DKDavid Koran& Associates
Home The CMMC Guide Part III · Risk Assessment RA.L2-3.11.3
The CMMC Guide · Risk Assessment Family

RA.L2-3.11.3  Remediate Vulnerabilities

Remediate vulnerabilities in accordance with risk assessments.

Family
Risk AssessmentRA, 3 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

RA.L2-3.11.3 closes the Risk Assessment family by acting on what scanning finds. It requires that vulnerabilities be remediated in accordance with risk assessments, so that the weaknesses found are actually fixed, prioritized by the risk they pose. It is a one-point requirement and may be deferred on a plan of action.

Finding vulnerabilities matters only if they are then addressed. This control requires that identified vulnerabilities be remediated, and that the remediation be guided by risk, so the most dangerous weaknesses are addressed first rather than every finding being treated identically. It closes the loop that the scanning of the previous control opens: scanning finds the weaknesses, and remediation, prioritized by risk, resolves them. The two assessment objectives are the identification of vulnerabilities and their risk-based remediation.

The requirement · NIST SP 800-171 Rev 2, 3.11.3

Remediate vulnerabilities in accordance with risk assessments.

The requirement is to remediate vulnerabilities, guided by risk assessments. The assessment objectives make clear that vulnerabilities are first identified, then remediated in accordance with the organization's risk assessments, so that the response is prioritized by the risk each vulnerability presents. Remediation may mean patching, reconfiguring, or otherwise resolving the weakness, and tying it to risk ensures effort goes where the exposure is greatest.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.11.3 into two objectives: identify vulnerabilities and remediate them in accordance with risk assessments.

[a]

Vulnerabilities are identified. The weaknesses to be addressed are known.

MeetsVulnerabilities are identified, typically through scanning and other sources.
FailsVulnerabilities are not identified, so there is nothing to remediate against.
[b]

Vulnerabilities are remediated in accordance with risk assessments. Weaknesses are fixed, prioritized by risk.

MeetsVulnerabilities are remediated, with priority guided by risk assessments.
FailsIdentified vulnerabilities are not remediated, or remediation ignores risk.

The two objectives are identification and risk-based remediation. The common failure is at objective [b], where vulnerabilities are identified and reported but not actually remediated, so scan findings accumulate unaddressed. The assessor looks for both identification and remediation guided by risk.

3Failure Patterns

The failures are about vulnerabilities found but not fixed.

Findings not remediated

Vulnerabilities identified by scanning but never remediated leave the weaknesses open despite being known. Remediation is what closes them.

No risk-based prioritization

Treating every finding identically, or addressing low-risk issues while high-risk ones wait, misuses limited effort. Remediation in accordance with risk assessments directs effort to the greatest exposure.

No remediation tracking

Without tracking which vulnerabilities are remediated and which remain, findings are lost and closure cannot be shown. Tracking remediation demonstrates the loop is closed.

The common root
This control fails in the gap between finding and fixing. Scanning produces findings readily, but remediation takes effort and coordination, so vulnerabilities are easy to identify and leave open. Remediating in accordance with risk is what turns findings into resolved weaknesses, worst first.

4Ownership

This is an IT and security-owned control tied to the remediation process.

RoleResponsibility for this control
IT and securityRemediates identified vulnerabilities, prioritized by risk. Owns the remediation evidence.
Security or compliance leadTies remediation priority to the risk assessments and tracks closure.
Program leadConfirms findings are remediated, not just reported, and retains the records.
See also: This control acts on the findings of RA.L2-3.11.2, is prioritized by RA.L2-3.11.1, and connects to the flaw remediation of the system and information integrity family.

5Tooling

The control is delivered by a remediation process that acts on findings by risk.

ObjectivesToolingWhat it provides
[a]Scanning and vulnerability sourcesIdentification of the vulnerabilities to address.
[b]Risk-prioritized remediation and trackingFixing of weaknesses, worst first, with closure tracked.

The caveat is that remediation has to actually happen and follow risk. Identifying vulnerabilities without resolving them, or resolving them without regard to risk, leaves the control unmet. The assessor examines both identification and risk-based remediation, so findings have to be tracked through to closure.

6Evidence

The satisfied version of 3.11.3 shows vulnerabilities remediated by risk.

EvidenceWhat it demonstrates
Vulnerability findingsObjective [a]. Vulnerabilities are identified.
Remediation recordsObjective [b]. Vulnerabilities remediated in accordance with risk.

The evidence should show vulnerabilities identified and then remediated with priority guided by risk assessments. The findings together with the remediation records are the clearest demonstration of the control.

Finding a weakness is not the same as closing it

Scanning produces findings readily, but they matter only when fixed, so this control asks that vulnerabilities be remediated in accordance with risk, worst first. Building a remediation process that closes findings by risk is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.3[a] and 3.11.3[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Risk Assessment
RA.L2-3.11.2 · Scan for Vulnerabilities
Next: Security Assessment →
CA.L2-3.12.1 · Assess Security Controls
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry RA.L2-3.11.3 · Edition 2026.1 · Last reviewed July 12, 2026