3.11 Risk Assessment5 pts

3.11.2 — Scan for vulnerabilities

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

You scan systems and apps for vulnerabilities — regularly and on new threats.

What it actually means

Run vulnerability scans on a schedule and when new vulnerabilities are announced. Scanning is how you find what to patch (3.14.1) and feeds your risk picture. A 5-pointer because you can't fix what you don't find.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Risk Assessment (3.11)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.