Practical Defense
Why You Should Start Vulnerability Scanning Before You Think You Need To
How should you approach vulnerability scanning when your company works with Controlled Unclassified Information? This task is a clear requirement in both NIST SP 800-171 Rev 2 and CMMC Level 2 under control RA.L2-3.11.2. The order in which you perform and document vulnerability scans can influence your compliance status and affect your self-assessment outcome.
What is required for vulnerability scanning under NIST SP 800-171 and CMMC?
NIST SP 800-171 Rev 2, which is cited directly by CMMC per 32 CFR Part 170, requires you to scan for vulnerabilities in your information systems and remediate those vulnerabilities in a timely manner. The relevant requirement, RA.L2-3.11.2, is mandatory for all Level 2 companies handling CUI assets. This is more than a paper exercise. You must be able to demonstrate, with system-generated evidence, that you have been scanning and remediating over time, more than once, and more than when you think an assessment is coming.
The Department of War suspended the CMMC Phase II third party certification requirement on July 13, 2026, but the underlying compliance requirements are still in full force. You are still required to self-assess against all 110 NIST SP 800-171 controls, post your score to the Supplier Performance Risk System (SPRS), and have a senior official affirm your self-assessment annually. The government has made it clear it will continue to enforce these requirements through self assessments and select government-led reviews.
Why does scan history matter during an assessment?
When an assessor or government reviewer examines your compliance, they do more than look for the existence of a vulnerability scanning tool or a written policy. They ask for evidence: system-generated artifacts with real creation dates. The scan history you can show accumulates over real elapsed time. This means you cannot backdate your compliance by running scans right before an assessment and expect that to satisfy the requirements.
The CMMC Scoping and Assessment Guides Level 2 v2.13 make it clear that proof of execution must be demonstrated through timestamped artifacts. If you start vulnerability scanning only when you are preparing for an assessment, your scan history will reveal that fact. Assessors are trained to look at creation dates and expect to see an ongoing pattern of scanning and remediation that matches your documented procedures.
When should you start vulnerability scanning?
You should start vulnerability scanning as soon as you identify systems in scope for CUI. This is best done early in your compliance journey, ideally before you finalize your System Security Plan (SSP) and before you post your SPRS score. Waiting until an audit or self-assessment is imminent puts you at risk of failing to provide the required historical evidence. The longer your documented scan history, the stronger your proof of compliance.
Remember, the proof chain for any control is: policy defines intent, procedure describes how, and evidence proves execution through real system-generated, timestamped artifacts. Documentation alone is not proof. Only actual scan results, with dates showing a consistent pattern over time, demonstrate that you have met the requirements.
What are the consequences of a weak or recent scan history?
With the third-party certification requirement suspended, your senior official’s signature on the self-assessment is the sole assurance of compliance. This actually increases your exposure under the False Claims Act if you inflate your score or misrepresent your practices. Recent cases show that companies have faced liability for failing to scan and remediate known vulnerabilities, failing to have an SSP on file, or failing to use approved email systems. Liability can extend to primes, subcontractors, affiliates, and even private equity owners. Whistleblowers can file actions on the government’s behalf if they discover noncompliance.
A weak or recent scan history is a red flag for reviewers and can call your entire self-assessment into question. It signals that processes may not be institutionalized, and that compliance may be more about checking a box than actually managing risk. This can affect your eligibility for contracts and expose your company to legal and financial consequences.
How does vulnerability scanning fit into your overall compliance timeline?
Vulnerability scanning is only one of 110 controls required for Level 2 compliance, but it is one where timing and sequencing are especially visible. The average SPRS score across the Defense Industrial Base is about 60, well short of the required 110 for full compliance. Fewer than half of companies have completed their SSP or Plan of Actions and Milestones (POA&M) documentation. To avoid falling into this group, integrate vulnerability scanning into your routine operations early, and ensure your scan results are part of the evidence package you maintain for every control.
The assessment process also requires you to be able to produce scoping artifacts such as a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List. These should be built alongside your vulnerability scanning program so that you can clearly demonstrate which assets are being scanned and why.
Common questions
What is the minimum scan history required for compliance? The source material does not specify a minimum period, but evidence must show ongoing, consistent scanning over time. A single recent scan is not sufficient.
Can I use vulnerability scans from a third-party provider? You may use a managed service provider to perform scans, but the evidence must be system-generated and show your organization's assets, more than the provider’s infrastructure.
Is vulnerability scanning required for Level 1? Vulnerability scanning is required at Level 2 under NIST SP 800-171 Rev 2. Level 1 does not include this specific control but does require basic safeguarding of Federal Contract Information.
How to Establish Continuous Scan Records
If you have not started vulnerability scanning, now is the time. Build it into your regular processes, document your procedures, and save your scan results with clear timestamps. If you need help understanding which assets are in scope or how to meet all 110 controls for CMMC Level 2, consider applying for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more at cybergrantsalliance.org/cmmc-gap-assessment-grant/.
For official guidance on NIST SP 800-171 Rev 2 requirements, see NIST’s Computer Security Resource Center. Start vulnerability scanning now, and you will be in a much stronger position when it comes time to document your compliance.