DKDavid Koran& Associates
Home The CMMC Guide Part III · Incident Response IR.L2-3.6.3
The CMMC Guide · Incident Response Family

IR.L2-3.6.3  Incident Response Testing

Test the organizational incident response capability.

Family
Incident ResponseIR, 3 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

IR.L2-3.6.3 closes the Incident Response family by proving the capability works. It requires that the organization test its incident response capability, so that the plan built under 3.6.1 is exercised and its gaps found before a real incident finds them. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

A response capability that has never been tested is a set of assumptions, and incidents have a way of exposing the assumptions that do not hold. Testing, through exercises such as tabletop scenarios or more involved drills, reveals where roles are unclear, procedures do not fit reality, or resources are missing, while there is still time to fix them. This control asks the organization to test its incident response capability, turning a plan that looks good on paper into one that has been shown to work.

The requirement · NIST SP 800-171 Rev 2, 3.6.3

Test the organizational incident response capability.

The requirement is brief: test the capability. The form of the test can vary, from a tabletop walkthrough of a scenario to a fuller exercise, and what matters is that the capability is actually exercised so its readiness is confirmed and its gaps surfaced. Testing is what connects the plan of 3.6.1 to reality, and it is most useful when its findings feed back into improving the capability.

2The Assessment Objective

NIST SP 800-171A frames 3.6.3 as a single objective: test the incident response capability.

The incident response capability is tested. The organization exercises its incident response capability.

MeetsThe capability is tested, for example through a tabletop exercise, with the test recorded.
FailsThe capability is never tested, so its readiness is unknown.

The single objective is testing the capability. The common failure is a plan that has never been exercised, so no one knows whether it would work. The assessor looks for evidence that the capability has been tested.

3Failure Patterns

The failures are about untested plans and tests that lead nowhere.

A plan never exercised

An incident response plan that has never been tested is a set of untested assumptions, and its gaps surface only during a real incident. Exercising it, even as a tabletop, is what the control requires.

No record of testing

A test conducted informally with nothing recorded cannot be demonstrated. Documenting the test shows it occurred and captures what it found.

Findings that go nowhere

A test that surfaces gaps but never leads to improvement wastes its value. The most useful testing feeds its findings back into the capability, though the control's core requirement is that the test happen.

The common root
This control fails when the capability is assumed rather than proven. A plan can look complete and still fall apart under the pressure of a real incident, and testing is what reveals the difference while there is still time to fix it. Exercising the capability is what turns a plan into readiness.

4Ownership

This is a security-owned control, exercised with the people who would respond to a real incident.

RoleResponsibility for this control
Security or compliance leadPlans and conducts the test of the incident response capability and records it. Owns the test evidence.
IT and respondersParticipate in the test as they would in a real incident, exercising their roles.
LeadershipSupports testing and acts on findings that call for resources or decisions.
See also: This control exercises the capability established under IR.L2-3.6.1 and helps confirm the reporting paths of IR.L2-3.6.2.

5Tooling

The control is delivered by incident response exercises and their records.

ObjectiveToolingWhat it provides
testTabletop exercises, response drillsExercise of the incident response capability.
recordTest records and after-action notesDocumentation that the test occurred and what it found.

The caveat is that the test has to actually exercise the capability and be recorded. A tabletop that walks through a realistic scenario satisfies the control when documented, while an untested plan does not. The assessor examines evidence of testing, so a recorded exercise is what demonstrates the control.

6Evidence

The satisfied version of 3.6.3 shows the capability tested and recorded.

EvidenceWhat it demonstrates
Test or exercise recordsThe objective. The incident response capability was tested.
After-action notesThe objective. Findings from the test, and any resulting improvements.

The evidence should show that the incident response capability has been tested, with a record of the exercise. The test records, ideally with findings that fed back into the capability, are the clearest demonstration of the control.

An untested plan is a set of assumptions

A response capability that has never been exercised reveals its gaps only during a real incident, and this control asks for testing that surfaces them while there is still time to fix them. Running a tabletop exercise and feeding its findings back into the capability is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.6.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.6.3. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Incident Response
IR.L2-3.6.2 · Incident Tracking and Reporting
Next: Maintenance →
MA.L2-3.7.1 · Perform Maintenance
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry IR.L2-3.6.3 · Edition 2026.1 · Last reviewed July 12, 2026