified but not restricted

Where the nonessential items in a category are identified but never actually restricted, disabled, or prevented, the restriction objective for that category is unmet. Identification has to lead to action across all five categories.

The common root
This control fails category by category when identification is not followed by restriction. It is common to know that certain ports, protocols, or services are unneeded and still leave them running, and every one left in place is a path the control was meant to close. The work is restricting the nonessential, not merely listing it.

4Ownership

This is an IT-owned technical control, and its work is methodically reducing each of the five categories to the essential.

RoleResponsibility for this control
IT and system administratorIdentifies essential and nonessential programs, functions, ports, protocols, and services, and restricts, disables, or prevents the nonessential. Owns the technical evidence.
Security or compliance leadConfirms each category is reduced to the essential and that restriction is actually applied.
Program leadIncludes the five categories in periodic review as new items appear, and retains the evidence.
See also: This control is the granular application of the least functionality of CM.L2-3.4.6, works with the security settings of CM.L2-3.4.2, and connects to the system and communications protection family for ports and protocols.

5Tooling

The control is delivered by hardening, host and network configuration, and the tools that reveal what is actually running and open.

CategoriesToolingWhat it provides
Programs, functionsSoftware removal, feature and role management, hardening baselinesReduction of installed programs and enabled functions to the essential.
Ports, protocolsHost and network firewalls, protocol configurationClosing nonessential ports and disabling nonessential protocols.
ServicesService configuration, disabling unneeded servicesStopping and disabling nonessential background services.
DiscoveryPort and service scanning, configuration reviewVisibility of what is actually open and running, so the nonessential can be found.

The caveat is that all five categories have to be addressed, and identification has to lead to restriction. Discovery reveals what is open and running, but the control is met only when the nonessential is actually closed, disabled, or removed across programs, functions, ports, protocols, and services. The assessor examines each category, so a reduction that covers some but not all leaves the control incomplete.

6Evidence

The satisfied version of 3.4.7 shows each category reduced to the essential.

EvidenceWhat it demonstrates
Essential and nonessential definitionsObjectives [a], [b], [d], [e], [g], [h], [j], [k], [m], [n]. What is essential and nonessential in each category.
Firewall and port configurationObjective [i]. Nonessential ports closed or blocked.
Service and protocol configurationObjectives [f], [l], [o]. Nonessential functions, protocols, and services disabled.
Installed software listObjective [c]. Nonessential programs removed or prevented.

The evidence should show the nonessential restricted across all five categories, backed by the definitions of what is essential in each. Configuration and scans demonstrating closed ports, disabled services and protocols, and removed programs, together with the definitions, are the clearest demonstration, and because this control cannot sit on a plan of action, the restriction has to be real at the time of assessment.

Five surfaces, each reduced to what the work needs

Open ports, running services, legacy protocols, and unused programs and functions each give an attacker a path, and this five-point control asks for the nonessential in every category to be restricted. Methodically reducing programs, functions, ports, protocols, and services to the essential is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.7. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.7[a] through 3.4.7[o]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing CM.L2-3.4.7 among the five-point derived security requirements. ecfr.gov
← Previous in Configuration Management
CM.L2-3.4.6 · Least Functionality
Next in Configuration Management →
CM.L2-3.4.8 · Application Allow and Deny Listing
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CM.L2-3.4.7 · Edition 2026.1 · Last reviewed July 12, 2026