Mapped to NIST 800-171 Requirement: 3.11.2
CMMC Assessment Objective: RA.L2-3.11.2[c]
What This Control Means
This control moves from planning to execution.
You must show that:
• Mitigation plans are in progress or completed
• Accepted risks are acknowledged and justified
• Transferred risks are documented via contracts or SLAs
• Avoided risks have been addressed by altering business practices or technologies
Plans are important—but action is essential.
Why It Matters
If you document risk responses but never follow through:
• CUI remains vulnerable to known threats
• POA&M items go unresolved
• Risk scores remain artificially low
• Auditors may view your risk management program as non-compliant
Implementation turns policy into real-world protection.
How to Implement It
1. Track All Risk Responses
• Use your risk register and POA&M to show progress
• Log completion dates and updates for mitigation actions
2. Show Supporting Documentation
• For mitigation:
◦ Screenshots, configuration files, or change logs
• For acceptance:
◦ Formal acceptance sign-offs by leadership
• For transfer:
◦ Vendor contracts, cyber insurance policies
• For avoidance:
◦ Business practice or scope changes
3. Review Periodically
• Follow up on risks with outstanding actions
• Adjust strategies if implementation isn’t effective
4. Assign Accountability
• Ensure every response has an owner
• Set deadlines and escalate if timelines slip
Evidence the Assessor Will Look For
• POA&M updates showing completed or in-progress mitigation
• Risk register with response status and action logs
• Documents showing vendor acceptance of transferred risk
• Screenshots, emails, or change records tied to mitigation efforts
• Formal records of risk acceptance decisions
Common Gaps
• Risk responses are planned but never acted on
• No evidence of completed POA&M items
• Mitigation deadlines missed with no updates
• Transferred risks have no supporting contracts or documentation
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Tracking implementation of risk responses through your POA&M and risk register
• Assigning owners, deadlines, and progress notes to each response
• Logging evidence of completed actions (e.g., uploaded screenshots, signed approvals)
• Integrating with ticketing or project management tools for workflow visibility
• Ensuring every risk decision leads to real-world follow-through
With Cuick Trac, your risk response isn’t just documented—it’s delivered.
Final CTA
Security isn’t what you say you’ll do—it’s what you actually do.
Schedule a Cuick Trac demo to prove your risk responses are implemented and protecting your CUI.