CMMC 2.0
CMMC 2.0 coverage
How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to CMMC 2.0 practices. CMMC practices are drawn from NIST SP 800-171, so the identity, logging, and configuration evidence LockList collects lines up directly with the technical practices an assessor scores — practice IDs below use the official DOMAIN.L#-3.x.y scheme (L1 = Foundational, L2 = Advanced).
Readiness evidence, not a CMMC certification. LockList evidences the technical/configuration practices these platforms expose. CMMC also includes policy, process, physical, and personnel practices a config scan can't see, and scoping (where CUI lives) is specific to your environment. Level 1 requires an annual self-assessment affirmed in SPRS; Level 2 certification requires assessment by a C3PAO. Confirm applicability with your assessor.
AC · Access Control
| Practice | What LockList assesses |
| AC.L1-3.1.1Authorized access control | Baseline access posture: Security Defaults, guest / external user privileges, and high-privilege application consents (M365); suspended account review (Google); owner and member inventory (GitHub). |
| AC.L1-3.1.2Transaction & function control | Guest / external user privilege limits (M365) — what external identities are permitted to do inside the tenant. |
| AC.L2-3.1.3Control CUI flow | SharePoint / OneDrive external sharing posture and external email auto-forwarding (M365); public blob / bucket access (Azure, AWS). |
| AC.L2-3.1.5Least privilege | Privileged role assignments, directory roles, and PIM just-in-time elevation (M365); super admin count and admin roles (Google); organisation owners (GitHub); root account usage (AWS). |
| AC.L2-3.1.6Non-privileged account use | Count of permanently privileged accounts (M365, Google); root access keys that make the root account a daily-use identity (AWS). |
| AC.L2-3.1.7Privileged functions | PIM (just-in-time activation) for privileged role use, keeping privileged functions gated and audited (M365). |
| AC.L2-3.1.12Control remote access | Named location (trusted IP) Conditional Access conditions (M365); NSG management ports open to the internet (Azure). |
| AC.L1-3.1.22Control public information | Account-level S3 Block Public Access (AWS); storage account public blob access (Azure); external sharing defaults (M365). |
IA · Identification & Authentication
| Practice | What LockList assesses |
| IA.L1-3.5.1 / 3.5.2Identification & authentication | Per-user authentication method inventory (M365); SAML SSO enforcement tying identities to the corporate IdP (GitHub). |
| IA.L2-3.5.3Multifactor authentication | Conditional Access MFA for admins and all users, MFA registration coverage, Security Defaults (M365); 2-Step Verification coverage and admin enrollment (Google); org-wide 2FA (GitHub); root and IAM user MFA (AWS). |
| IA.L2-3.5.4Replay-resistant authentication | Legacy / basic authentication blocking — protocols that can't do modern, replay-resistant auth (M365). |
| IA.L2-3.5.6Identifier handling | Suspended / dormant account review (Google); stale deploy keys (GitHub); access keys past their rotation window (AWS). |
| IA.L2-3.5.7 / 3.5.8Password complexity & reuse | IAM password policy length, complexity, and reuse settings (AWS); self-service password reset posture (M365). |
| IA.L2-3.5.10Cryptographically-protected passwords | Secret scanning and push protection, catching credentials committed in plaintext (GitHub); access key hygiene (AWS). |
AU · Audit & Accountability
| Practice | What LockList assesses |
| AU.L2-3.3.1System auditing | Sign-in and directory audit log accessibility (M365); login and admin audit logs (Google); CloudTrail configuration (AWS); SQL auditing and Activity Log export (Azure); activity log accessibility (NinjaOne). |
| AU.L2-3.3.2User accountability | Sign-in logs and admin audit trails that trace actions to individual users (M365, Google, AWS). |
| AU.L2-3.3.8Audit protection | Activity Log export to durable storage, protecting audit records from loss (Azure). |
CM · Configuration Management
| Practice | What LockList assesses |
| CM.L2-3.4.1System baselining | Intune device management coverage (M365); tenant licensing / subscription inventory (M365); organisation and verified domain inventory (Google); RMM device inventory, agent coverage, and stale / offline agent detection (NinjaOne). |
| CM.L2-3.4.2Security configuration enforcement | Intune compliance policy enforcement and non-compliant device count (M365). |
| CM.L2-3.4.3 / 3.4.5Change management & access restrictions | Default branch protection rules — required reviews, status checks, and force-push restrictions (GitHub). |
SC · System & Communications Protection
| Practice | What LockList assesses |
| SC.L1-3.13.1Boundary protection | NSG rules exposing management ports (RDP/SSH) to the internet (Azure); legacy authentication blocking at the identity boundary (M365). |
| SC.L2-3.13.8Data in transit | Storage secure-transfer (HTTPS-only) enforcement and minimum TLS version (Azure). |
| SC.L2-3.13.10Key management | Key Vault soft-delete and purge protection, guarding cryptographic keys against destruction (Azure). |
SI / CA · System Integrity & Assessment
| Practice | What LockList assesses |
| SI.L1-3.14.1 / 3.14.2Flaw remediation & malicious code protection | Microsoft Defender / email security licensing posture and non-compliant device detection (M365); Defender for Cloud plans (Azure); OS patch status and antivirus coverage across managed endpoints (NinjaOne). |
| SI.L2-3.14.6 / 3.14.7Monitoring for attacks & unauthorized use | Risky user detection via Identity Protection (M365); Defender for Cloud threat detection (Azure); open alert review and offline agent detection (NinjaOne). |
| CA.L2-3.12.1 / 3.12.3Security assessment & monitoring | Microsoft Secure Score as an ongoing measurement of configuration against the security baseline (M365). |
Every finding in your LockList Report carries its CMMC 2.0 practice ID alongside SOC 2, ISO 27001, CIS, HIPAA, and HITRUST CSF mappings. Run a free assessment →