1Overview
MA.L2-3.7.1 opens the Maintenance family with the baseline requirement to keep systems maintained. It requires that the organization perform maintenance on its systems, so that the systems that protect CUI are kept in working order rather than left to decay. It is a three-point requirement with a single assessment objective, and it cannot be deferred on a plan of action.
Security controls run on systems, and systems that are not maintained degrade: patches go unapplied, hardware fails, and configurations drift, each opening a gap that the security program then cannot rely on. This control asks the organization simply to perform maintenance on its systems, establishing the routine upkeep that keeps the environment functioning as intended. It is the foundation the rest of the family builds on, since the more specific maintenance controls all assume that maintenance is actually happening.
Perform maintenance on organizational systems.
The requirement is broad and foundational: maintenance is performed. This covers the routine upkeep that keeps systems working, from applying updates to servicing hardware, done in a controlled and documented way. The three-point weight reflects that unmaintained systems are both unreliable and insecure, and that the rest of the maintenance family depends on maintenance actually being carried out.
2The Assessment Objective
NIST SP 800-171A frames 3.7.1 as a single objective: system maintenance is performed.
System maintenance is performed. The organization carries out maintenance on its systems.
The single objective is that maintenance is performed. The common failure is ad hoc or neglected maintenance with no evidence that it happens routinely. The assessor looks for maintenance actually being carried out and recorded.
3Failure Patterns
The failures are about neglected or undocumented maintenance.
Maintenance left undone
Where systems are not maintained, they accumulate unpatched software, failing hardware, and drifted configurations, undermining both reliability and security. Performing routine maintenance is what the control requires.
No record of maintenance
Maintenance that happens informally with nothing recorded cannot be demonstrated. Documenting maintenance activity shows the control is met.
Reactive-only maintenance
Maintaining systems only when they break, with no routine upkeep, lets preventable problems accumulate. Regular maintenance keeps systems in working order rather than waiting for failure.
4Ownership
This is an IT-owned control, delivered through routine system maintenance.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Performs and records routine maintenance on systems. Owns the maintenance evidence. |
| Security or compliance lead | Confirms maintenance is performed routinely and documented. |
| Program lead | Includes maintenance in operational practice and retains the records. |
5Tooling
The control is delivered by the routine maintenance practices and their records.
| Objective | Tooling | What it provides |
|---|---|---|
| perform | Maintenance schedule and procedures | Routine upkeep that keeps systems in working order. |
| record | Maintenance logs or records | Documentation that maintenance is performed. |
The caveat is that maintenance has to be routine and demonstrable, not reactive and invisible. A maintenance schedule with records is what shows the control is met, rather than fixing systems only when they fail. The assessor examines evidence that maintenance is performed, so records of routine upkeep are what demonstrate it.
6Evidence
The satisfied version of 3.7.1 shows maintenance performed and recorded.
| Evidence | What it demonstrates |
|---|---|
| Maintenance records | The objective. Maintenance is performed on systems. |
| Maintenance schedule | The objective. Routine, planned upkeep. |
The evidence should show that maintenance is performed routinely and recorded. The maintenance records and schedule are the clearest demonstration, and because this control cannot sit on a plan of action, maintenance has to be a real, ongoing practice at the time of assessment.
Unmaintained systems quietly become unreliable ones
Systems that are not maintained accumulate unpatched software, failing hardware, and drifted configurations, and this control asks for the routine upkeep that keeps them dependable. Establishing a maintenance practice with records is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.1. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing MA.L2-3.7.1 among the three-point basic security requirements. ecfr.gov