DKDavid Koran& Associates
Home The CMMC Guide Part III · Maintenance MA.L2-3.7.6
The CMMC Guide · Maintenance Family

MA.L2-3.7.6  Supervise Maintenance Personnel

Supervise the maintenance activities of maintenance personnel without required access authorization.

Family
MaintenanceMA, 6 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
OnePer NIST SP 800-171A

1Overview

MA.L2-3.7.6 closes the Maintenance family with a control on unauthorized maintainers. It requires that maintenance personnel who lack the required access authorization be supervised during their maintenance activities, so that someone without their own authorization does not gain unsupervised access to systems and CUI. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.

Not every maintainer holds authorization to access the organization's systems and CUI. An outside technician, a vendor specialist, or a contractor may need to perform maintenance without having been granted access in their own right. This control requires that such unauthorized personnel be supervised while they work, so an authorized person is present to ensure they do only the maintenance needed and do not reach beyond it. It lets necessary maintenance happen without granting standing access to those who should not have it.

The requirement · NIST SP 800-171 Rev 2, 3.7.6

Supervise the maintenance activities of maintenance personnel without required access authorization.

The requirement applies specifically to maintenance personnel who lack the required access authorization. For them, supervision during maintenance is required: an authorized individual accompanies and oversees the work, so the unauthorized maintainer's access is bounded by that supervision rather than left open. This is the maintenance parallel to escorting a visitor, applied to the people who service systems without their own authorization.

2The Assessment Objective

NIST SP 800-171A frames 3.7.6 as a single objective: supervise unauthorized maintenance personnel.

Maintenance personnel without required access authorization are supervised during maintenance activities. Unauthorized maintainers are overseen while they work.

MeetsMaintenance personnel lacking authorization are supervised by an authorized person during their work.
FailsUnauthorized maintainers work unsupervised, with unbounded access.

The single objective is supervision of unauthorized maintenance personnel. The common failure is an outside technician left to work alone. The assessor looks for supervision whenever a maintainer lacks the required authorization.

3Failure Patterns

The failures are about unauthorized maintainers working without oversight.

Outside technician left alone

A vendor or contractor without authorization left to perform maintenance unsupervised gains unbounded access to systems and CUI. Supervision by an authorized person keeps the access bounded.

No process for unauthorized maintainers

Without a process to identify who lacks authorization and assign supervision, unauthorized maintainers slip through unsupervised. A defined process ties supervision to the maintenance visit.

Nominal supervision

Supervision that is only nominal, where the authorized person is not actually present or attentive, does not bound the access. The supervision has to be real oversight during the work.

The common root
This control fails when maintenance is trusted regardless of who performs it. An unauthorized maintainer needs to do the work but should not have free access, and unless supervision is required and real, the maintenance visit becomes unsupervised access to the very systems and data the program protects.

4Ownership

This is an operations and IT-owned control tied to how outside maintenance is handled.

RoleResponsibility for this control
IT and system administratorSupervises unauthorized maintenance personnel during their work. Owns the supervision evidence.
Security or compliance leadConfirms supervision is required and real for maintainers lacking authorization.
Program leadTies supervision to the maintenance process and retains the records.
See also: This control complements the personnel control of MA.L2-3.7.2 and parallels the visitor escorting of the physical protection family.

5Tooling

The control is largely procedural, delivered by supervision during maintenance visits.

ObjectiveToolingWhat it provides
identifyAuthorization check for maintainersRecognition of who lacks required authorization.
superviseAssigned supervision during maintenanceReal oversight of unauthorized maintainers while they work.

The caveat is that supervision has to be real and applied whenever a maintainer lacks authorization. Nominal supervision, or supervision skipped for a trusted vendor, leaves the access unbounded. The assessor examines whether unauthorized maintainers are actually supervised, so the oversight has to be genuine and consistent.

6Evidence

The satisfied version of 3.7.6 shows unauthorized maintainers supervised during their work.

EvidenceWhat it demonstrates
Maintenance supervision processThe objective. Supervision required for unauthorized maintainers.
Supervision recordsThe objective. Evidence unauthorized maintainers were supervised.

The evidence should show maintenance personnel lacking authorization supervised during their activities, tied to a defined process. The supervision process and records are the clearest demonstration of the control.

Necessary maintenance need not mean unsupervised access

An outside maintainer may need to service systems without holding authorization, and this control asks that they be supervised so the access stays bounded. Building supervision into how outside maintenance is handled is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.7.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.7.6. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Maintenance
MA.L2-3.7.5 · Nonlocal Maintenance MFA
Next: Media Protection →
MP.L2-3.8.1 · Protect Media
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry MA.L2-3.7.6 · Edition 2026.1 · Last reviewed July 12, 2026