1Overview
MA.L2-3.7.6 closes the Maintenance family with a control on unauthorized maintainers. It requires that maintenance personnel who lack the required access authorization be supervised during their maintenance activities, so that someone without their own authorization does not gain unsupervised access to systems and CUI. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
Not every maintainer holds authorization to access the organization's systems and CUI. An outside technician, a vendor specialist, or a contractor may need to perform maintenance without having been granted access in their own right. This control requires that such unauthorized personnel be supervised while they work, so an authorized person is present to ensure they do only the maintenance needed and do not reach beyond it. It lets necessary maintenance happen without granting standing access to those who should not have it.
Supervise the maintenance activities of maintenance personnel without required access authorization.
The requirement applies specifically to maintenance personnel who lack the required access authorization. For them, supervision during maintenance is required: an authorized individual accompanies and oversees the work, so the unauthorized maintainer's access is bounded by that supervision rather than left open. This is the maintenance parallel to escorting a visitor, applied to the people who service systems without their own authorization.
2The Assessment Objective
NIST SP 800-171A frames 3.7.6 as a single objective: supervise unauthorized maintenance personnel.
Maintenance personnel without required access authorization are supervised during maintenance activities. Unauthorized maintainers are overseen while they work.
The single objective is supervision of unauthorized maintenance personnel. The common failure is an outside technician left to work alone. The assessor looks for supervision whenever a maintainer lacks the required authorization.
3Failure Patterns
The failures are about unauthorized maintainers working without oversight.
Outside technician left alone
A vendor or contractor without authorization left to perform maintenance unsupervised gains unbounded access to systems and CUI. Supervision by an authorized person keeps the access bounded.
No process for unauthorized maintainers
Without a process to identify who lacks authorization and assign supervision, unauthorized maintainers slip through unsupervised. A defined process ties supervision to the maintenance visit.
Nominal supervision
Supervision that is only nominal, where the authorized person is not actually present or attentive, does not bound the access. The supervision has to be real oversight during the work.
4Ownership
This is an operations and IT-owned control tied to how outside maintenance is handled.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Supervises unauthorized maintenance personnel during their work. Owns the supervision evidence. |
| Security or compliance lead | Confirms supervision is required and real for maintainers lacking authorization. |
| Program lead | Ties supervision to the maintenance process and retains the records. |
5Tooling
The control is largely procedural, delivered by supervision during maintenance visits.
| Objective | Tooling | What it provides |
|---|---|---|
| identify | Authorization check for maintainers | Recognition of who lacks required authorization. |
| supervise | Assigned supervision during maintenance | Real oversight of unauthorized maintainers while they work. |
The caveat is that supervision has to be real and applied whenever a maintainer lacks authorization. Nominal supervision, or supervision skipped for a trusted vendor, leaves the access unbounded. The assessor examines whether unauthorized maintainers are actually supervised, so the oversight has to be genuine and consistent.
6Evidence
The satisfied version of 3.7.6 shows unauthorized maintainers supervised during their work.
| Evidence | What it demonstrates |
|---|---|
| Maintenance supervision process | The objective. Supervision required for unauthorized maintainers. |
| Supervision records | The objective. Evidence unauthorized maintainers were supervised. |
The evidence should show maintenance personnel lacking authorization supervised during their activities, tied to a defined process. The supervision process and records are the clearest demonstration of the control.
Necessary maintenance need not mean unsupervised access
An outside maintainer may need to service systems without holding authorization, and this control asks that they be supervised so the access stays bounded. Building supervision into how outside maintenance is handled is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.6. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.6. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov