CMMC control families
CMMC Maintenance (3.7 MA): 6 requirements, support contracts and sanitizing before service
Six requirements about who maintains your systems, with what tools, watched by whom — and what has to happen to a machine before it leaves your boundary for repair. The authorization and the supervision are yours. OEM support and maintenance contracts, the out-of-band access at 3.7.5 and refresh planning are all quotable line items.
- Family
- 3.7 — Maintenance
- Requirements
- 6 of the 110 Level 2 requirements
- Level 1
- Not in Level 1 — appears at Level 2
- Boundary
- The capability behind the control — never a certification we hold
Who touches the equipment, with what, and what leaves the building
Maintenance carries six requirements. You perform maintenance on your systems (3.7.1) and control the tools, techniques, mechanisms and personnel used to do it (3.7.2). Equipment removed for off-site maintenance has to be sanitized of CUI first (3.7.3). Media carrying diagnostic and test programs has to be checked for malicious code (3.7.4). Nonlocal maintenance sessions established over external network connections need multifactor authentication and have to be terminated when the work is done (3.7.5). And maintenance personnel without the required access authorization have to be supervised (3.7.6). The authorization, the tool control and the supervision are your program's. Everything the maintenance actually runs on is procurement: the OEM support, maintenance and warranty contracts that entitle you to the fix in the first place — one of the largest priced categories in our catalog — the out-of-band access path 3.7.5 is written about, and the refresh planning that decides when a machine stops being maintained and starts being replaced.
What each level asks of this family
Level 1 never asks who touched the equipment. All six maintenance requirements land at Level 2 — the family is not among the six that Level 1's 15 FAR 52.204-21 requirements reach.
At Level 2 all six apply, and the two that generate assessment findings most reliably are 3.7.3 and 3.7.5. The first is a discipline question — does a failed drive actually get pulled before the chassis goes back to the manufacturer? The second is an architecture question — is the remote hands path authenticated with more than a password, and does it close when the vendor hangs up?
Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.
What you can actually quote against this family
Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
OEM support and maintenance contracts (3.7.1)
Support, maintenance, warranty and on-site service contracts are the second-largest priced category in our catalog, carried across well over a hundred manufacturers. They are quoted the way any other line is — attached to new hardware, or renewed against an installed base by serial and coverage tier. The entitlement is the manufacturer's program; we source it and price it, and the coverage level you choose is the one an assessor will read against 3.7.1.
Nonlocal maintenance (3.7.5)
Nonlocal maintenance rides out-of-band paths, and serial console servers and KVM-over-IP are the equipment those paths run on — Lantronix, Perle, Opengear, Digi, ATEN, Vertiv's Avocent line, Black Box and Eaton all appear, with availability stated on the quote. Secure remote-access subscriptions on the boundary platforms we carry sit alongside them. The multifactor authentication and the session-termination discipline are configuration on top, not features of the box. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
Refresh and lifecycle planning
Maintenance ends where replacement begins, and that boundary is a planning question rather than a purchase. Our logistics lane runs asset tracking, refresh scheduling and reverse logistics for decommissioned equipment as one program, so an asset tagged on the dock keeps one identity through staging, delivery, every refresh and eventual retirement.
Where the line falls
Maintenance authorization, tool control, supervision of uncleared personnel and the records that evidence all three are your program's work — a support contract entitles you to a fix, it does not decide who is allowed to touch the rack.
There is also no sanitization equipment to sell. Our catalog carries no degaussers at all, and shredder availability is thin enough that it is a quote-only line rather than a shelf. For most contractors the practical answer to 3.7.3 is procedural: pull and retain the drive before the chassis leaves, buy a replacement, and handle the retained drive under media protection's sanitization and destruction requirement at 3.8.3. That is cheaper, more defensible and easier to evidence than any machine we could sell you.
We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.
Maintenance questions
Do you have to sanitize equipment before sending it out for repair?
Yes — 3.7.3 requires equipment removed for off-site maintenance to be sanitized of any CUI. In practice most contractors satisfy it by removing and retaining the storage media before the chassis leaves, then handling that media under 3.8.3. We do not sell sanitization equipment; we can quote the replacement drive, and the retained one stays your problem to sanitize or destroy on a documented process.
What are the CMMC nonlocal maintenance requirements?
3.7.5 requires multifactor authentication to establish nonlocal maintenance sessions over external network connections, and requires those connections to be terminated when the maintenance is complete. It is aimed squarely at vendor remote-hands access. The out-of-band console and KVM-over-IP hardware those sessions run on is something we quote; the authentication and the termination discipline are configuration and procedure.
How many maintenance requirements are in NIST SP 800-171?
Six, numbered 3.7.1 to 3.7.6 in Rev 2. They cover performing maintenance, controlling the tools and personnel, sanitizing equipment before off-site service, checking diagnostic media for malicious code, authenticating and terminating nonlocal sessions, and supervising maintenance personnel who lack the required access authorization.
Is maintenance assessed at CMMC Level 1?
No. Maintenance is one of the eight Level 2-only families — none of the 15 FAR 52.204-21 requirements behind a Level 1 self-assessment reach it. Contractors handling CUI carry 3.7 through DFARS 252.204-7012 regardless of level.
Related families and background
Get a CMMC estimate — CMMC Maintenance (3.7 MA)
Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Talk to us about coverage and out-of-band access
Send the rack layout, the remote-hands design or the serial list you are renewing against. A Uniqcli specialist replies with an estimate for the support and maintenance coverage, the console and KVM-over-IP hardware and any refresh planning the estate needs — availability stated per line, TAA and §889 screening performed before it goes out.