Skip to content
Pass My CMMC
Practices Start Here Prep Timeline Glossary Free Tools About

Risk-Assessment

RA.L2-3.11.1
RA.L2-3.11.1: Risk Assessments
Periodically assess the risk to organizational operations, assets, and individuals from operating systems that process, store, or transmit CUI.
moderate
RA.L2-3.11.2
RA.L2-3.11.2: Vulnerability Scanning
Scan for vulnerabilities periodically and when new vulnerabilities are identified.
medium
RA.L2-3.11.3
RA.L2-3.11.3: Vulnerability Remediation
Remediate vulnerabilities in accordance with assessments of risk.
medium

Pass My CMMC

Site

All Practices Start Here CMMC Levels Explained Assessment Day Glossary About

Popular Families

Access Control (AC) Incident Response (IR) System Protection (SC) All 14 families

Newsletter

Subscribe on Substack

© 2026 Pass My CMMC. This site provides general guidance based on real assessment experience. It is not legal, compliance, or professional advice. Your organization's situation is unique. Work with qualified professionals for formal assessment preparation.