3.11 Risk Assessment3 pts

3.11.1 — Assess your risk

Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

You periodically assess the risk to operations from your CUI systems.

What it actually means

A periodic risk assessment — what could go wrong with the systems handling CUI, how likely, how bad — documented and used to drive decisions. It doesn't need to be elaborate; it needs to be real, current, and actually inform what you prioritize.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Risk Assessment (3.11)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.