Incident response is one of the most commonly under-prepared control families in CMMC Level 2 assessments. For defense manufacturers, aerospace subcontractors, CNC machining shops, and fabrication operations, the incident response plan for CMMC is not just a policy document, it is an operational requirement with specific evidence standards.
The NIST SP 800-171 Incident Response (IR) control family includes 3 practices (IR.2.092, IR.2.093, IR.3.098). Each one has multiple assessment objectives. Failing any of them can prevent your certification or require a corrective action plan before your C3PAO will close the finding.
This post covers the 6 requirements that defense contractors most commonly miss when building their CMMC incident response plan.
What CMMC Requires for Incident Response
The CMMC Level 2 Incident Response domain requires that organizations:
- IR.2.092 - Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user activities
- IR.2.093 - Track, document, and report incidents to appropriate officials and/or authorities
- IR.3.098 - Test the organizational incident response capability
Each practice has multiple assessment objectives. IR.2.092 alone has eight objectives that an assessor will evaluate independently.
Relevant resource: NIST SP 800-171A, CMMC Assessment Procedures
6 Requirements Most Defense Manufacturers Miss
Requirement 1: The Plan Must Name Your Organization Specifically
A generic IR template with your company logo on the cover is not an organizational incident response plan. Assessors look for specific details: the names or roles of personnel responsible for each phase, the systems in scope, the communication channels used during an incident, and the escalation path to DoD reporting.
If your plan could belong to any company without changing a word, it will not meet this requirement.
Requirement 2: Roles and Responsibilities Must Be Current
The IR plan must identify who does what during an incident. For small manufacturers, this often means the IT manager handles detection and containment while the owner or COO handles external reporting. That is a valid structure, but it must be documented, and the named individuals must be aware of their responsibilities.
Assessors often interview the personnel named in the IR plan. If the person named as incident commander is unaware that they hold that role, the control fails.
Requirement 3: Detection Procedures Must Reference Real Tools
Your IR plan must describe how incidents are detected. For CMMC Level 2, that means referencing the actual monitoring tools in your environment: your SIEM or log management system, your endpoint detection and response (EDR) solution, your vulnerability scanner.
A plan that says "monitor systems for anomalous activity" without specifying how that monitoring occurs does not satisfy the detection assessment objective.
Requirement 4: Containment and Recovery Steps Must Be Specific
For manufacturers with mixed IT/OT environments, containment procedures need to address the specific risk that a compromised workstation poses to production systems. A generic "isolate the affected system" step is not sufficient if your CNC controllers and your office network share the same infrastructure.
Your containment procedures should address network segmentation steps, which systems get isolated first, and how to maintain production continuity during an active incident.
Requirement 5: DFARS 72-Hour Reporting Must Be Documented
Under DFARS 252.204-7012, contractors must report cyber incidents to the DoD within 72 hours of discovery. Your IR plan must document this obligation, specify who submits the report, identify the reporting portal (the DoD DIBNet portal), and include the information required in the report.
Many contractors have an IR plan that covers internal response but completely omits the DoD reporting requirement. That is a direct control gap that assessors check specifically.
Requirement 6: The Plan Must Have Been Tested Within the Past Year
IR.3.098 requires that your incident response capability be tested. This does not necessarily mean a full tabletop exercise every year, though that is the gold standard. At minimum, you need documented evidence that the plan has been reviewed, key personnel have walked through their roles, and any gaps identified during the review have been addressed.
An IR plan with a creation date of three years ago and no subsequent revision or test record will fail this control immediately.
Testing Your IR Plan: What Assessors Actually Check
When evaluating IR.3.098, assessors typically ask for:
- Documentation of the most recent IR test or tabletop exercise (date, attendees, scenarios covered)
- Any lessons-learned records or after-action reports from the test
- Evidence that gaps identified during testing were tracked and remediated
- Confirmation that the IR plan was updated after the test if changes were identified
A tabletop exercise does not need to be elaborate. A two-hour walkthrough with your IT manager, operations lead, and senior leadership, documented with an agenda and sign-in sheet, satisfies this control for most small manufacturers.
DoD Breach Reporting Under DFARS 7012
If your organization experiences a cyber incident involving CUI, the 72-hour reporting clock under DFARS 252.204-7012 starts from the moment you discover the incident, not from when you determine it was a breach.
Your IR plan needs to document this trigger clearly. Many manufacturers delay reporting while conducting their own investigation, believing they need to confirm a breach before notifying DoD. That approach can result in a late report even when the underlying incident was minor.
Related reading: DFARS 7012 vs CMMC: Which Requirement Applies to Your Contract?
Building an IR Plan That Survives Assessment
A CMMC-ready incident response plan is not a long document. A well-structured plan for a 20-50 person manufacturer can cover all six requirements in 8-12 pages. The goal is specificity, not volume.
Build your plan around your actual environment: your real systems, your real people, your real escalation paths. Then test it, document the test, and keep it current.
Need help building a CMMC-ready incident response plan for your manufacturing or defense operation? Contact our CMMC compliance team or take the free self-assessment to see where your IR controls stand today.
