Uniqcli

CMMC control families

CMMC Risk Assessment (3.11 RA): 3 requirements, scanning and remediation

Three requirements: assess the risk, scan for vulnerabilities, remediate against what the assessment said. We quote the scanning licenses and the work of standing the scanning estate up. We do not run the scan, we do not triage the findings, and we never produce the assessment.

Family
3.11 — Risk Assessment
Requirements
3 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

Three requirements that turn scanning output into a decision

Risk assessment carries three requirements: periodically assess the risk to organizational operations, assets and individuals from the operation of systems processing, storing or transmitting CUI (3.11.1); scan for vulnerabilities in those systems and applications periodically and when new vulnerabilities affecting them are identified (3.11.2); and remediate vulnerabilities in accordance with the risk assessment (3.11.3). The chain matters: the scan feeds the assessment, and the assessment decides what gets fixed and in what order. A tool produces findings; only your program produces the decision.

Levels

What each level asks of this family

Level 1 does not ask you to scan. Risk assessment is one of the eight families that only appear from Level 2 up, so the 15 FAR 52.204-21 requirements behind a Level 1 self-assessment never reach 3.11.1 to 3.11.3.

At Level 2 all three apply, and 3.11.2 is where implementations diverge most. It does not name an interval, a tool or a scan type — it says periodically and when new vulnerabilities affecting the system are identified, which means your period has to be written down and your process has to react to advisories rather than only to the calendar. 3.11.3 then ties remediation back to the assessment, so a scan report nobody triaged is a finding waiting to happen.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

Limits

What's quotable, and what stays yours to run

Uniqcli does not assess risk, run scans, triage findings or produce a risk assessment — none of that is a supplier function, and anyone offering it is offering you a consultancy engagement under an equipment invoice. The assessment, the periodicity, the triage and the remediation decisions are your program's. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.

The licensing is genuinely quotable. Vulnerability-scanning subscriptions ride the same distribution as everything else we sell: Tenable's Nessus, Nessus Manager and Passive Vulnerability Scanner lines are priced across hundreds of rows in our catalog, Sophos carries vulnerability-scanning add-ons, and McAfee's scanning modules appear alongside them. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Qualys and Rapid7 are not in our catalog at all, and we will say so rather than promise to find them. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

The deployment leg is real too. Standing a scanning estate up — sizing and racking the collectors, configuring credentialed access to the systems in scope, and recording what was changed — is work we scope alongside the licenses. It produces a working scanner. It does not produce a finding, a priority or a decision.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Scanning licenses

The lines we can genuinely quote

Software, not hardware, and never stocked. We price the subscription and the work of standing it up; the scan, the triage and the remediation decision stay with your team.

Questions

Risk assessment questions

How often does CMMC require vulnerability scanning?

3.11.2 requires scanning periodically and when new vulnerabilities affecting the system are identified. No interval is named, so the period is yours to define in the SSP and defend — and the second half matters as much as the first, because it means the process has to react to advisories rather than only to the schedule.

What does RA.L2-3.11.2 require?

It is the CMMC practice identifier for the same requirement: scan for vulnerabilities in organizational systems and applications periodically, and when new vulnerabilities affecting those systems and applications are identified. The Level 2 assessment guide breaks it into objectives covering both triggers, so a documented periodic scan alone does not close it.

How many risk assessment requirements are in NIST SP 800-171?

Three, numbered 3.11.1 to 3.11.3 in Rev 2 — assess risk, scan for vulnerabilities, and remediate in accordance with the assessment. Three of the 110 a Level 2 assessment covers.

Is risk assessment part of CMMC Level 1?

No. Risk assessment is one of the eight Level 2-only families, so scanning is not part of an annual Level 1 self-assessment against the 15 FAR 52.204-21 requirements. A contractor handling CUI carries 3.11 through DFARS 252.204-7012 either way.

Get a CMMC estimate — CMMC Risk Assessment (3.11 RA)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Risk Assessment (3.11 RA)

Talk to us about the scanning estate

Send the seat or asset count and your renewal date. A Uniqcli specialist replies with an estimate for the subscription and any collector hardware or standing-up work it needs — quoted against your term, with no claim that we run the scan, triage the findings or produce the assessment.