Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Maintenance (MA)
Maintenance contains 6 CMMC Level 2 requirements focused on keeping your systems in good working order while maintaining security. These controls ensure that routine upkeep, repairs, and vendor support do not create security vulnerabilities.
Maintenance means performing upkeep on systems—installing updates, replacing parts, troubleshooting problems, and conducting repairs.
System maintenance is essential for security and reliability, but it also creates risk. Maintenance activities often require elevated access, may involve external personnel, and can introduce vulnerabilities if not performed correctly.
Why Maintenance Matters for CMMC
The Department of Defense requires Maintenance controls because poorly managed maintenance creates significant security risks for Controlled Unclassified Information (CUI).
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
Maintenance risks include:
- External technicians accessing systems containing CUI
- Maintenance tools introducing malware
- Equipment sent for repair containing sensitive data
- Unpatched vulnerabilities from skipped maintenance
- Unauthorized changes during maintenance activities
Proper maintenance controls balance operational needs with security requirements.
The 6 Maintenance Requirements
MA.L2-3.7.1: System Maintenance
“Perform maintenance on organizational systems.”
This foundational requirement establishes that you must maintain your systems:
- Apply security patches and updates regularly
- Perform preventive maintenance on hardware
- Address problems before they cause failures
- Keep systems in supported configurations
Unmaintained systems accumulate vulnerabilities. Skipping maintenance to avoid downtime creates larger problems later.
MA.L2-3.7.2: System Maintenance Control
“Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.”
Maintenance activities must be controlled:
Tools
- Approve maintenance tools before use
- Scan tools for malware
- Control physical maintenance equipment
Techniques
- Document approved maintenance procedures
- Follow manufacturer recommendations
- Use secure methods for remote maintenance
Mechanisms
- Log maintenance activities
- Monitor maintenance sessions
- Verify changes made during maintenance
Personnel
- Authorize personnel before allowing maintenance access
- Verify credentials of external technicians
- Supervise maintenance activities
MA.L2-3.7.3: Equipment Sanitization
“Ensure equipment removed for off-site maintenance is sanitized of any CUI.”
Before sending equipment for external repair:
- Remove or destroy storage media containing CUI
- Verify no CUI remains on the equipment
- Document sanitization performed
- Use secure disposal methods for media that cannot be sanitized
Sanitization means removing data from storage media so thoroughly that it cannot be recovered, even with forensic tools.
If equipment must retain data for troubleshooting, use cleared maintenance providers or perform repairs on-site.
MA.L2-3.7.4: Media Inspection
“Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.”
Maintenance often involves diagnostic software, firmware updates, or test programs:
- Scan all maintenance media for malware before use
- Verify the integrity of firmware and software updates
- Use trusted sources for maintenance software
- Do not use unknown USB drives or media
This prevents maintenance activities from introducing malware into your environment.
MA.L2-3.7.5: Nonlocal Maintenance
“Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.”
Remote maintenance requires strong controls:
Authentication
- Require multi-factor authentication (MFA) for remote maintenance access
- Do not allow password-only authentication for maintenance sessions
- Verify the identity of remote maintenance personnel
Multi-factor authentication (MFA) requires two or more different verification methods—like a password plus a code from your phone.
Session Management
- Monitor remote maintenance sessions
- Log all activities during remote maintenance
- Terminate sessions immediately when maintenance completes
- Do not leave remote access connections open
Network Controls
- Use encrypted connections (VPN) for remote maintenance
- Limit remote maintenance to approved systems
- Control which external parties can perform remote maintenance
MA.L2-3.7.6: Maintenance Personnel
“Supervise the maintenance activities of maintenance personnel without required access authorization.”
When maintenance personnel do not have authorization to access CUI:
Supervision Requirements
- Escort maintenance personnel at all times
- Observe their activities directly
- Do not leave them unattended with CUI systems
- Verify work performed before they leave
Access Limitations
- Provide only necessary access for the maintenance task
- Remove access immediately when work completes
- Do not provide credentials that allow unsupervised return access
Documentation
- Record who performed maintenance
- Document what systems were accessed
- Note what work was performed
- Maintain visitor logs
Implementing Maintenance Controls
Establish Maintenance Procedures
Document your maintenance practices:
- Patch management schedule and procedures
- Hardware maintenance requirements
- Approved maintenance tools and software
- Procedures for external technicians
- Remote maintenance authorization process
Create a Patch Management Program
Regular patching is the most critical maintenance activity:
- Inventory all systems requiring updates
- Subscribe to vendor security notifications
- Test patches before deployment when possible
- Apply critical security patches promptly
- Document patch status for all systems
Control Maintenance Tools
Manage tools used for maintenance:
- Maintain inventory of approved tools
- Scan portable media before use
- Control access to maintenance equipment
- Verify software integrity before installation
Manage External Maintenance
When using external technicians or sending equipment for repair:
- Sanitize equipment before external repair
- Require background checks for regular maintenance vendors
- Supervise all external maintenance personnel
- Use non-disclosure agreements with maintenance providers
- Verify credentials before granting access
Secure Remote Maintenance
For remote support and maintenance:
- Require MFA for all remote maintenance access
- Use encrypted connections only
- Monitor and log remote sessions
- Terminate connections when complete
- Approve remote maintenance requests in advance
Common Maintenance Mistakes
Mistake 1: Skipping Patches
Delaying patches to avoid disruption accumulates vulnerabilities. Establish regular patching cycles and stick to them.
Mistake 2: Unsupervised Vendors
Allowing external technicians to work unsupervised on CUI systems violates requirements and creates risk. Always supervise unauthorized personnel.
Mistake 3: Forgetting Equipment Sanitization
Sending equipment for repair without removing CUI exposes sensitive data. Sanitize before any equipment leaves your control.
Mistake 4: Password-Only Remote Access
Remote maintenance sessions without MFA violate requirements. Require multi-factor authentication for all remote maintenance.
Mistake 5: No Maintenance Records
Without documentation, you cannot demonstrate compliance or investigate problems. Log all maintenance activities.
Key Takeaways
Maintenance’s 6 requirements ensure systems stay secure during routine upkeep and repairs. Perform regular maintenance, including patching, control maintenance tools and personnel, sanitize equipment before external repair, and secure remote maintenance sessions with MFA.
The key principle is that maintenance activities should not create security gaps. Control who performs maintenance, what tools they use, and what access they have. Document everything.
Related Articles:
- What is CMMC Level 2?
- CMMC Access Control Requirements for Level 2
- NIST SP 800-171 Rev 2 – Maintenance Family
- 32 CFR Part 170 – CMMC Program Rule
- CMMC Level 2 Assessment Guide
Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” specifically the Maintenance family (Section 3.7), and the DoD CMMC Level 2 Assessment Guide.
Need help implementing maintenance controls for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.