The fourteen families below contain all one hundred ten Level 2 requirements, each pinned to NIST SP 800-171 Rev 2, and every entry links to a full treatment of its assessment objectives, failure patterns, ownership, tooling, and evidence.
AC
AC.L2-3.1.1Limit system access to authorized users, processes, and devices
AC.L2-3.1.2Limit access to the transactions and functions users are permitted to execute
AC.L2-3.1.3Control the flow of CUI
AC.L2-3.1.4Separate the duties of individuals
AC.L2-3.1.5Employ least privilege
AC.L2-3.1.6Use non-privileged accounts for nonsecurity functions
AC.L2-3.1.7Prevent non-privileged users from executing privileged functions; audit them
AC.L2-3.1.8Limit unsuccessful logon attempts
AC.L2-3.1.9Provide privacy and security notices
AC.L2-3.1.10Session lock with pattern-hiding displays
AC.L2-3.1.11Terminate user sessions after a defined condition
AC.L2-3.1.12Monitor and control remote access sessions
AC.L2-3.1.13Cryptographic mechanisms for remote access sessions
AC.L2-3.1.14Route remote access through managed access control points
AC.L2-3.1.15Authorize remote execution of privileged commands
AC.L2-3.1.16Authorize wireless access before connection
AC.L2-3.1.17Protect wireless access with authentication and encryption
AC.L2-3.1.18Control connection of mobile devices
AC.L2-3.1.19Encrypt CUI on mobile devices and platforms
AC.L2-3.1.20Verify and control connections to external systems
AC.L2-3.1.21Limit use of portable storage devices on external systems
AC.L2-3.1.22Control CUI posted on publicly accessible systems
Access Control
22 requirementsAT
AT.L2-3.2.1Security awareness for all users
AT.L2-3.2.2Role-based security training
AT.L2-3.2.3Insider threat awareness training
Awareness and Training
3 requirementsAU
AU.L2-3.3.1Create and retain audit logs and records
AU.L2-3.3.2Trace actions to individual users
AU.L2-3.3.3Review and update logged events
AU.L2-3.3.4Alert on audit logging process failure
AU.L2-3.3.5Correlate audit review, analysis, and reporting
AU.L2-3.3.6Audit record reduction and report generation
AU.L2-3.3.7Authoritative time source for audit timestamps
AU.L2-3.3.8Protect audit information and tools
AU.L2-3.3.9Limit audit management to a privileged subset
Audit and Accountability
9 requirementsCM
CM.L2-3.4.1Establish baseline configurations and inventories
CM.L2-3.4.2Enforce security configuration settings
CM.L2-3.4.3Track, review, approve, and log changes
CM.L2-3.4.4Analyze the security impact of changes
CM.L2-3.4.5Access restrictions for changes
CM.L2-3.4.6Employ least functionality
CM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and services
CM.L2-3.4.8Deny-by-exception or permit-by-exception software policy
CM.L2-3.4.9Control and monitor user-installed software
Configuration Management
9 requirementsIA
IA.L2-3.5.1Identify users, processes, and devices
IA.L2-3.5.2Authenticate identities before granting access
IA.L2-3.5.3Multifactor authentication for local privileged and network access
IA.L2-3.5.4Replay-resistant authentication
IA.L2-3.5.5Prevent identifier reuse for a defined period
IA.L2-3.5.6Disable identifiers after a period of inactivity
IA.L2-3.5.7Enforce password complexity and change of characters
IA.L2-3.5.8Prohibit password reuse for a specified number of generations
IA.L2-3.5.9Temporary passwords changed to permanent on first use
IA.L2-3.5.10Store and transmit only cryptographically protected passwords
IA.L2-3.5.11Obscure authentication feedback
Identification and Authentication
11 requirementsIR
IR.L2-3.6.1Operational incident-handling capability
IR.L2-3.6.2Track, document, and report incidents
IR.L2-3.6.3Test the incident response capability
Incident Response
3 requirementsMA
MA.L2-3.7.1Perform system maintenance
