DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.1
The CMMC Guide · Maintenance Family

MA.L2-3.7.1  Perform Maintenance

Perform maintenance on organizational systems.

Family
MaintenanceMA, 6 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MA.L2-3.7.1 opens the Maintenance family with the baseline requirement to keep systems maintained. It requires that the organization perform maintenance on its systems, so that the systems that protect CUI are kept in working order rather than left to decay. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.

Security controls run on systems, and systems that are not maintained degrade: patches go unapplied, hardware fails, and configurations drift, each opening a gap that the security program then cannot rely on. This control asks the organization simply to perform maintenance on its systems, establishing the routine upkeep that keeps the environment functioning as intended. It is the foundation the rest of the family builds on, since the more specific maintenance controls all assume that maintenance is actually happening.

The requirement · NIST SP 800-171 Rev 2, 3.7.1

Perform maintenance on organizational systems.

The requirement is broad and foundational: maintenance is performed. This covers the routine upkeep that keeps systems working, from applying updates to servicing hardware, done in a controlled and documented way. The three-point weight reflects that unmaintained systems are both unreliable and insecure, and that the rest of the maintenance family depends on maintenance actually being carried out.

2The Assessment Objective

NIST SP 800-171A frames 3.7.1 as a single objective: system maintenance is performed.

System maintenance is performed. The organization carries out maintenance on its systems.

MeetsMaintenance is performed on systems in a controlled, documented way, keeping them in working order.
FailsSystems are not maintained, so they degrade and drift over time.

The single objective is that maintenance is performed. The common failure is ad hoc or neglected maintenance with no evidence that it happens routinely. The assessor looks for maintenance actually being carried out and recorded.

3Failure Patterns

The failures are about neglected or undocumented maintenance.

Maintenance left undone

Where systems are not maintained, they accumulate unpatched software, failing hardware, and drifted configurations, undermining both reliability and security. Performing routine maintenance is what the control requires.

No record of maintenance

Maintenance that happens informally with nothing recorded cannot be demonstrated. Documenting maintenance activity shows the control is met.

Reactive-only maintenance

Maintaining systems only when they break, with no routine upkeep, lets preventable problems accumulate. Regular maintenance keeps systems in working order rather than waiting for failure.

The common root
This control fails through neglect. Maintenance is easy to defer under other pressures, but unmaintained systems quietly degrade until a gap the security program depended on is no longer there. Routine, recorded maintenance is what keeps the environment dependable.

4Ownership

This is an IT-owned control, delivered through routine system maintenance.

RoleResponsibility for this control
IT and system administratorPerforms and records routine maintenance on systems. Owns the maintenance evidence.
Security or compliance leadConfirms maintenance is performed routinely and documented.
Program leadIncludes maintenance in operational practice and retains the records.
See also: This control is the foundation of the Maintenance family, and the more specific requirements at MA.L2-3.7.2 and beyond assume it is carried out.

5Tooling

The control is delivered by the routine maintenance practices and their records.

ObjectiveToolingWhat it provides
performMaintenance schedule and proceduresRoutine upkeep that keeps systems in working order.
recordMaintenance logs or recordsDocumentation that maintenance is performed.

The caveat is that maintenance has to be routine and demonstrable, not reactive and invisible. A maintenance schedule with records is what shows the control is met, rather than fixing systems only when they fail. The assessor examines evidence that maintenance is performed, so records of routine upkeep are what demonstrate it.

6Evidence

The satisfied version of 3.7.1 shows maintenance performed and recorded.

EvidenceWhat it demonstrates
Maintenance recordsThe objective. Maintenance is performed on systems.
Maintenance scheduleThe objective. Routine, planned upkeep.

The evidence should show that maintenance is performed routinely and recorded. The maintenance records and schedule are the clearest demonstration, and because this control cannot sit on a plan of action, maintenance has to be a real, ongoing practice at the time of assessment.

Unmaintained systems quietly become unreliable ones

Systems that are not maintained accumulate unpatched software, failing hardware, and drifted configurations, and this control asks for the routine upkeep that keeps them dependable. Establishing a maintenance practice with records is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.1. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.1 among the three-point basic security requirements. ecfr.gov
← Previous: Incident Response
IR.L2-3.6.3 · Incident Response Testing
Next in Maintenance →
MA.L2-3.7.2 · Control Maintenance Tools and Personnel
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.1 · Edition 2026.1 · Last reviewed July 12, 2026