Uniqcli

CMMC control families

CMMC Configuration Management (3.4 CM): 9 requirements, baselines, inventory and the tooling behind them

Nine requirements about baselines, change control, least functionality and what users are allowed to install. Authoring the baseline is engineering work only your program can do. Building to it is not — imaging, firmware baselining and configuration staging are how our OEM lane ships hardware, and the allowlisting and patch tooling above it is licensable.

Family
3.4 — Configuration Management
Requirements
9 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

Know what you have, decide how it should be set, and control what changes

Configuration management carries nine requirements. You establish and maintain baseline configurations and inventories of the systems in scope (3.4.1); you set and enforce security configuration settings (3.4.2); you track, review, approve and log changes (3.4.3); you apply least functionality by configuring systems to provide only essential capabilities (3.4.6) and by restricting or disabling nonessential programs, ports, protocols and services (3.4.7); you take a deny-by-exception or permit-by-exception position on software execution (3.4.8); and you control user-installed software (3.4.9). Deciding what the baseline says is work your engineers do, and no invoice reaches it. Everything downstream of that decision is a supply question: the allowlisting, patch and asset-visibility tooling that enforces and reports on it, the imaging and configuration staging that builds a machine to it before it ships, and the labels and scanners that keep the inventory half of 3.4.1 current.

Levels

What each level asks of this family

Level 1 never asks for a baseline. Configuration management sits outside the six families the 15 FAR 52.204-21 requirements touch, which is why a contractor moving up to Level 2 usually meets 3.4 as new work rather than as an upgrade to something already in place.

At Level 2 all nine apply. The pair that generates the most assessment traffic is 3.4.1 and 3.4.2 — a baseline you can produce on demand and settings that actually match it — followed by the least-functionality requirements at 3.4.6 and 3.4.7 and the software-execution position at 3.4.8, where application allowlisting is one recognized way of answering but not the only one the requirement admits.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Software execution control (3.4.8, 3.4.9)

3.4.8 asks for a deny-by-exception or permit-by-exception position on software execution, and allowlisting is one recognized way of implementing the permit-by-exception side — not the only one the requirement admits. ThreatLocker's allowlisting and ringfencing lines are priced across our licensing catalog, with Trend Micro's and WatchGuard's application-control lines alongside them. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Patch and configuration tooling (3.4.2, 3.4.6)

Settings that match the baseline, and stay matched, are usually reported by the endpoint platform rather than by hand. Bitdefender's GravityZone patch modules and WatchGuard's and Trend Micro's configuration and policy lines are priced in our catalog; Absolute's data-and-device-security subscriptions sit alongside them as device posture and visibility rather than patching. Quoted per seat against your term; the baseline they enforce is still yours to write.

Built to the baseline before it ships (3.4.1, 3.4.2)

Units ship configured, not factory-default: through our OEM-integration lane we load your OS images, firmware versions and configuration files and validate against your baseline before burn-in, logging the asset tag, the serial, the loaded image and the firmware level against each unit. Custom builds run the same way — consign the material against the bill of materials, or we source it turnkey through TAA-compliant channels.

Keeping the inventory current (3.4.1)

An inventory is a record of physical things, and physical things get tagged and scanned. Asset labels and barcode scanners are ordinary supply we quote like any other consumable — Zebra, Honeywell and Socket Mobile all appear, with availability that varies by model. That equips the inventory; it does not perform it.

Limits

Where the line falls

Authoring the baseline is the part nobody can sell you. What the approved specification says, which settings are security-relevant, what counts as essential capability under 3.4.6, which change gets approved under 3.4.3 and whether the deployed estate actually matches any of it are engineering decisions and engineering evidence. A tool reports drift; it does not decide what drift means.

Nothing here is an attestation either. We can build a machine to the image you supply and record what we loaded onto it; we cannot attest that the resulting configuration satisfies a requirement. That judgement belongs to your program and, where relevant, your assessor.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Configuration management questions

What is a baseline configuration under CMMC?

A documented, approved specification of how a system is built and set — the software, the versions, the settings and the network configuration — that later changes are measured against. 3.4.1 requires you to establish and maintain baselines along with inventories of the systems in scope, and 3.4.2 requires you to establish and enforce the security configuration settings that go with them. The baseline is a document your engineers own; nothing you buy produces it.

Does CMMC require an asset inventory?

Yes — 3.4.1 pairs baseline configurations with inventories of organizational systems, and scoping the assessment is impossible without one. The inventory has to cover what is in the CUI boundary and be current enough to defend. Labels and scanners make maintaining it practical; they do not make it exist.

How many configuration management requirements are in NIST 800-171?

Nine, numbered 3.4.1 to 3.4.9 in Rev 2 — the revision still pinned for DoD work by Class Deviation 2024-O0013. All nine appear at Level 2; none are scored at Level 1.

Is application allowlisting required for CMMC Level 2?

3.4.8 requires a deny-by-exception or permit-by-exception policy for software execution, and allowlisting is the common way of implementing the permit-by-exception side. The requirement is written about the policy and its enforcement, not about a named product, so the honest answer is that your implementation has to satisfy the objective in the DoD assessment guide — a decision for your program and, where relevant, your assessor.

Get a CMMC estimate — CMMC Configuration Management (3.4 CM)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Configuration Management (3.4 CM)

Send the image, not the baseline

Writing the baseline is yours. Building to it is ours: send the image, the firmware levels and the fleet, and a Uniqcli specialist replies with an estimate covering the units, the imaging and staging work, the allowlisting or patch subscriptions the design calls for, and the labels and scanners that keep 3.4.1's inventory current — availability stated per line, TAA and §889 screening performed before it goes out.