CMMC incident response is one of the requirement families a defense contractor has to satisfy for Level 2, and it carries an obligation many organizations underestimate until an assessor asks to see the evidence. The requirements are not simply about having a plan on a shelf; they are about demonstrating a working capability to detect, handle, and report security incidents, and proving that capability with records. This guide explains what CMMC incident response requires, what Level 2 assessors test, what evidence to keep, and how it connects to the separate reporting duty you owe the Department of War under your contract.
There are really two obligations in play, and contractors frequently conflate them. The first is the set of incident response practices built into the security standard behind CMMC Level 2, which an assessor evaluates. The second is the contractual duty under a specific DFARS clause to report cyber incidents rapidly to the government. They overlap in spirit but are distinct in practice, and getting both right is what incident response readiness actually means for a defense contractor.
What CMMC Incident Response Requires
CMMC Level 2 is built on the 110 requirements of NIST SP 800-171 Revision 2, and incident response is one of the families within it. The family sets out three connected requirements that together define an operational capability rather than a paper exercise, and an assessor examines all three.
An Operational Incident-Handling Capability
The core requirement is an operational incident-handling capability for your systems that spans the full lifecycle of an incident: preparation before anything happens, detection and analysis when it does, containment to limit the damage, recovery to restore normal operations, and the user response activities that tie people into the process. The word that matters is operational. The requirement is not satisfied by a document describing what you would do; it is satisfied by a capability you can show actually exists and functions, with the roles, tools, and procedures to work an incident from detection through recovery.
Incident Tracking, Documentation, and Reporting
The second requirement is to track, document, and report incidents to the designated officials and authorities, both inside and outside your organization. This is the recordkeeping and communication half of incident response: every incident is logged, documented as it is worked, and reported to the people who need to know, which includes internal leadership and, where required, external authorities. The documentation this generates is also the evidence an assessor will later ask to see, so disciplined incident records serve both the operational and the assessment purpose.
Capability Testing
The third requirement is to test the incident response capability, because a capability that has never been exercised is an assumption rather than a fact. Testing, through tabletop exercises or more involved simulations, is how you confirm the capability works before a real incident proves it does not, and it is also how you generate the evidence that the capability is real. An assessor who asks whether you have tested your incident response is asking for proof, so the test itself has to be documented.
The DFARS Reporting Duty: 72 Hours
Alongside the CMMC practices sits a separate and specific contractual obligation. Under DFARS clause 252.204-7012, a contractor that discovers a cyber incident affecting a covered system or the controlled unclassified information on it must report it to the Department of War within 72 hours of discovery, through the DIBNet portal. This is a hard deadline measured from discovery, not from resolution, and it is one of the obligations most likely to catch an unprepared contractor because the clock is short and the reporting channel is specific.
The duty does not end at the report. The clause also requires preserving and protecting images of the affected systems so that evidence is available for analysis, commonly for a defined retention period, submitting any malicious software discovered, and providing the government access needed for a forensic review. This reporting duty is distinct from the CMMC incident response practices and is in force regardless of the current suspension of third-party assessment, because it is a contractual clause rather than a certification step. A contractor can be fully occupied with its Level 2 self-assessment and still owe this 72-hour report the moment an incident is discovered.
What Level 2 Assessors Test
An assessor evaluating your incident response is looking for proof that the capability exists, is used, and has been tested, and that proof lives in your records. Expect an assessor to ask for your incident response plan or policy, for documentation of incidents you have handled, for evidence that you have tested the capability, and for the records that show incidents were tracked and reported appropriately. The recurring theme across all of it is that a capability you cannot evidence is treated, in an assessment, as a capability you do not have.
This also matters to your score. Because incident response is part of the 110 requirements, gaps in it reduce your assessment score under the weighting codified in the CMMC rule, so an incomplete or unevidenced incident response capability costs you points as well as risking a failed assessment. Understanding how the requirements are scored, covered in the guide to the NIST 800-171 assessment, helps you see why the evidence behind incident response is worth building properly rather than assembling in a rush before an assessment.
Evidence to Keep
The practical takeaway is to treat evidence as a byproduct of running incident response well, rather than something to reconstruct later. The records worth maintaining include a documented incident response plan or policy that describes your capability, logs and documentation of the incidents you have actually handled, records of the exercises or tests you have run to validate the capability, and the reporting records that show incidents reached the right internal and external parties within the required timeframes. After-action reviews that capture what an incident taught you are valuable both operationally and as proof of a maturing capability.
Kept consistently, these records do double duty: they make your incident response genuinely effective, and they satisfy an assessor without a scramble. The contractors who struggle with the incident response family at assessment time are almost always the ones who had the capability but never documented it, which is a self-inflicted and entirely avoidable way to lose points.
