Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Maintenance (MA)

Maintenance contains 6 CMMC Level 2 requirements focused on keeping your systems in good working order while maintaining security. These controls ensure that routine upkeep, repairs, and vendor support do not create security vulnerabilities.

Maintenance means performing upkeep on systems—installing updates, replacing parts, troubleshooting problems, and conducting repairs.

System maintenance is essential for security and reliability, but it also creates risk. Maintenance activities often require elevated access, may involve external personnel, and can introduce vulnerabilities if not performed correctly.

Why Maintenance Matters for CMMC

The Department of Defense requires Maintenance controls because poorly managed maintenance creates significant security risks for Controlled Unclassified Information (CUI).

CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.

Maintenance risks include:

  • External technicians accessing systems containing CUI
  • Maintenance tools introducing malware
  • Equipment sent for repair containing sensitive data
  • Unpatched vulnerabilities from skipped maintenance
  • Unauthorized changes during maintenance activities

Proper maintenance controls balance operational needs with security requirements.

The 6 Maintenance Requirements

MA.L2-3.7.1: System Maintenance

“Perform maintenance on organizational systems.”

This foundational requirement establishes that you must maintain your systems:

  • Apply security patches and updates regularly
  • Perform preventive maintenance on hardware
  • Address problems before they cause failures
  • Keep systems in supported configurations

Unmaintained systems accumulate vulnerabilities. Skipping maintenance to avoid downtime creates larger problems later.

MA.L2-3.7.2: System Maintenance Control

“Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.”

Maintenance activities must be controlled:

Tools

  • Approve maintenance tools before use
  • Scan tools for malware
  • Control physical maintenance equipment

Techniques

  • Document approved maintenance procedures
  • Follow manufacturer recommendations
  • Use secure methods for remote maintenance

Mechanisms

  • Log maintenance activities
  • Monitor maintenance sessions
  • Verify changes made during maintenance

Personnel

  • Authorize personnel before allowing maintenance access
  • Verify credentials of external technicians
  • Supervise maintenance activities

MA.L2-3.7.3: Equipment Sanitization

“Ensure equipment removed for off-site maintenance is sanitized of any CUI.”

Before sending equipment for external repair:

  • Remove or destroy storage media containing CUI
  • Verify no CUI remains on the equipment
  • Document sanitization performed
  • Use secure disposal methods for media that cannot be sanitized

Sanitization means removing data from storage media so thoroughly that it cannot be recovered, even with forensic tools.

If equipment must retain data for troubleshooting, use cleared maintenance providers or perform repairs on-site.

MA.L2-3.7.4: Media Inspection

“Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.”

Maintenance often involves diagnostic software, firmware updates, or test programs:

  • Scan all maintenance media for malware before use
  • Verify the integrity of firmware and software updates
  • Use trusted sources for maintenance software
  • Do not use unknown USB drives or media

This prevents maintenance activities from introducing malware into your environment.

MA.L2-3.7.5: Nonlocal Maintenance

“Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.”

Remote maintenance requires strong controls:

Authentication

  • Require multi-factor authentication (MFA) for remote maintenance access
  • Do not allow password-only authentication for maintenance sessions
  • Verify the identity of remote maintenance personnel

Multi-factor authentication (MFA) requires two or more different verification methods—like a password plus a code from your phone.

Session Management

  • Monitor remote maintenance sessions
  • Log all activities during remote maintenance
  • Terminate sessions immediately when maintenance completes
  • Do not leave remote access connections open

Network Controls

  • Use encrypted connections (VPN) for remote maintenance
  • Limit remote maintenance to approved systems
  • Control which external parties can perform remote maintenance

MA.L2-3.7.6: Maintenance Personnel

“Supervise the maintenance activities of maintenance personnel without required access authorization.”

When maintenance personnel do not have authorization to access CUI:

Supervision Requirements

  • Escort maintenance personnel at all times
  • Observe their activities directly
  • Do not leave them unattended with CUI systems
  • Verify work performed before they leave

Access Limitations

  • Provide only necessary access for the maintenance task
  • Remove access immediately when work completes
  • Do not provide credentials that allow unsupervised return access

Documentation

  • Record who performed maintenance
  • Document what systems were accessed
  • Note what work was performed
  • Maintain visitor logs

Implementing Maintenance Controls

Establish Maintenance Procedures

Document your maintenance practices:

  • Patch management schedule and procedures
  • Hardware maintenance requirements
  • Approved maintenance tools and software
  • Procedures for external technicians
  • Remote maintenance authorization process

Create a Patch Management Program

Regular patching is the most critical maintenance activity:

  • Inventory all systems requiring updates
  • Subscribe to vendor security notifications
  • Test patches before deployment when possible
  • Apply critical security patches promptly
  • Document patch status for all systems

Control Maintenance Tools

Manage tools used for maintenance:

  • Maintain inventory of approved tools
  • Scan portable media before use
  • Control access to maintenance equipment
  • Verify software integrity before installation

Manage External Maintenance

When using external technicians or sending equipment for repair:

  • Sanitize equipment before external repair
  • Require background checks for regular maintenance vendors
  • Supervise all external maintenance personnel
  • Use non-disclosure agreements with maintenance providers
  • Verify credentials before granting access

Secure Remote Maintenance

For remote support and maintenance:

  • Require MFA for all remote maintenance access
  • Use encrypted connections only
  • Monitor and log remote sessions
  • Terminate connections when complete
  • Approve remote maintenance requests in advance

Common Maintenance Mistakes

Mistake 1: Skipping Patches

Delaying patches to avoid disruption accumulates vulnerabilities. Establish regular patching cycles and stick to them.

Mistake 2: Unsupervised Vendors

Allowing external technicians to work unsupervised on CUI systems violates requirements and creates risk. Always supervise unauthorized personnel.

Mistake 3: Forgetting Equipment Sanitization

Sending equipment for repair without removing CUI exposes sensitive data. Sanitize before any equipment leaves your control.

Mistake 4: Password-Only Remote Access

Remote maintenance sessions without MFA violate requirements. Require multi-factor authentication for all remote maintenance.

Mistake 5: No Maintenance Records

Without documentation, you cannot demonstrate compliance or investigate problems. Log all maintenance activities.

Key Takeaways

Maintenance’s 6 requirements ensure systems stay secure during routine upkeep and repairs. Perform regular maintenance, including patching, control maintenance tools and personnel, sanitize equipment before external repair, and secure remote maintenance sessions with MFA.

The key principle is that maintenance activities should not create security gaps. Control who performs maintenance, what tools they use, and what access they have. Document everything.


Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” specifically the Maintenance family (Section 3.7), and the DoD CMMC Level 2 Assessment Guide.


Need help implementing maintenance controls for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Table of Contents