DKDavid Koran& Associates
Home The CMMC Guide Part III · Incident Response IR.L2-3.6.2
The CMMC Guide · Incident Response Family

IR.L2-3.6.2  Incident Tracking and Reporting

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

Family
Incident ResponseIR, 3 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
SixPer NIST SP 800-171A

1Overview

IR.L2-3.6.2 is the family's second five-point requirement and it governs the record and reach of incidents. It requires that the organization track, document, and report incidents to designated officials and authorities, both internal and external, so that incidents are recorded and the right people, inside and outside the organization, are told. It is a five-point requirement that cannot be deferred on a plan of action.

Handling an incident is not enough on its own; it has to be recorded and reported. Tracking and documenting incidents builds the history needed to learn from them and to demonstrate that response happened, and reporting ensures that the people who need to know, internal leadership and external authorities such as the government customer, are notified. For defense contractors, external reporting obligations can carry contractual and legal weight, so knowing who must be told and actually telling them is central. The five-point weight reflects that unreported incidents leave both the organization and its customer blind.

The requirement · NIST SP 800-171 Rev 2, 3.6.2

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

The requirement has three actions and two audiences. Tracking and documenting create the record of incidents; reporting delivers that information to designated recipients. The recipients fall into two groups: internal officials, such as organizational leadership, and external authorities, such as the government customer or relevant agencies. The organization has to identify who those recipients are in advance and actually notify them when an incident occurs, so that reporting is defined and executed rather than improvised in the moment.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.6.2 into six objectives: track and document incidents, identify internal and external recipients, and notify each.

[a]

Incidents are tracked. The organization maintains a record of incidents.

MeetsIncidents are tracked in a record such as an incident log or ticketing system.
FailsIncidents are handled without being tracked.
[b]

Incidents are documented. Each incident is recorded with its details.

MeetsIncidents are documented with what happened, the response, and the outcome.
FailsIncidents leave no documentation.
[c]

Authorities to whom incidents are to be reported are identified. The external recipients are known in advance.

MeetsExternal authorities, such as the government customer, are identified as reporting recipients.
FailsNo external authorities are identified.
[d]

Organizational officials to whom incidents are to be reported are identified. The internal recipients are known in advance.

MeetsInternal officials, such as leadership, are identified as reporting recipients.
FailsNo internal officials are identified.
[e]

Identified authorities are notified of incidents. External recipients are actually told.

MeetsIncidents are reported to the identified external authorities as required.
FailsIncidents are not reported externally despite the obligation.
[f]

Identified organizational officials are notified of incidents. Internal recipients are actually told.

MeetsIncidents are reported to the identified internal officials.
FailsLeadership is not informed of incidents.

The six objectives cover tracking, documenting, identifying both audiences, and notifying each. The common gap is at objectives [c] and [e], the external side, where the organization has not identified who to report to externally or does not actually report, which for defense contractors can carry contractual consequences. The assessor looks for tracking, documentation, and reporting that reaches both audiences.

3Failure Patterns

The failures are about incidents that go unrecorded or unreported, especially externally.

No external reporting path

Where the organization has not identified who to report incidents to externally, or does not report when required, it fails the external objectives and may breach a contractual obligation. Identifying the external authorities and reporting to them is essential.

Incidents handled but not documented

An incident resolved informally with no record leaves nothing to learn from or to demonstrate, failing the documentation objective. Documenting each incident builds the history the organization needs.

Leadership left uninformed

Where internal officials are not notified, decision-makers are blind to incidents affecting the organization. Internal reporting has to reach the identified officials.

Recipients not identified in advance

Without identifying internal and external recipients ahead of time, reporting is improvised under pressure and may miss required parties. The recipients have to be identified before an incident, not decided during one.

The common root
This control fails most often on the external side. Internal handling is natural, but identifying the external authorities and meeting reporting obligations is easy to overlook until an incident makes it urgent, and for a defense contractor an unreported incident can carry consequences beyond the incident itself. Knowing who to tell and telling them is the core of the control.

4Ownership

This is a security-owned control with a reporting dimension that often involves leadership and, for external obligations, counsel.

RoleResponsibility for this control
Security or compliance leadTracks and documents incidents, identifies internal and external recipients, and ensures reporting occurs. Owns the incident records.
LeadershipReceives internal incident reports and supports meeting external obligations.
CounselAdvises on external reporting obligations, which for defense contractors can carry contractual and legal weight.
See also: This control records and reports the incidents handled under IR.L2-3.6.1 and draws on the audit records of the audit and accountability family for incident detail.

5Tooling

The control is delivered by incident tracking and documentation and by defined reporting to identified recipients.

ObjectivesToolingWhat it provides
[a], [b]Incident log or ticketing systemTracking and documentation of incidents.
[c], [d]Defined reporting recipients, internal and externalIdentification of who must be notified.
[e], [f]Reporting procedures and recordsActual notification of the identified recipients.

The caveat is that identifying recipients is not the same as notifying them, and the external obligation is the one most often missed. Reporting has to actually reach both the internal officials and the external authorities, with records to show it. The assessor examines tracking, documentation, and reporting to both audiences, so the external path in particular has to be real.

6Evidence

The satisfied version of 3.6.2 shows tracked, documented incidents reported to both audiences.

EvidenceWhat it demonstrates
Incident log or recordsObjectives [a], [b]. Incidents tracked and documented.
Identified recipientsObjectives [c], [d]. Internal officials and external authorities identified.
Reporting recordsObjectives [e], [f]. Notification of the identified recipients.

The evidence should show incidents tracked and documented, with reporting reaching both identified internal officials and external authorities. The incident records together with identified recipients and reporting records are the clearest demonstration, and because this control cannot sit on a plan of action, the tracking and reporting have to be real at the time of assessment.

An unreported incident leaves everyone blind

Handling an incident is not enough if it is never recorded or the right people, inside and outside, are never told, and for a defense contractor the external obligation can carry real consequences. Building incident tracking and a reporting path that reaches both audiences is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.6.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.6.2[a] through 3.6.2[f]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing IR.L2-3.6.2 among the five-point basic security requirements. ecfr.gov
← Previous in Incident Response
IR.L2-3.6.1 · Incident Handling
Next in Incident Response →
IR.L2-3.6.3 · Incident Response Testing
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IR.L2-3.6.2 · Edition 2026.1 · Last reviewed July 12, 2026