MA.L2-3.7.2Controls on maintenance tools, techniques, mechanisms, and personnel
MA.L2-3.7.3Sanitize equipment removed for off-site maintenance
MA.L2-3.7.4Check media containing diagnostic and test programs
MA.L2-3.7.5Multifactor authentication for nonlocal maintenance; terminate sessions
MA.L2-3.7.6Supervise maintenance by personnel without required access
Maintenance
6 requirementsMP
MP.L2-3.8.1Physically protect media containing CUI
MP.L2-3.8.2Limit access to CUI on media to authorized users
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse
MP.L2-3.8.4Mark media with CUI markings and distribution limitations
MP.L2-3.8.5Control access to media during transport
MP.L2-3.8.6Cryptographic protection of media during transport
MP.L2-3.8.7Control the use of removable media
MP.L2-3.8.8Prohibit portable storage with no identifiable owner
MP.L2-3.8.9Protect the confidentiality of backup CUI at storage locations
Media Protection
9 requirementsPS
PS.L2-3.9.1Screen individuals prior to authorizing access
PS.L2-3.9.2Protect CUI during personnel actions such as terminations and transfers
Personnel Security
2 requirementsPE
PE.L2-3.10.1Limit physical access to authorized individuals
PE.L2-3.10.2Protect and monitor the physical facility and support infrastructure
PE.L2-3.10.3Escort visitors and monitor visitor activity
PE.L2-3.10.4Maintain physical access audit logs
PE.L2-3.10.5Control and manage physical access devices
PE.L2-3.10.6Safeguarding measures for CUI at alternate work sites
Physical Protection
6 requirementsRA
RA.L2-3.11.1Periodically assess risk to operations, assets, and individuals
RA.L2-3.11.2Scan for vulnerabilities periodically and when new ones are identified
RA.L2-3.11.3Remediate vulnerabilities in accordance with risk assessments
Risk Assessment
3 requirementsCA
CA.L2-3.12.1Periodically assess security controls for effectiveness
CA.L2-3.12.2Develop and implement plans of action (POA&M)
CA.L2-3.12.3Monitor security controls on an ongoing basis
CA.L2-3.12.4Develop, document, and update the System Security Plan
Security Assessment
4 requirementsSC
SC.L2-3.13.1Monitor, control, and protect communications at system boundaries
SC.L2-3.13.2Architectural designs and engineering principles that promote security
SC.L2-3.13.3Separate user functionality from system management functionality
SC.L2-3.13.4Prevent unauthorized information transfer via shared system resources
SC.L2-3.13.5Implement subnetworks for publicly accessible components
SC.L2-3.13.6Deny network traffic by default, allow by exception
SC.L2-3.13.7Prevent split tunneling for remote devices
SC.L2-3.13.8Cryptographic mechanisms to protect CUI in transit
SC.L2-3.13.9Terminate network connections at session end or after inactivity
SC.L2-3.13.10Establish and manage cryptographic keys
SC.L2-3.13.11Employ FIPS-validated cryptography to protect CUI
SC.L2-3.13.12Prohibit remote activation of collaborative computing devices
SC.L2-3.13.13Control and monitor the use of mobile code
SC.L2-3.13.14Control and monitor Voice over Internet Protocol
SC.L2-3.13.15Protect the authenticity of communications sessions
SC.L2-3.13.16Protect the confidentiality of CUI at rest
System and Communications Protection
16 requirementsSI
SI.L2-3.14.1Identify, report, and correct system flaws in a timely manner
SI.L2-3.14.2Provide protection from malicious code at designated locations
SI.L2-3.14.3Monitor security alerts and advisories and take action
SI.L2-3.14.4Update malicious code protection mechanisms
SI.L2-3.14.5Periodic and real-time scans of systems and files
SI.L2-3.14.6Monitor systems and communications traffic for attacks and indicators
SI.L2-3.14.7Identify unauthorized use of systems
System and Information Integrity
7 requirementsPart III: The 110 Level 2 Controls · Edition 2026.1 · Last reviewed July 12, 2026