HomeTemplatesCA Policy
CMMC Level 2 CA Domain All 4 Practices

Security Assessment (CA) Policy Template

Periodic control assessments, POA&M lifecycle management, ongoing monitoring schedules, and System Security Plan documentation. All four CA domain practices covered in one editable Word document.

What Is Included

  • Policy scope, purpose, and applicability statement
  • Roles and responsibilities matrix (ISSO, System Owner, Management)
  • Practice 3.12.1: Control assessment methodology, frequency table, and assessor qualifications
  • Practice 3.12.2: POA&M structure, risk-level classification table, ownership assignments, and closure criteria
  • Practice 3.12.3: Ongoing monitoring schedule (daily, monthly, quarterly, annual activities)
  • Practice 3.12.4: SSP documentation requirements, update triggers, and review cadence
  • Records retention requirements
  • Policy exception process
  • Revision history table and document control block
  • All placeholders clearly bracketed for organization-specific customization

Practice Coverage

3.12.1Periodically assess the security controls in organizational systems to determine if the controls are effective in their application
3.12.2Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems
3.12.3Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls
3.12.4Develop, document, and periodically update system security plans that describe system boundaries, system environments, and implementation of security controls

Who Needs This

Any organization pursuing CMMC Level 2 certification needs written policy documentation for the CA domain before their C3PAO assessment. This template is specifically built for:

  • Defense contractors handling CUI under a DoD contract
  • MSPs managing CMMC compliance for DIB clients
  • IT managers building out their NIST SP 800-171 documentation package
  • Organizations that have a SPRS score below 110 and need to formalize their POA&M process

Frequently Asked Questions

This policy covers all four CA domain practices: 3.12.1 (periodically assess security controls), 3.12.2 (develop and manage a POA&M), 3.12.3 (monitor controls on an ongoing basis), and 3.12.4 (develop and maintain a System Security Plan). Together these four practices account for the complete Security Assessment domain under CMMC Level 2.
A Plan of Action and Milestones (POA&M) is a formal document that tracks identified security weaknesses, assigns ownership, sets remediation timelines, and documents risk acceptance decisions. Practice 3.12.2 requires defense contractors to maintain a POA&M as evidence that they are actively managing identified gaps. Without one, assessors have no way to verify deficiencies are being tracked and remediated.
Practice 3.12.1 requires periodic assessments but does not mandate a specific frequency. Most assessors expect at minimum an annual full assessment, with additional continuous monitoring activities running throughout the year (monthly vulnerability scans, quarterly log reviews, etc.). This template includes a monitoring frequency table that maps specific activities to daily, monthly, quarterly, and annual cadences.
Yes. Section 5.4 of the template addresses System Security Plan requirements under practice 3.12.4 - including what the SSP must document, who owns it, how often it must be updated, and how it relates to your assessment and monitoring activities. It complements our standalone SSP template if you need the full SSP document as well.
Security Assessment (CA) Policy
$29
Instant download · Editable .docx · CMMC mapped
Buy Now - $29 →
✓ Covers all 4 CA domain practices
✓ POA&M risk-level table included
✓ Monitoring frequency schedule included
✓ SSP documentation requirements included
✓ 30-day money-back guarantee
✓ Written by CISSP-exam-pass holder
Save more with bundles:
CMMC Certification Kit - $299 (12 policies + SSP + POA&M) CMMC Domain Policy Bundle

Related Resources

📖 CA Domain Implementation Guide 📄 CMMC SSP Template 📋 CMMC POA&M Template (XLSX) 🔍 Evidence Collection Guide
🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, instant access.