DKDavid Koran& Associates
Home The CMMC Guide Part III · Risk Assessment RA.L2-3.11.2
The CMMC Guide · Risk Assessment Family

RA.L2-3.11.2  Scan for Vulnerabilities

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

Family
Risk AssessmentRA, 3 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
FivePer NIST SP 800-171A

1Overview

RA.L2-3.11.2 is the family's five-point requirement and it puts risk assessment into regular technical practice. It requires that the organization scan for vulnerabilities in its systems and applications periodically and when new vulnerabilities affecting them are identified, so that weaknesses are found before they are exploited. It is a five-point requirement with five assessment objectives, and it cannot be deferred on a plan of action.

Vulnerabilities appear constantly, as new flaws are discovered in software already in use, and a system that was secure last month may be exposed today. This control requires vulnerability scanning on two triggers: periodically, at a defined frequency, and additionally whenever new vulnerabilities affecting the systems or applications are identified. Both triggers apply to both systems and applications. Scanning on a schedule catches drift; scanning on new-vulnerability news catches the freshly disclosed flaws that attackers move on quickly. Its five-point weight reflects that unfound vulnerabilities are the openings that attacks exploit.

The requirement · NIST SP 800-171 Rev 2, 3.11.2

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

The requirement combines a defined scanning frequency with an event trigger, applied across systems and applications. The five assessment objectives spell this out: define the frequency, then scan systems and scan applications at that frequency, and scan systems and scan applications when new affecting vulnerabilities are identified. Covering both the periodic cadence and the new-vulnerability trigger, for both systems and applications, is what keeps the vulnerability picture current.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.11.2 into five objectives: define the frequency, scan systems and applications on that frequency, and scan systems and applications when new vulnerabilities are identified.

[a]

The frequency to scan for vulnerabilities is defined. How often scanning occurs is set.

MeetsA frequency for vulnerability scanning is defined.
FailsNo scanning frequency is defined.
[b]

Vulnerability scans are performed on systems with the defined frequency. Systems are scanned on schedule.

MeetsSystems are scanned at the defined frequency.
FailsSystems are not scanned on the defined schedule.
[c]

Vulnerability scans are performed on applications with the defined frequency. Applications are scanned on schedule.

MeetsApplications are scanned at the defined frequency.
FailsApplications are left out of periodic scanning.
[d]

Vulnerability scans are performed on systems when new vulnerabilities affecting them are identified. Systems are scanned on new-vulnerability news.

MeetsSystems are scanned when new affecting vulnerabilities are identified.
FailsNewly disclosed vulnerabilities do not trigger a scan.
[e]

Vulnerability scans are performed on applications when new vulnerabilities affecting them are identified. Applications are scanned on new-vulnerability news.

MeetsApplications are scanned when new affecting vulnerabilities are identified.
FailsNew application vulnerabilities do not trigger a scan.

The five objectives cover the frequency, periodic scanning of systems and applications, and event-triggered scanning of both. The common gaps are at objectives [c] and [e], applications, which are often left out of scanning aimed at infrastructure, and at [d] and [e], the new-vulnerability trigger, which is skipped when scanning is treated as purely periodic. The assessor looks for all five.

3Failure Patterns

The failures are about scanning that is incomplete in coverage or trigger.

Applications not scanned

Scanning that covers infrastructure but omits applications leaves application vulnerabilities unfound. Both systems and applications have to be scanned.

Only periodic, never on disclosure

Scanning only on a schedule misses the window when a newly disclosed vulnerability is most exploited. Scanning when new affecting vulnerabilities are identified catches those.

No defined frequency

Without a defined scanning frequency, periodic scanning has no cadence and tends to lapse. Defining the frequency anchors the periodic scans.

Scans run but not on the systems that matter

Scanning that does not cover the CUI systems and their applications leaves the important assets unexamined. Coverage has to include the systems in scope.

The common root
This control fails through partial coverage. Vulnerabilities emerge continuously across both systems and applications, so scanning that omits applications, skips the new-vulnerability trigger, or lacks a defined cadence leaves openings unfound. Full coverage on both triggers is what keeps the picture current.

4Ownership

This is an IT and security-owned technical control.

RoleResponsibility for this control
IT and securityRuns vulnerability scans on systems and applications, periodically and on new-vulnerability news. Owns the scan evidence.
Security or compliance leadDefines the scanning frequency and confirms coverage and triggers.
Program leadReviews scan cadence and retains the scan records.
See also: This control feeds the remediation of RA.L2-3.11.3, is guided by the risk assessment of RA.L2-3.11.1, and connects to the flaw remediation of the system and information integrity family.

5Tooling

The control is delivered by vulnerability scanning on a defined cadence and on new-vulnerability triggers.

ObjectivesToolingWhat it provides
[a]Defined scanning frequencyA set cadence for scans.
[b], [c]Vulnerability scanner covering systems and applicationsPeriodic scanning of both.
[d], [e]New-vulnerability trigger processScanning of systems and applications when new flaws are identified.

The caveat is that coverage has to span systems and applications and both triggers. A scanner run on a schedule but only against infrastructure, or never re-run when a major vulnerability is disclosed, leaves objectives unmet. The assessor examines all five, so the frequency, the periodic scans of both subjects, and the event-triggered scans all have to hold.

6Evidence

The satisfied version of 3.11.2 shows scanning across systems and applications on both triggers.

EvidenceWhat it demonstrates
Defined scanning frequencyObjective [a]. The scanning cadence.
Scan reports for systems and applicationsObjectives [b], [c]. Periodic scanning of both.
Event-triggered scan recordsObjectives [d], [e]. Scanning on new-vulnerability news.

The evidence should show a defined frequency, periodic scans of systems and applications, and scans triggered by newly identified vulnerabilities. The scan reports across both subjects and both triggers are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

Yesterday's secure system can be today's open one

Vulnerabilities emerge continuously, so this five-point control asks for scanning of both systems and applications, on a defined cadence and whenever new flaws are disclosed. Building complete vulnerability scanning is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.2[a] through 3.11.2[e]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing RA.L2-3.11.2 among the five-point derived security requirements. ecfr.gov
← Previous in Risk Assessment
RA.L2-3.11.1 · Assess Risk
Next in Risk Assessment →
RA.L2-3.11.3 · Remediate Vulnerabilities
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry RA.L2-3.11.2 · Edition 2026.1 · Last reviewed July 12, 2026