Framework overlap

Does CMMC 2.0 Level 1 cover CMMC 2.0?

You hold CMMC 2.0 Level 1 and have been told to do CMMC 2.0. Here is how much overlaps, control by control.

16% of CMMC 2.0 you already have

CMMC 2.0 Level 1 already covers about 16% of CMMC 2.0, leaving 92 of 110 controls as genuinely new work.

Already covered 17 Likely covered 1 New work 92

What is genuinely new work

Nothing in CMMC 2.0 Level 1 reaches these. This is the list to scope.

AC.L2-3.1.10
Session Lock
AC.L2-3.1.11
Session Termination
AC.L2-3.1.12
Control Remote Access
AC.L2-3.1.13
Remote Access Confidentiality
AC.L2-3.1.14
Remote Access Routing
AC.L2-3.1.15
Privileged Remote Access
AC.L2-3.1.16
Wireless Access Authorization
AC.L2-3.1.17
Wireless Access Protection
AC.L2-3.1.18
Mobile Device Connection
AC.L2-3.1.19
Encrypt CUI on Mobile
AC.L2-3.1.21
Portable Storage Use
AC.L2-3.1.3
Control CUI Flow
AC.L2-3.1.4
Separation of Duties
AC.L2-3.1.5
Least Privilege
AC.L2-3.1.6
Non-Privileged Account Use
AC.L2-3.1.7
Privileged Functions
AC.L2-3.1.8
Unsuccessful Logon Attempts
AC.L2-3.1.9
Privacy & Security Notices
AT.L2-3.2.1
Role-Based Risk Awareness
AT.L2-3.2.2
Role-Based Training
AT.L2-3.2.3
Insider Threat Awareness
AU.L2-3.3.1
System Auditing
AU.L2-3.3.2
User Accountability
AU.L2-3.3.3
Event Review
AU.L2-3.3.4
Audit Failure Alerting
AU.L2-3.3.5
Audit Correlation
AU.L2-3.3.6
Reduction & Reporting
AU.L2-3.3.7
Time Stamps & Synchronization
AU.L2-3.3.8
Audit Protection
AU.L2-3.3.9
Audit Management
CA.L2-3.12.1
Security Control Assessment
CA.L2-3.12.2
Plan of Action
CA.L2-3.12.3
Security Control Monitoring
CA.L2-3.12.4
System Security Plan
CM.L2-3.4.1
System Baselining
CM.L2-3.4.2
Security Configuration Enforcement
CM.L2-3.4.3
System Change Management
CM.L2-3.4.4
Security Impact Analysis
CM.L2-3.4.5
Access Restrictions for Change
CM.L2-3.4.6
Least Functionality
CM.L2-3.4.7
Nonessential Functionality
CM.L2-3.4.8
Application Execution Policy
CM.L2-3.4.9
User-Installed Software
IA.L2-3.5.10
Cryptographically-Protected Passwords
IA.L2-3.5.11
Obscure Feedback
IA.L2-3.5.4
Replay-Resistant Authentication
IA.L2-3.5.5
Identifier Reuse
IA.L2-3.5.6
Identifier Handling
IA.L2-3.5.7
Password Complexity
IA.L2-3.5.8
Password Reuse
IA.L2-3.5.9
Temporary Passwords
IR.L2-3.6.1
Incident Handling
IR.L2-3.6.2
Incident Reporting
IR.L2-3.6.3
Incident Response Testing
MA.L2-3.7.1
Perform Maintenance
MA.L2-3.7.2
System Maintenance Control
MA.L2-3.7.3
Equipment Sanitization
MA.L2-3.7.4
Media Inspection
MA.L2-3.7.5
Nonlocal Maintenance
MA.L2-3.7.6
Maintenance Personnel
MP.L2-3.8.1
Media Protection
MP.L2-3.8.2
Media Access
MP.L2-3.8.4
Media Markings
MP.L2-3.8.5
Media Accountability
MP.L2-3.8.6
Portable Storage Encryption
MP.L2-3.8.7
Removable Media
MP.L2-3.8.8
Shared Media
MP.L2-3.8.9
Protect Backups
PE.L2-3.10.2
Monitor Facility
PE.L2-3.10.6
Alternative Work Sites
PS.L2-3.9.1
Screen Individuals
PS.L2-3.9.2
Personnel Actions
RA.L2-3.11.1
Risk Assessments
RA.L2-3.11.2
Vulnerability Scan
RA.L2-3.11.3
Vulnerability Remediation
SC.L2-3.13.10
Key Management
SC.L2-3.13.11
CUI Encryption
SC.L2-3.13.12
Collaborative Device Control
SC.L2-3.13.13
Mobile Code
SC.L2-3.13.14
Voice over Internet Protocol
SC.L2-3.13.15
Communications Authenticity
SC.L2-3.13.16
Data at Rest
SC.L2-3.13.2
Security Engineering
SC.L2-3.13.3
Role Separation
SC.L2-3.13.4
Shared Resource Control
SC.L2-3.13.6
Network Communication by Exception
SC.L2-3.13.7
Split Tunneling
SC.L2-3.13.8
Data in Transit
SC.L2-3.13.9
Connections Termination
SI.L2-3.14.3
Security Alerts & Advisories
SI.L2-3.14.6
Monitor Communications for Attacks
SI.L2-3.14.7
Identify Unauthorized Use
Show the 18 you already have
AC.L2-3.1.1
Authorized Access Control
AC.L2-3.1.2
Transaction & Function Control
AC.L2-3.1.20
External Connections
AC.L2-3.1.22
Control Public Information
IA.L2-3.5.1
Identification
IA.L2-3.5.2
Authentication
MP.L2-3.8.3
Media Disposal
PE.L2-3.10.1
Limit Physical Access
PE.L2-3.10.3
Escort Visitors
PE.L2-3.10.4
Physical Access Logs
PE.L2-3.10.5
Manage Physical Access
SC.L2-3.13.1
Boundary Protection
SC.L2-3.13.5
Public-Access System Separation
SI.L2-3.14.1
Flaw Remediation
SI.L2-3.14.2
Malicious Code Protection
SI.L2-3.14.4
Update Malicious Code Protection
SI.L2-3.14.5
System & File Scanning
IA.L2-3.5.3
Multifactor Authentication

How this is calculated

Already covered means a mapping runs from a control in CMMC 2.0 Level 1 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition