Uniqcli

CMMC control families

CMMC Maintenance (3.7 MA): 6 requirements, support contracts and sanitizing before service

Six requirements about who maintains your systems, with what tools, watched by whom — and what has to happen to a machine before it leaves your boundary for repair. The authorization and the supervision are yours. OEM support and maintenance contracts, the out-of-band access at 3.7.5 and refresh planning are all quotable line items.

Family
3.7 — Maintenance
Requirements
6 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

Who touches the equipment, with what, and what leaves the building

Maintenance carries six requirements. You perform maintenance on your systems (3.7.1) and control the tools, techniques, mechanisms and personnel used to do it (3.7.2). Equipment removed for off-site maintenance has to be sanitized of CUI first (3.7.3). Media carrying diagnostic and test programs has to be checked for malicious code (3.7.4). Nonlocal maintenance sessions established over external network connections need multifactor authentication and have to be terminated when the work is done (3.7.5). And maintenance personnel without the required access authorization have to be supervised (3.7.6). The authorization, the tool control and the supervision are your program's. Everything the maintenance actually runs on is procurement: the OEM support, maintenance and warranty contracts that entitle you to the fix in the first place — one of the largest priced categories in our catalog — the out-of-band access path 3.7.5 is written about, and the refresh planning that decides when a machine stops being maintained and starts being replaced.

Levels

What each level asks of this family

Level 1 never asks who touched the equipment. All six maintenance requirements land at Level 2 — the family is not among the six that Level 1's 15 FAR 52.204-21 requirements reach.

At Level 2 all six apply, and the two that generate assessment findings most reliably are 3.7.3 and 3.7.5. The first is a discipline question — does a failed drive actually get pulled before the chassis goes back to the manufacturer? The second is an architecture question — is the remote hands path authenticated with more than a password, and does it close when the vendor hangs up?

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote against this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Limits

Where the line falls

Maintenance authorization, tool control, supervision of uncleared personnel and the records that evidence all three are your program's work — a support contract entitles you to a fix, it does not decide who is allowed to touch the rack.

There is also no sanitization equipment to sell. Our catalog carries no degaussers at all, and shredder availability is thin enough that it is a quote-only line rather than a shelf. For most contractors the practical answer to 3.7.3 is procedural: pull and retain the drive before the chassis leaves, buy a replacement, and handle the retained drive under media protection's sanitization and destruction requirement at 3.8.3. That is cheaper, more defensible and easier to evidence than any machine we could sell you.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Maintenance questions

Do you have to sanitize equipment before sending it out for repair?

Yes — 3.7.3 requires equipment removed for off-site maintenance to be sanitized of any CUI. In practice most contractors satisfy it by removing and retaining the storage media before the chassis leaves, then handling that media under 3.8.3. We do not sell sanitization equipment; we can quote the replacement drive, and the retained one stays your problem to sanitize or destroy on a documented process.

What are the CMMC nonlocal maintenance requirements?

3.7.5 requires multifactor authentication to establish nonlocal maintenance sessions over external network connections, and requires those connections to be terminated when the maintenance is complete. It is aimed squarely at vendor remote-hands access. The out-of-band console and KVM-over-IP hardware those sessions run on is something we quote; the authentication and the termination discipline are configuration and procedure.

How many maintenance requirements are in NIST SP 800-171?

Six, numbered 3.7.1 to 3.7.6 in Rev 2. They cover performing maintenance, controlling the tools and personnel, sanitizing equipment before off-site service, checking diagnostic media for malicious code, authenticating and terminating nonlocal sessions, and supervising maintenance personnel who lack the required access authorization.

Is maintenance assessed at CMMC Level 1?

No. Maintenance is one of the eight Level 2-only families — none of the 15 FAR 52.204-21 requirements behind a Level 1 self-assessment reach it. Contractors handling CUI carry 3.7 through DFARS 252.204-7012 regardless of level.

Get a CMMC estimate — CMMC Maintenance (3.7 MA)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Maintenance (3.7 MA)

Talk to us about coverage and out-of-band access

Send the rack layout, the remote-hands design or the serial list you are renewing against. A Uniqcli specialist replies with an estimate for the support and maintenance coverage, the console and KVM-over-IP hardware and any refresh planning the estate needs — availability stated per line, TAA and §889 screening performed before it goes out.