Skip to content
ControlVerdict
IR.L2-3.6.2CMMC Level 2Level 2

Incident Reporting

Practice statement

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.6.2.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(6)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    incidents are tracked;

    1 example covers this

  2. [b]

    incidents are documented;

    1 example covers this

  3. [c]

    authorities to whom incidents are to be reported are identified;

    1 example covers this

  4. [d]

    organizational officials to whom incidents are to be reported are identified;

    1 example covers this

  5. [e]

    identified authorities are notified of incidents; and

    1 example covers this

  6. [f]

    identified organizational officials are notified of incidents.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    IR.L2-3.6.2Incident Reporting
    Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
    • [a]

      incidents are tracked;
    • [b]

      incidents are documented;
    • [c]

      authorities to whom incidents are to be reported are identified;
    • [d]

      organizational officials to whom incidents are to be reported are identified;
    • [e]

      identified authorities are notified of incidents; and
    • [f]

      identified organizational officials are notified of incidents.

    One case record drives internal escalation and the 72-hour external report

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses all Incident Reporting objectives: tracking and documenting incidents, identifying both the external authorities and the internal officials to notify, and actually notifying each.

    Tracking. Every incident, including ones that turn out to be false positives, gets a case number in the case management system at intake. Cases carry status, severity, assigned responder, and the current CUI determination. Nothing is tracked in email threads or a personal notebook; the case record is the system of record and it is what an assessor will be shown.

    Documentation. A case cannot be closed without: the timeline, systems and accounts involved, the CUI determination and its basis, actions taken with timestamps, notifications made with recipients and times, root cause, and after-action items. A closure template enforces the fields, which is the only reason they get filled in consistently.

    Identified authorities (external). The reporting matrix names each external recipient and its trigger and deadline: the DoD reporting portal for a cyber incident affecting covered defense information or the ability to perform on the contract, within 72 hours of discovery; the affected prime or customer per the specific contract's notification clause; law enforcement where criminal activity is suspected, through counsel; and state breach notification authorities where personal information is implicated. Each row cites the clause or statute so nobody argues about deadlines mid-incident.

    Identified officials (internal). The same matrix names internal recipients: the incident commander immediately, the ISSO and IT director for any severity, the general counsel and contracts lead when a CUI determination is positive or ambiguous, the CEO for high severity, and the program manager for the affected contract. Ambiguity resolves toward notification.

    Actually notifying. Notification is a checklist item inside the case with a timestamp and the recipient, not an assumption. The 72-hour clock starts at discovery and is displayed on the case; a countdown reminder fires at 24 and 48 hours. The portal submission is prepared by the ISSO, reviewed by counsel, and submitted with the certificate — and because the certificate and the submitting account are tested annually, the first time we use them is not during a real incident.

    Maintenance. The matrix is reviewed when a new contract with different notification terms is signed, and annually otherwise. Notification timeliness is measured in the after-action.

    Accepted gap. Determining whether CUI was actually accessed rather than merely accessible is often not possible within 72 hours. We report on the conservative reading and supplement the submission as analysis completes, which the after-action documents.

    What the evidence looks like

    • Incident reporting matrix listing external authorities and internal officials with triggers and deadlines
    • Case management closure template showing the required documentation fields
    • Redacted closed case with notification timestamps and recipients
    • Annual test record for the reporting portal credential and submitting account
    • Contract review note showing the matrix updated for a new customer's notification clause

    Environment

    Prime subcontractor carrying the DFARS cyber incident reporting flowdown. Contracts and outside counsel must be in the loop before any external notification; the medium assurance certificate needed for the DoD reporting portal is already issued and tested.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.