If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Maintenance (MA)
Maintenance contains 6 CMMC Level 2 requirements focused on keeping your systems in good working order while maintaining security. These controls ensure that routine upkeep, repairs, and vendor support do not create security vulnerabilities.
Maintenance means performing upkeep on systems—installing updates, replacing parts, troubleshooting problems, and conducting repairs.
System maintenance is essential for security and reliability, but it also creates risk. Maintenance activities often require elevated access, may involve external personnel, and can introduce vulnerabilities if not performed correctly.
Why Maintenance Matters for CMMC
The Department of Defense requires Maintenance controls because poorly managed maintenance creates significant security risks for Controlled Unclassified Information (CUI).
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection but not classified as secret.
Maintenance risks include:
- External technicians accessing systems containing CUI
- Maintenance tools introducing malware
- Equipment sent for repair containing sensitive data
- Unpatched vulnerabilities from skipped maintenance
- Unauthorized changes during maintenance activities
Proper maintenance controls balance operational needs with security requirements.
The 6 Maintenance Requirements
MA.L2-3.7.1: System Maintenance
“Perform maintenance on organizational systems.”
This foundational requirement establishes that you must maintain your systems:
- Apply security patches and updates regularly
- Perform preventive maintenance on hardware
- Address problems before they cause failures
- Keep systems in supported configurations
Unmaintained systems accumulate vulnerabilities. Skipping maintenance to avoid downtime creates larger problems later.
MA.L2-3.7.2: System Maintenance Control
“Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.”
Maintenance activities must be controlled:
Tools
- Approve maintenance tools before use
- Scan tools for malware
- Control physical maintenance equipment
Techniques
- Document approved maintenance procedures
- Follow manufacturer recommendations
- Use secure methods for remote maintenance
Mechanisms
- Log maintenance activities
- Monitor maintenance sessions
- Verify changes made during maintenance
Personnel
- Authorize personnel before allowing maintenance access
- Verify credentials of external technicians
- Supervise maintenance activities
MA.L2-3.7.3: Equipment Sanitization
“Ensure equipment removed for off-site maintenance is sanitized of any CUI.”
Before sending equipment for external repair:
- Remove or destroy storage media containing CUI
- Verify no CUI remains on the equipment
- Document sanitization performed
- Use secure disposal methods for media that cannot be sanitized
Sanitization means removing data from storage media so thoroughly that it cannot be recovered, even with forensic tools.
If equipment must retain data for troubleshooting, use cleared maintenance providers or perform repairs on-site.
MA.L2-3.7.4: Media Inspection
“Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.”
Maintenance often involves diagnostic software, firmware updates, or test programs:
- Scan all maintenance media for malware before use
- Verify the integrity of firmware and software updates
- Use trusted sources for maintenance software
- Do not use unknown USB drives or media
This prevents maintenance activities from introducing malware into your environment.
MA.L2-3.7.5: Nonlocal Maintenance
“Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.”
Remote maintenance requires strong controls:
Authentication
- Require multi-factor authentication (MFA) for remote maintenance access
- Do not allow password-only authentication for maintenance sessions
- Verify the identity of remote maintenance personnel
Multi-factor authentication (MFA) requires two or more different verification methods—like a password plus a code from your phone.
Session Management
- Monitor remote maintenance sessions
- Log all activities during remote maintenance
- Terminate sessions immediately when maintenance completes
- Do not leave remote access connections open
Network Controls
- Use encrypted connections (VPN) for remote maintenance
- Limit remote maintenance to approved systems
- Control which external parties can perform remote maintenance
MA.L2-3.7.6: Maintenance Personnel
“Supervise the maintenance activities of maintenance personnel without required access authorization.”
When maintenance personnel do not have authorization to access CUI:
Supervision Requirements
- Escort maintenance personnel at all times
- Observe their activities directly
- Do not leave them unattended with CUI systems
- Verify work performed before they leave
Access Limitations
- Provide only necessary access for the maintenance task
- Remove access immediately when work completes
- Do not provide credentials that allow unsupervised return access
Documentation
- Record who performed maintenance
- Document what systems were accessed
- Note what work was performed
- Maintain visitor logs
Implementing Maintenance Controls
Establish Maintenance Procedures
Document your maintenance practices:
- Patch management schedule and procedures
- Hardware maintenance requirements
- Approved maintenance tools and software
- Procedures for external technicians
- Remote maintenance authorization process
Create a Patch Management Program
Regular patching is the most critical maintenance activity:
- Inventory all systems requiring updates
- Subscribe to vendor security notifications
- Test patches before deployment when possible
- Apply critical security patches promptly
- Document patch status for all systems
Control Maintenance Tools
Manage tools used for maintenance:
- Maintain inventory of approved tools
- Scan portable media before use
- Control access to maintenance equipment
- Verify software integrity before installation
Manage External Maintenance
When using external technicians or sending equipment for repair:
- Sanitize equipment before external repair
- Require background checks for regular maintenance vendors
- Supervise all external maintenance personnel
- Use non-disclosure agreements with maintenance providers
- Verify credentials before granting access
Secure Remote Maintenance
For remote support and maintenance:
- Require MFA for all remote maintenance access
- Use encrypted connections only
- Monitor and log remote sessions
- Terminate connections when complete
- Approve remote maintenance requests in advance
Common Maintenance Mistakes
Mistake 1: Skipping Patches
Delaying patches to avoid disruption accumulates vulnerabilities. Establish regular patching cycles and stick to them.
Mistake 2: Unsupervised Vendors
Allowing external technicians to work unsupervised on CUI systems violates requirements and creates risk. Always supervise unauthorized personnel.
Mistake 3: Forgetting Equipment Sanitization
Sending equipment for repair without removing CUI exposes sensitive data. Sanitize before any equipment leaves your control.
Mistake 4: Password-Only Remote Access
Remote maintenance sessions without MFA violate requirements. Require multi-factor authentication for all remote maintenance.
Mistake 5: No Maintenance Records
Without documentation, you cannot demonstrate compliance or investigate problems. Log all maintenance activities.
Key Takeaways
Maintenance’s 6 requirements ensure systems stay secure during routine upkeep and repairs. Perform regular maintenance, including patching, control maintenance tools and personnel, sanitize equipment before external repair, and secure remote maintenance sessions with MFA.
The key principle is that maintenance activities should not create security gaps. Control who performs maintenance, what tools they use, and what access they have. Document everything.
Keep reading
More in The 14 Control Families
- Access Control (AC) →
- Audit and Accountability (AU) →
- Awareness and Training (AT) →
- CMMC Incident Response (IR) →
- Configuration Management (CM) →
- Identification and Authentication (IA) →
- Media Protection (MP) →
- Personnel Security (PS) →
- Physical Protection (PE) →
- Risk Assessment (RA) →
- Security Assessment (CA) →
- System and Communications Protection (SC) →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5