DKDavid Koran& Associates
Home The CMMC Guide Part III · Risk Assessment RA.L2-3.11.1
The CMMC Guide · Risk Assessment Family

RA.L2-3.11.1  Assess Risk

Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

Family
Risk AssessmentRA, 3 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

RA.L2-3.11.1 opens the Risk Assessment family with the requirement to assess risk periodically. It requires that the organization periodically assess the risk to its operations, assets, and individuals arising from operating systems that process, store, or transmit CUI, so that security decisions rest on an understanding of the risks that actually face the organization. It is a three-point requirement that cannot be deferred on a plan of action.

Security controls are worth applying because they address risk, and understanding that risk is what makes the security program deliberate rather than arbitrary. This control requires the organization to define how often it will assess risk and then actually assess, at that frequency, the risk that operating CUI systems poses to its mission, assets, and people. The result is a current picture of the threats and vulnerabilities the organization faces, which informs where to focus protection. Its three-point weight reflects that a program without a risk assessment is guessing at its own priorities.

The requirement · NIST SP 800-171 Rev 2, 3.11.1

Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

The requirement has two elements the assessment objectives make explicit: a defined frequency, and assessment at that frequency. The organization decides how often it will assess risk, then assesses the risk to operations, assets, and individuals from operating systems that process, store, or transmit CUI. Periodic assessment keeps the risk picture current as the environment and threats change, so the program is guided by present risk rather than a one-time snapshot.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.11.1 into two objectives: define the frequency and assess at that frequency.

[a]

The frequency to assess risk to organizational operations, assets, and individuals is defined. How often risk is assessed is set.

MeetsA frequency for assessing risk is defined.
FailsNo frequency for risk assessment is defined.
[b]

Risk resulting from the operation of a system that processes, stores, or transmits CUI is assessed with the defined frequency. Risk is actually assessed on schedule.

MeetsRisk is assessed at the defined frequency, covering CUI systems.
FailsRisk is assessed once or never, not at the defined frequency.

The two objectives are the frequency and the assessment. The common gap is at objective [b], where a frequency is defined but the assessment does not actually happen on that schedule. The assessor looks for a defined frequency and evidence of assessment at that cadence.

3Failure Patterns

The failures are about risk assessment that is undefined or does not recur.

No defined frequency

Without setting how often risk is assessed, the assessment has no schedule and tends not to recur. Defining the frequency establishes the cadence.

One-time assessment

A risk assessment done once and never repeated goes stale as the environment and threats change. Periodic assessment at the defined frequency keeps the picture current.

Assessment not tied to CUI systems

A generic risk exercise that does not address the risk from operating CUI systems misses the control's focus. The assessment has to cover the risk those systems pose.

The common root
This control fails when risk assessment is treated as a one-time document rather than a recurring practice. Risk changes as systems, threats, and the environment change, so an assessment frozen in time stops reflecting reality, and the program it guides drifts from present risk. Assessing periodically keeps the guidance current.

4Ownership

This is a security and management-owned control.

RoleResponsibility for this control
Security or compliance leadDefines the frequency and conducts the risk assessment covering CUI systems. Owns the risk assessment records.
ManagementUses the risk assessment to guide security priorities.
Program leadConfirms the assessment recurs at the defined frequency and retains the records.
See also: This control informs the vulnerability scanning of RA.L2-3.11.2 and the remediation of RA.L2-3.11.3, which act on the risks it identifies.

5Tooling

The control is largely procedural, delivered by a defined and recurring risk assessment.

ObjectivesToolingWhat it provides
[a]Defined assessment frequencyA set cadence for assessing risk.
[b]Risk assessment covering CUI systemsAssessment of the risk from operating CUI systems at that cadence.

The caveat is that the assessment has to actually recur at the defined frequency and cover the CUI systems. A frequency on paper without assessments on that schedule, or a generic exercise that ignores CUI systems, leaves the control unmet. The assessor examines the frequency and the recurring assessment, so both objectives have to hold.

6Evidence

The satisfied version of 3.11.1 shows a defined frequency and recurring risk assessments.

EvidenceWhat it demonstrates
Defined assessment frequencyObjective [a]. How often risk is assessed.
Risk assessment recordsObjective [b]. Risk assessed at the defined frequency, covering CUI systems.

The evidence should show a defined assessment frequency and risk assessments performed at that cadence covering CUI systems. The defined frequency together with the assessment records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

A program guided by stale risk drifts from reality

Risk changes as systems and threats change, so this three-point control asks for a defined frequency and recurring assessment of the risk from operating CUI systems. Establishing a real, periodic risk assessment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.1[a] and 3.11.1[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing RA.L2-3.11.1 among the three-point basic security requirements. ecfr.gov
← Previous: Physical Protection
PE.L2-3.10.6 · Safeguard CUI at Alternate Work Sites
Next in Risk Assessment →
RA.L2-3.11.2 · Scan for Vulnerabilities
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry RA.L2-3.11.1 · Edition 2026.1 · Last reviewed July 12, 2026