Skip to main content
CMMC Compliance

Incident Response Plan for CMMC: 6 Requirements Most Defense Manufacturers Miss

A generic incident response template downloaded from the internet will not pass a CMMC Level 2 assessment. Assessors know what a real IR plan looks like and what a placeholder looks like.

By Telco United • 7 min read

Incident response is one of the most commonly under-prepared control families in CMMC Level 2 assessments. For defense manufacturers, aerospace subcontractors, CNC machining shops, and fabrication operations, the incident response plan for CMMC is not just a policy document, it is an operational requirement with specific evidence standards.

The NIST SP 800-171 Incident Response (IR) control family includes 3 practices (IR.2.092, IR.2.093, IR.3.098). Each one has multiple assessment objectives. Failing any of them can prevent your certification or require a corrective action plan before your C3PAO will close the finding.

This post covers the 6 requirements that defense contractors most commonly miss when building their CMMC incident response plan.

What CMMC Requires for Incident Response

The CMMC Level 2 Incident Response domain requires that organizations:

Each practice has multiple assessment objectives. IR.2.092 alone has eight objectives that an assessor will evaluate independently.

Relevant resource: NIST SP 800-171A, CMMC Assessment Procedures

6 Requirements Most Defense Manufacturers Miss

Requirement 1: The Plan Must Name Your Organization Specifically

A generic IR template with your company logo on the cover is not an organizational incident response plan. Assessors look for specific details: the names or roles of personnel responsible for each phase, the systems in scope, the communication channels used during an incident, and the escalation path to DoD reporting.

If your plan could belong to any company without changing a word, it will not meet this requirement.

Requirement 2: Roles and Responsibilities Must Be Current

The IR plan must identify who does what during an incident. For small manufacturers, this often means the IT manager handles detection and containment while the owner or COO handles external reporting. That is a valid structure, but it must be documented, and the named individuals must be aware of their responsibilities.

Assessors often interview the personnel named in the IR plan. If the person named as incident commander is unaware that they hold that role, the control fails.

Requirement 3: Detection Procedures Must Reference Real Tools

Your IR plan must describe how incidents are detected. For CMMC Level 2, that means referencing the actual monitoring tools in your environment: your SIEM or log management system, your endpoint detection and response (EDR) solution, your vulnerability scanner.

A plan that says "monitor systems for anomalous activity" without specifying how that monitoring occurs does not satisfy the detection assessment objective.

Requirement 4: Containment and Recovery Steps Must Be Specific

For manufacturers with mixed IT/OT environments, containment procedures need to address the specific risk that a compromised workstation poses to production systems. A generic "isolate the affected system" step is not sufficient if your CNC controllers and your office network share the same infrastructure.

Your containment procedures should address network segmentation steps, which systems get isolated first, and how to maintain production continuity during an active incident.

Requirement 5: DFARS 72-Hour Reporting Must Be Documented

Under DFARS 252.204-7012, contractors must report cyber incidents to the DoD within 72 hours of discovery. Your IR plan must document this obligation, specify who submits the report, identify the reporting portal (the DoD DIBNet portal), and include the information required in the report.

Many contractors have an IR plan that covers internal response but completely omits the DoD reporting requirement. That is a direct control gap that assessors check specifically.

Requirement 6: The Plan Must Have Been Tested Within the Past Year

IR.3.098 requires that your incident response capability be tested. This does not necessarily mean a full tabletop exercise every year, though that is the gold standard. At minimum, you need documented evidence that the plan has been reviewed, key personnel have walked through their roles, and any gaps identified during the review have been addressed.

An IR plan with a creation date of three years ago and no subsequent revision or test record will fail this control immediately.

Testing Your IR Plan: What Assessors Actually Check

When evaluating IR.3.098, assessors typically ask for:

A tabletop exercise does not need to be elaborate. A two-hour walkthrough with your IT manager, operations lead, and senior leadership, documented with an agenda and sign-in sheet, satisfies this control for most small manufacturers.

DoD Breach Reporting Under DFARS 7012

If your organization experiences a cyber incident involving CUI, the 72-hour reporting clock under DFARS 252.204-7012 starts from the moment you discover the incident, not from when you determine it was a breach.

Your IR plan needs to document this trigger clearly. Many manufacturers delay reporting while conducting their own investigation, believing they need to confirm a breach before notifying DoD. That approach can result in a late report even when the underlying incident was minor.

Related reading: DFARS 7012 vs CMMC: Which Requirement Applies to Your Contract?

Building an IR Plan That Survives Assessment

A CMMC-ready incident response plan is not a long document. A well-structured plan for a 20-50 person manufacturer can cover all six requirements in 8-12 pages. The goal is specificity, not volume.

Build your plan around your actual environment: your real systems, your real people, your real escalation paths. Then test it, document the test, and keep it current.

Need help building a CMMC-ready incident response plan for your manufacturing or defense operation? Contact our CMMC compliance team or take the free self-assessment to see where your IR controls stand today.

See Where Your IR Controls Stand Today

Take the free self-assessment to identify gaps in your incident response posture before your C3PAO assessment reveals them.

Take Free Self-Assessment Or talk to our CMMC compliance team

Subscribe to our Newsletter: