CMMC Level 2 Influence Matrix
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
Which practices influence which CMMC Level 2 practice identifiers. This is an influence matrix, not a coverage or readiness matrix: no row states that a practice satisfies a CMMC requirement, and the matrix cannot be used to calculate a score.
How to use it
Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.
Read this first
A CMMC Level 2 assessment evaluates 110 NIST SP 800-171 requirements against your specific system boundary, with evidence. This matrix shows where the twenty practices push in the same direction. It does not measure coverage, produce a score, indicate assessment readiness, or reduce the number of requirements you must implement. Do not present it to a customer or an assessor as evidence of anything.
How these mappings were made
Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.
Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.
| Term | Meaning |
|---|---|
| Direct | The practice addresses the substance of the requirement head-on. |
| Supporting | The practice materially helps satisfy the requirement but does not cover it alone. |
| Enabling | The practice is a prerequisite that makes the requirement achievable. |
| Contextual | The practice informs or constrains how the requirement is met. |
| High confidence | Reviewed against the primary source text; the relationship is explicit. |
| Moderate confidence | Reviewed against the primary source; the relationship is a reasoned interpretation. |
| Low confidence | Directional only. Treat as a starting point for your own analysis. |
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
IT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| IT-01 | Phishing-resistant MFA | IA.L2-3.5.3 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-02 | Asset inventory | CM.L2-3.4.1 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-03 | Technical debt reduction | CM.L2-3.4.1 / SI.L2-3.14.1 | Supporting | Moderate | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-04 | Flexible technology stack | CM.L2-3.4.2 | Supporting | Moderate | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-05 | Logical segmentation | SC.L2-3.13.1 / SC.L2-3.13.5 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-06 | Risk-based vulnerability management | RA.L2-3.11.2 / RA.L2-3.11.3 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-07 | Security in the development lifecycle | CM.L2-3.4.3 | Supporting | Moderate | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-08 | Secure AI adoption | AC.L2-3.1.3 / AC.L2-3.1.20 | Supporting | Moderate | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-09 | Backup and disaster recovery | MP.L2-3.8.9 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
| IT-10 | Technical workforce readiness | AT.L2-3.2.1 / AT.L2-3.2.2 | Direct | High | Supports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that. |
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-cmmc-level-2-influence-matrix to keep filenames consistent across your team.