How Incident Response Fits Your CMMC Program
Incident response is one family among the many that make up a CMMC Level 2 program, and like the others it needs a written policy that maps to the requirements, not just a technical capability. Building that policy from scratch is slow, which is why starting from a proven, tailored policy set is the efficient path. Elevate’s CMMC Level 2 Master Policy Compendium includes the incident response policy among the families it covers, so you adapt a document that already maps to the requirements rather than writing one from a blank page. For the operational side of standing up the capability itself, the guide to building an incident response plan walks through the plan in detail.
The goal is an incident response capability that is real, documented, tested, and tied into your DFARS reporting obligations, so that both an assessor and an actual incident find you ready. Elevate helps contractors build incident response that satisfies CMMC Level 2 and the reporting duties that accompany it, as part of its CMMC advisory services.
Conclusion
CMMC incident response asks for a working, tested, and documented capability, not a plan that has never left the drawer, and it sits next to a separate contractual duty to report cyber incidents to the Department of War within 72 hours. Level 2 assessors test the capability through its evidence, so the incident records, test results, and reporting logs you keep are what determine whether the requirement is met, and because incident response is part of the scored 110 requirements, gaps here cost points as well as risking the assessment. Both obligations remain fully in force through the current suspension.
The contractors who handle this family well treat evidence as something built while running incident response rather than reconstructed before an assessment, and they keep their DFARS reporting duty ready to execute on short notice. To build an incident response capability that satisfies Level 2 and your reporting obligations, book a call with an Elevate advisor.
Key Takeaways
CMMC incident response requires a working, tested, and evidenced capability under Level 2, plus a separate DFARS duty to report incidents to the Department of War quickly.
- The standard requires an operational capability: an incident-handling capability across the full lifecycle, tracking and reporting of incidents, and testing of the capability, not just a written plan.
- Evidence is what assessors test: an incident response plan, incident records, test results, and reporting logs are what prove the capability, and a capability you cannot evidence is treated as absent.
- DFARS reporting is separate and strict: under DFARS 252.204-7012 a cyber incident must be reported within 72 hours of discovery through DIBNet, with evidence preserved and malware submitted, a duty in force regardless of the suspension.
- Incident response is scored: because it is part of the 110 requirements, gaps reduce your assessment score under the codified weighting, so an unevidenced capability costs points.
- Policy plus capability: a written incident response policy that maps to the requirements, built from a proven template, paired with a tested operational capability, is what satisfies both the assessor and a real incident.
FAQs
Q1. What does CMMC require for incident response? CMMC Level 2 is built on NIST SP 800-171 Revision 2, and its incident response family requires three things: an operational incident-handling capability that spans preparation, detection, analysis, containment, recovery, and user response; the tracking, documentation, and reporting of incidents to the appropriate internal and external parties; and testing of the capability to confirm it works. The requirement is for a demonstrable, working capability rather than a plan that exists only on paper, and an assessor evaluates all three parts through the evidence you keep.
Q2. What is the DFARS 72-hour incident reporting requirement? DFARS clause 252.204-7012 requires a contractor that discovers a cyber incident affecting a covered system or its controlled unclassified information to report it to the Department of War within 72 hours of discovery, through the DIBNet portal. The clause also requires preserving images of the affected systems for a defined period, submitting any malicious software found, and providing access for a forensic review. The 72-hour clock runs from discovery, not from resolution, and this duty is separate from the CMMC incident response practices.
Q3. Is CMMC incident response affected by the 2026 suspension? No. Incident response is part of the 110 requirements of NIST SP 800-171 Revision 2, which remain fully in force during the suspension, and the DFARS 252.204-7012 reporting duty is a contractual obligation that does not depend on certification assessment being active. The suspension paused third-party certification assessment, but it did not pause the requirement to have an incident response capability or the duty to report cyber incidents within 72 hours. Both obligations apply today.
Q4. What incident response evidence do CMMC assessors want? Assessors look for proof that the capability exists, is used, and has been tested. That means a documented incident response plan or policy, records of incidents you have actually handled, evidence that you have tested the capability through exercises or simulations, and records showing incidents were tracked and reported to the right parties within the required timeframes. Because a control that cannot be evidenced is treated as not met, the quality of your incident response records directly determines whether the requirement is satisfied.
Q5. How does incident response affect my CMMC score? Incident response is part of the scored 110 requirements, so gaps in it reduce your assessment score under the point weighting codified in the CMMC rule at 32 CFR 170.24. An incident response capability that is incomplete, untested, or undocumented costs points and can contribute to a failed assessment. Because the requirements are weighted, closing meaningful incident response gaps improves both your security posture and your score, which is why building the capability and its evidence properly is worth the effort.