3.11 Risk Assessment1 ptPOA&M-eligible

3.11.3 — Remediate vulnerabilities

Remediate vulnerabilities in accordance with risk assessments.

You fix the vulnerabilities you find, prioritized by risk.

What it actually means

Finding vulnerabilities (3.11.2) only matters if you fix them. Remediate based on risk — highest-risk first — and track to closure. It connects scanning, risk, and patching into one loop.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Risk Assessment (3.11)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.