Learn CMMC

CMMC continuous monitoring: keeping compliance real between assessments

Controls drift. People leave, systems change, vendors lose authorizations. Continuous monitoring is the discipline that catches drift while it is cheap, and it is a requirement in its own right.

Key takeaways

  • Continuous monitoring is a requirement in its own right (3.12.3), not a best practice.
  • Controls drift through people, infrastructure and vendor changes. Drift found at reassessment is expensive; drift found in a monthly review is cheap.
  • Set a review frequency per family, name an owner, and define what "current" evidence means.
  • Rev. 3 would make several review frequencies explicit parameters. Writing yours down now costs nothing.

What continuous monitoring is

Continuous monitoring is the ongoing work of reviewing, maintaining and verifying your controls after they are in place. It is required by requirement 3.12.3, which asks you to monitor security controls on an ongoing basis to ensure their continued effectiveness.

A Level 2 certification is valid for three years, but the annual affirmation asks a senior official to state that the controls still work, and a reassessment checks that they were maintained throughout. Neither is survivable without a monitoring program.

Why it matters

Without active monitoring controls degrade. The industry calls it compliance drift, and it is the most common reason organizations struggle at reassessment. Controls that were fully implemented two years ago stop being effective because of:

  • People: new hires who were never shown the procedure, key staff who leave.
  • Infrastructure: new systems, cloud migrations, network changes that move the CUI boundary.
  • Vendors: providers that lose an authorization, change service, or get replaced.
  • Threats: new vulnerabilities and attack paths.

Organizations without a monitoring program routinely discover at reassessment that controls implemented two years earlier no longer work. By then remediation is urgent and expensive. A program catches drift when it is easy to fix.

Building the program

  1. Set a review frequency per family

    Technical families like Audit and Accountability need monthly attention. Personnel Security may need annual review. Set the cadence by how fast each family drifts.

  2. Name an owner per family

    Someone reviews the evidence, confirms the control still works, and escalates. Without a name, reviews do not happen.

  3. Define current evidence

    A vulnerability scan from twelve months ago is stale. Training records from last quarter are current. Decide, write it down, and track when each artifact was last reviewed.

  4. Track review status per control

    Current, due soon, or overdue. That is the at-a-glance health of the program.

  5. Watch the aggregate

    Roll the review statuses into one health measure. A falling number is the early warning.

In Bedrock CMMC

The monitoring dashboard does this for you: frequencies per family, review status per requirement, evidence ageing, and a health score that updates as reviews are completed or evidence expires. See it running.

Review frequencies by domain

These are starting points. Adjust for your environment and risk. Revision 3 of NIST SP 800-171 would make several of these frequencies organization-defined parameters that an assessor checks, and the Department has published its own values in preparation; if you plan to dual-track, align your cadence with them.

FrequencyDomainWhy
MonthlyAudit and Accountability (AU)Log review is a continuous activity
MonthlySystem and Information Integrity (SI)Patching, malware protection and scanning are ongoing
MonthlyConfiguration Management (CM)Change tracking and baseline drift
QuarterlyAccess Control (AC)Access reviews, privilege audits, account management
QuarterlyIdentification and Authentication (IA)MFA coverage and authenticator hygiene
QuarterlyRisk Assessment (RA)Scan results and risk posture
QuarterlySystem and Communications Protection (SC)Segmentation, encryption, boundary devices
Semi-annualIncident Response (IR)Review incidents quarterly, test the plan annually
Semi-annualSecurity Assessment (CA)Control effectiveness reviews
AnnualAwareness and Training (AT)Completion tracking and content refresh
AnnualPhysical Protection (PE)Access reviews and facility changes
AnnualPersonnel Security (PS)Screening and termination procedures
AnnualMaintenance (MA)Procedures and tool controls
AnnualMedia Protection (MP)Handling and sanitisation procedures

Evidence that stays current

Refresh monthly

  • Vulnerability scan results
  • Audit log review records
  • Patch reports
  • Malware scan logs

Refresh quarterly

  • Access review results
  • Baseline checks
  • Privilege audits
  • Network diagram updates

Refresh annually

  • Awareness training records
  • Incident response test results
  • Risk assessment reports
  • Policy and procedure reviews

Update when they change

  • The system security plan
  • Architecture diagrams
  • Asset inventory
  • Provider documentation

Common pitfalls

  • Checkbox reviews. Approving a review without examining the evidence defeats the purpose.
  • A plan that lags reality. Infrastructure changes and new tools need the system security plan updated. Assessors compare the plan with what they observe.
  • Forgotten POA&M items. Open items need active remediation. A stale POA&M tells an assessor the program is not working.
  • Unwatched providers. If a provider loses its authorization, every control you inherit from it is affected the same day.
  • No single source of truth. Spreadsheets, shares and email threads cannot show that controls were maintained when the question is asked.

Questions people ask

What is continuous monitoring in CMMC?

The ongoing review and maintenance of your controls, required by 3.12.3, so they remain effective between assessments. It includes evidence reviews, scanning, configuration checks and policy updates on a schedule.

How often should controls be reviewed?

There is no single answer. Technical families are typically monthly, access and configuration quarterly, and slower-moving families annually. What matters is a defined schedule that is followed.

What is the annual affirmation?

A senior official's formal statement in SPRS that your controls remain in place and effective. It continues during the Phase 2 suspension.

What if controls drift between assessments?

Record the gap on the POA&M and remediate it. Significant drift found at affirmation or reassessment puts the certification, and contract eligibility, at risk.

Do I need software for this?

Not strictly, but tracking review schedules, evidence age and health across 110 requirements by hand is error-prone. That is what the monitoring dashboard in Bedrock CMMC exists for.

Keep the proof, not just the plan.

Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.