Table 7 to § 170.24 (c)(2)(ii) -CMMC Level 2 Scoring Table
CMMC Level 2 requirement categories | Point value subtracted from maximum score |
Basic Security Requirements: | |
If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI | 5 |
If not implemented, has specific and confined effect on the security of the network and its data | 3 |
Derived Security Requirements: | |
If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI | 5 |
If not completely or properly implemented, could be partially effective and points adjusted depending on how the security requirement is implemented: | 3 or 5 |
-Partially effective implementation-3 points. | |
-Non-effective (not implemented at all)-5 points. | |
If not implemented, has specific and confined effect on the security of the network and its data | 3 |
If not implemented, has a limited or indirect effect on the security of the network and its data | 1 |
32 C.F.R. §170.24