CMMC 2.0

CMMC 2.0 coverage

How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to CMMC 2.0 practices. CMMC practices are drawn from NIST SP 800-171, so the identity, logging, and configuration evidence LockList collects lines up directly with the technical practices an assessor scores — practice IDs below use the official DOMAIN.L#-3.x.y scheme (L1 = Foundational, L2 = Advanced).

Readiness evidence, not a CMMC certification. LockList evidences the technical/configuration practices these platforms expose. CMMC also includes policy, process, physical, and personnel practices a config scan can't see, and scoping (where CUI lives) is specific to your environment. Level 1 requires an annual self-assessment affirmed in SPRS; Level 2 certification requires assessment by a C3PAO. Confirm applicability with your assessor.

AC · Access Control

PracticeWhat LockList assesses
AC.L1-3.1.1Authorized access controlBaseline access posture: Security Defaults, guest / external user privileges, and high-privilege application consents (M365); suspended account review (Google); owner and member inventory (GitHub).
AC.L1-3.1.2Transaction & function controlGuest / external user privilege limits (M365) — what external identities are permitted to do inside the tenant.
AC.L2-3.1.3Control CUI flowSharePoint / OneDrive external sharing posture and external email auto-forwarding (M365); public blob / bucket access (Azure, AWS).
AC.L2-3.1.5Least privilegePrivileged role assignments, directory roles, and PIM just-in-time elevation (M365); super admin count and admin roles (Google); organisation owners (GitHub); root account usage (AWS).
AC.L2-3.1.6Non-privileged account useCount of permanently privileged accounts (M365, Google); root access keys that make the root account a daily-use identity (AWS).
AC.L2-3.1.7Privileged functionsPIM (just-in-time activation) for privileged role use, keeping privileged functions gated and audited (M365).
AC.L2-3.1.12Control remote accessNamed location (trusted IP) Conditional Access conditions (M365); NSG management ports open to the internet (Azure).
AC.L1-3.1.22Control public informationAccount-level S3 Block Public Access (AWS); storage account public blob access (Azure); external sharing defaults (M365).

IA · Identification & Authentication

PracticeWhat LockList assesses
IA.L1-3.5.1 / 3.5.2Identification & authenticationPer-user authentication method inventory (M365); SAML SSO enforcement tying identities to the corporate IdP (GitHub).
IA.L2-3.5.3Multifactor authenticationConditional Access MFA for admins and all users, MFA registration coverage, Security Defaults (M365); 2-Step Verification coverage and admin enrollment (Google); org-wide 2FA (GitHub); root and IAM user MFA (AWS).
IA.L2-3.5.4Replay-resistant authenticationLegacy / basic authentication blocking — protocols that can't do modern, replay-resistant auth (M365).
IA.L2-3.5.6Identifier handlingSuspended / dormant account review (Google); stale deploy keys (GitHub); access keys past their rotation window (AWS).
IA.L2-3.5.7 / 3.5.8Password complexity & reuseIAM password policy length, complexity, and reuse settings (AWS); self-service password reset posture (M365).
IA.L2-3.5.10Cryptographically-protected passwordsSecret scanning and push protection, catching credentials committed in plaintext (GitHub); access key hygiene (AWS).

AU · Audit & Accountability

PracticeWhat LockList assesses
AU.L2-3.3.1System auditingSign-in and directory audit log accessibility (M365); login and admin audit logs (Google); CloudTrail configuration (AWS); SQL auditing and Activity Log export (Azure); activity log accessibility (NinjaOne).
AU.L2-3.3.2User accountabilitySign-in logs and admin audit trails that trace actions to individual users (M365, Google, AWS).
AU.L2-3.3.8Audit protectionActivity Log export to durable storage, protecting audit records from loss (Azure).

CM · Configuration Management

PracticeWhat LockList assesses
CM.L2-3.4.1System baseliningIntune device management coverage (M365); tenant licensing / subscription inventory (M365); organisation and verified domain inventory (Google); RMM device inventory, agent coverage, and stale / offline agent detection (NinjaOne).
CM.L2-3.4.2Security configuration enforcementIntune compliance policy enforcement and non-compliant device count (M365).
CM.L2-3.4.3 / 3.4.5Change management & access restrictionsDefault branch protection rules — required reviews, status checks, and force-push restrictions (GitHub).

SC · System & Communications Protection

PracticeWhat LockList assesses
SC.L1-3.13.1Boundary protectionNSG rules exposing management ports (RDP/SSH) to the internet (Azure); legacy authentication blocking at the identity boundary (M365).
SC.L2-3.13.8Data in transitStorage secure-transfer (HTTPS-only) enforcement and minimum TLS version (Azure).
SC.L2-3.13.10Key managementKey Vault soft-delete and purge protection, guarding cryptographic keys against destruction (Azure).

SI / CA · System Integrity & Assessment

PracticeWhat LockList assesses
SI.L1-3.14.1 / 3.14.2Flaw remediation & malicious code protectionMicrosoft Defender / email security licensing posture and non-compliant device detection (M365); Defender for Cloud plans (Azure); OS patch status and antivirus coverage across managed endpoints (NinjaOne).
SI.L2-3.14.6 / 3.14.7Monitoring for attacks & unauthorized useRisky user detection via Identity Protection (M365); Defender for Cloud threat detection (Azure); open alert review and offline agent detection (NinjaOne).
CA.L2-3.12.1 / 3.12.3Security assessment & monitoringMicrosoft Secure Score as an ongoing measurement of configuration against the security baseline (M365).

Every finding in your LockList Report carries its CMMC 2.0 practice ID alongside SOC 2, ISO 27001, CIS, HIPAA, and HITRUST CSF mappings. Run a free assessment →