What Does CMMC Configuration Management Require?


Organizations working with Controlled Unclassified Information need a consistent way to understand how their systems are configured and how those configurations change. CMMC configuration management establishes requirements for maintaining approved system baselines, inventories, security settings, software, and changes.
At CMMC Level 2, Configuration Management includes nine requirements derived from NIST SP 800-171. Together, they help organizations maintain visibility into system components, establish approved configurations, evaluate modifications, and limit unnecessary functionality.
What Is CMMC Configuration Management?
CMMC configuration management provides a structured process for defining how systems should operate and maintaining that approved state as technology changes. It applies to hardware, software, firmware, and supporting documentation within the CMMC assessment scope.
Configuration Baselines
A baseline documents the approved configuration of a system at a specific point. It provides a reference for identifying modifications and determining whether current settings remain consistent with established requirements.
System Inventories
Inventories identify hardware, software, firmware, and documentation associated with applicable systems. They should remain current as components are added, replaced, updated, or removed.
Maintaining that visibility becomes particularly important as technology ages. A 2025 U.S. Government Accountability Office review identified 11 critical federal legacy systems most in need of modernization and found that four had unsupported hardware or software, while seven were operating with known cybersecurity vulnerabilities. Although federal systems differ from CMMC environments, the findings illustrate why organizations need visibility into the technologies operating within their infrastructure.
What Are the CMMC Configuration Management Requirements?
CMMC Level 2 divides Configuration Management into nine requirements. Organizations pursuing CMMC 2.0 Compliance Arizona should understand how these requirements connect documented configurations with the way systems are actually administered.
Establish Baseline Configurations and Inventories
Organizations must establish and maintain baseline configurations and inventories throughout system development and use. The records should identify relevant hardware, software, firmware, and documentation.
Establish Security Configuration Settings
Security settings should be defined and enforced for technology products used within applicable systems. Approved settings create a reference for administrators and help identify configurations that require correction or authorization.
Track, Review, and Approve System Changes
Changes to organizational systems should be tracked, reviewed, and approved or disapproved. Documenting these decisions creates accountability and helps prevent modifications from occurring without appropriate review.
Analyze the Security Impact of Changes
Organizations must analyze the potential security impact of changes before implementation. This can apply to software, infrastructure, network, and cloud solutions in Phoenix when modifications involve systems within the CMMC scope.
Restrict Who Can Make System Changes
Physical and logical access restrictions should limit system modifications to authorized personnel. Administrative permissions should reflect defined responsibilities rather than providing unnecessary configuration privileges.
Apply the Principle of Least Functionality
Systems should provide only necessary capabilities. Organizations should identify and restrict nonessential programs, functions, ports, protocols, and services to reduce unnecessary system functionality.
Control Which Software Can Run
Organizations need policies governing software execution. That includes identifying authorized or unauthorized applications and enforcing those decisions. New technologies, including AI Services in Arizona, should be evaluated according to applicable security and authorization requirements before introduction into CUI environments.
The range of applications organizations need to evaluate continues to expand. U.S. Census Bureau data published in 2026 found that 17% to 20% of U.S. businesses reported using AI between December 2025 and May 2026, with adoption reaching 37% among businesses with at least 250 employees. As organizations introduce AI and other applications, determining what software is authorized to operate within CUI environments becomes part of maintaining configuration control.
Control User-Installed Software
Organizations should establish policies for software employees can install and monitor user-installed applications. This provides visibility into software that could otherwise operate outside approved configuration standards.
How Does CMMC Configuration Management Work Throughout the System Lifecycle?
Configuration management continues as systems and business requirements change. Organizations using managed IT services in Scottsdale AZ can incorporate these responsibilities into ongoing technology administration rather than addressing them only before an assessment.
Establish: Document approved baselines and inventory applicable components.
Configure: Apply established security settings and restrict unnecessary functionality.
Control: Define who can modify systems and which applications may operate.
Review: Evaluate proposed changes and their security implications before implementation.
Document: Record approvals, modifications, and updated configuration information.
Monitor: Compare current systems with approved configurations and address identified differences.
What Documentation Supports CMMC Configuration Management?
Documentation helps demonstrate how configuration management processes operate in practice. Relevant evidence can include configuration management policies, system inventories, baseline records, security configuration standards, change requests, approvals, security impact analyses, and software installation records.
The specific evidence depends on the environment and requirement being assessed. Documentation should remain consistent with the systems, procedures, and technical controls that personnel actually use.
What Are Common CMMC Configuration Management Gaps?
Gaps can develop when inventories become outdated, baseline configurations are incomplete, or system modifications occur without documented review. Organizations may also encounter unnecessary administrative privileges, enabled services that are no longer required, or inconsistent controls over software installation.
Consistent administration and reliable IT support can help maintain configuration records as systems change and provide clearer ownership for routine technology modifications.
How Can Organizations Prepare for CMMC Configuration Management Assessment?
Preparation starts with identifying systems in scope and comparing their current configurations with documented baselines. Organizations can then review security settings, change procedures, administrative privileges, system functionality, and software controls.
Companies using IT outsourcing in Phoenix should also define responsibilities between internal personnel and external providers. Regardless of who performs a change, the organization needs appropriate approval, documentation, and evidence to support its configuration management practices.
Build a Consistent Approach to CMMC Configuration Management
CMMC configuration management connects system inventories, approved baselines, security settings, controlled changes, least functionality, and software restrictions. Maintaining these practices as systems change provides clearer evidence of how configurations are governed.
Blue Fox Group can help organizations evaluate technology practices and prepare their systems and documentation for CMMC requirements.
FAQ's
Is Configuration Management Required for CMMC Level 1?
The nine Configuration Management practices discussed here are CMMC Level 2 requirements. Organizations should determine which CMMC level applies to their contractual requirements.
How Many Configuration Management Requirements Are in CMMC Level 2?
CMMC Level 2 includes nine Configuration Management requirements, identified as CM.L2-3.4.1 through CM.L2-3.4.9.
What Should a CMMC Configuration Baseline Include?
A baseline should document the approved configuration of applicable systems and provide enough detail to identify and evaluate changes from that approved state.
How Often Should Configuration Baselines Be Updated?
Updates should reflect changes to applicable systems so the documented baseline continues to represent the approved configuration.
Does CMMC Require System Changes to Be Approved?
CMMC Level 2 requires organizations to track, review, approve or disapprove, and log changes to organizational systems.
Can Users Install Their Own Software Under CMMC?
CMMC requires organizations to control and monitor user-installed software. Organizations should establish and enforce policies defining what installation activity is permitted.








