CMMC control families
CMMC Risk Assessment (3.11 RA): 3 requirements, scanning and remediation
Three requirements: assess the risk, scan for vulnerabilities, remediate against what the assessment said. We quote the scanning licenses and the work of standing the scanning estate up. We do not run the scan, we do not triage the findings, and we never produce the assessment.
- Family
- 3.11 — Risk Assessment
- Requirements
- 3 of the 110 Level 2 requirements
- Level 1
- Not in Level 1 — appears at Level 2
- Boundary
- The capability behind the control — never a certification we hold
Three requirements that turn scanning output into a decision
Risk assessment carries three requirements: periodically assess the risk to organizational operations, assets and individuals from the operation of systems processing, storing or transmitting CUI (3.11.1); scan for vulnerabilities in those systems and applications periodically and when new vulnerabilities affecting them are identified (3.11.2); and remediate vulnerabilities in accordance with the risk assessment (3.11.3). The chain matters: the scan feeds the assessment, and the assessment decides what gets fixed and in what order. A tool produces findings; only your program produces the decision.
What each level asks of this family
Level 1 does not ask you to scan. Risk assessment is one of the eight families that only appear from Level 2 up, so the 15 FAR 52.204-21 requirements behind a Level 1 self-assessment never reach 3.11.1 to 3.11.3.
At Level 2 all three apply, and 3.11.2 is where implementations diverge most. It does not name an interval, a tool or a scan type — it says periodically and when new vulnerabilities affecting the system are identified, which means your period has to be written down and your process has to react to advisories rather than only to the calendar. 3.11.3 then ties remediation back to the assessment, so a scan report nobody triaged is a finding waiting to happen.
Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.
What's quotable, and what stays yours to run
Uniqcli does not assess risk, run scans, triage findings or produce a risk assessment — none of that is a supplier function, and anyone offering it is offering you a consultancy engagement under an equipment invoice. The assessment, the periodicity, the triage and the remediation decisions are your program's. The program stays yours to run — the policy, the decisions, the cadence and the evidence an assessor actually reads. What a supplier puts behind it is the tooling, the licensing and the integration work.
The licensing is genuinely quotable. Vulnerability-scanning subscriptions ride the same distribution as everything else we sell: Tenable's Nessus, Nessus Manager and Passive Vulnerability Scanner lines are priced across hundreds of rows in our catalog, Sophos carries vulnerability-scanning add-ons, and McAfee's scanning modules appear alongside them. Software is sourced through authorized US distribution rather than held on a shelf, so availability language does not apply to it. Qualys and Rapid7 are not in our catalog at all, and we will say so rather than promise to find them. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
The deployment leg is real too. Standing a scanning estate up — sizing and racking the collectors, configuring credentialed access to the systems in scope, and recording what was changed — is work we scope alongside the licenses. It produces a working scanner. It does not produce a finding, a priority or a decision.
We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.
The lines we can genuinely quote
Software, not hardware, and never stocked. We price the subscription and the work of standing it up; the scan, the triage and the remediation decision stay with your team.
Risk assessment questions
How often does CMMC require vulnerability scanning?
3.11.2 requires scanning periodically and when new vulnerabilities affecting the system are identified. No interval is named, so the period is yours to define in the SSP and defend — and the second half matters as much as the first, because it means the process has to react to advisories rather than only to the schedule.
What does RA.L2-3.11.2 require?
It is the CMMC practice identifier for the same requirement: scan for vulnerabilities in organizational systems and applications periodically, and when new vulnerabilities affecting those systems and applications are identified. The Level 2 assessment guide breaks it into objectives covering both triggers, so a documented periodic scan alone does not close it.
How many risk assessment requirements are in NIST SP 800-171?
Three, numbered 3.11.1 to 3.11.3 in Rev 2 — assess risk, scan for vulnerabilities, and remediate in accordance with the assessment. Three of the 110 a Level 2 assessment covers.
Is risk assessment part of CMMC Level 1?
No. Risk assessment is one of the eight Level 2-only families, so scanning is not part of an annual Level 1 self-assessment against the 15 FAR 52.204-21 requirements. A contractor handling CUI carries 3.11 through DFARS 252.204-7012 either way.
Related families and background
Get a CMMC estimate — CMMC Risk Assessment (3.11 RA)
Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.
An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Talk to us about the scanning estate
Send the seat or asset count and your renewal date. A Uniqcli specialist replies with an estimate for the subscription and any collector hardware or standing-up work it needs — quoted against your term, with no claim that we run the scan, triage the findings or produce the assessment.