2% of CMMC 2.0 you already have
NIST SP 800-53A Rev. 5 already covers about 2% of CMMC 2.0, leaving
108 of 110 controls as genuinely new work.
Already covered 0
Likely covered 2
New work 108
No control in NIST SP 800-53A Rev. 5
maps directly to one in CMMC 2.0. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-53A Rev. 5 reaches these. This is the list to scope.
AC.L2-3.1.1Authorized Access Control
AC.L2-3.1.11Session Termination
AC.L2-3.1.12Control Remote Access
AC.L2-3.1.13Remote Access Confidentiality
AC.L2-3.1.14Remote Access Routing
AC.L2-3.1.15Privileged Remote Access
AC.L2-3.1.16Wireless Access Authorization
AC.L2-3.1.17Wireless Access Protection
AC.L2-3.1.18Mobile Device Connection
AC.L2-3.1.19Encrypt CUI on Mobile
AC.L2-3.1.2Transaction & Function Control
AC.L2-3.1.20External Connections
AC.L2-3.1.21Portable Storage Use
AC.L2-3.1.22Control Public Information
AC.L2-3.1.3Control CUI Flow
AC.L2-3.1.4Separation of Duties
AC.L2-3.1.5Least Privilege
AC.L2-3.1.6Non-Privileged Account Use
AC.L2-3.1.7Privileged Functions
AC.L2-3.1.8Unsuccessful Logon Attempts
AC.L2-3.1.9Privacy & Security Notices
AT.L2-3.2.1Role-Based Risk Awareness
AT.L2-3.2.2Role-Based Training
AT.L2-3.2.3Insider Threat Awareness
AU.L2-3.3.1System Auditing
AU.L2-3.3.2User Accountability
AU.L2-3.3.4Audit Failure Alerting
AU.L2-3.3.5Audit Correlation
AU.L2-3.3.6Reduction & Reporting
AU.L2-3.3.7Time Stamps & Synchronization
AU.L2-3.3.8Audit Protection
AU.L2-3.3.9Audit Management
CA.L2-3.12.3Security Control Monitoring
CA.L2-3.12.4System Security Plan
CM.L2-3.4.1System Baselining
CM.L2-3.4.2Security Configuration Enforcement
CM.L2-3.4.3System Change Management
CM.L2-3.4.4Security Impact Analysis
CM.L2-3.4.5Access Restrictions for Change
CM.L2-3.4.6Least Functionality
CM.L2-3.4.7Nonessential Functionality
CM.L2-3.4.8Application Execution Policy
CM.L2-3.4.9User-Installed Software
IA.L2-3.5.1Identification
IA.L2-3.5.10Cryptographically-Protected Passwords
IA.L2-3.5.11Obscure Feedback
IA.L2-3.5.2Authentication
IA.L2-3.5.3Multifactor Authentication
IA.L2-3.5.4Replay-Resistant Authentication
IA.L2-3.5.5Identifier Reuse
IA.L2-3.5.6Identifier Handling
IA.L2-3.5.7Password Complexity
IA.L2-3.5.8Password Reuse
IA.L2-3.5.9Temporary Passwords
IR.L2-3.6.1Incident Handling
IR.L2-3.6.2Incident Reporting
IR.L2-3.6.3Incident Response Testing
MA.L2-3.7.1Perform Maintenance
MA.L2-3.7.2System Maintenance Control
MA.L2-3.7.3Equipment Sanitization
MA.L2-3.7.4Media Inspection
MA.L2-3.7.5Nonlocal Maintenance
MA.L2-3.7.6Maintenance Personnel
MP.L2-3.8.1Media Protection
MP.L2-3.8.3Media Disposal
MP.L2-3.8.4Media Markings
MP.L2-3.8.5Media Accountability
MP.L2-3.8.6Portable Storage Encryption
MP.L2-3.8.7Removable Media
MP.L2-3.8.9Protect Backups
PE.L2-3.10.1Limit Physical Access
PE.L2-3.10.2Monitor Facility
PE.L2-3.10.3Escort Visitors
PE.L2-3.10.4Physical Access Logs
PE.L2-3.10.5Manage Physical Access
PE.L2-3.10.6Alternative Work Sites
PS.L2-3.9.1Screen Individuals
PS.L2-3.9.2Personnel Actions
RA.L2-3.11.1Risk Assessments
RA.L2-3.11.2Vulnerability Scan
RA.L2-3.11.3Vulnerability Remediation
SC.L2-3.13.1Boundary Protection
SC.L2-3.13.10Key Management
SC.L2-3.13.11CUI Encryption
SC.L2-3.13.12Collaborative Device Control
SC.L2-3.13.14Voice over Internet Protocol
SC.L2-3.13.15Communications Authenticity
SC.L2-3.13.16Data at Rest
SC.L2-3.13.2Security Engineering
SC.L2-3.13.3Role Separation
SC.L2-3.13.4Shared Resource Control
SC.L2-3.13.5Public-Access System Separation
SC.L2-3.13.6Network Communication by Exception
SC.L2-3.13.7Split Tunneling
SC.L2-3.13.8Data in Transit
SC.L2-3.13.9Connections Termination
SI.L2-3.14.1Flaw Remediation
SI.L2-3.14.2Malicious Code Protection
SI.L2-3.14.3Security Alerts & Advisories
SI.L2-3.14.4Update Malicious Code Protection
SI.L2-3.14.5System & File Scanning
SI.L2-3.14.6Monitor Communications for Attacks
SI.L2-3.14.7Identify Unauthorized Use
Show the 2 you already have
CA.L2-3.12.1Security Control Assessment
CA.L2-3.12.2Plan of Action
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-53A Rev. 5 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition