Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
MATRIX · IT / OTv1.0 · REVIEWED 2026-07-28

CMMC Level 2 Influence Matrix

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

Which practices influence which CMMC Level 2 practice identifiers. This is an influence matrix, not a coverage or readiness matrix: no row states that a practice satisfies a CMMC requirement, and the matrix cannot be used to calculate a score.

How to use it

Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.

Read this first

How these mappings were made

Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.

Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.

TermMeaning
DirectThe practice addresses the substance of the requirement head-on.
SupportingThe practice materially helps satisfy the requirement but does not cover it alone.
EnablingThe practice is a prerequisite that makes the requirement achievable.
ContextualThe practice informs or constrains how the requirement is met.
High confidenceReviewed against the primary source text; the relationship is explicit.
Moderate confidenceReviewed against the primary source; the relationship is a reasoned interpretation.
Low confidenceDirectional only. Treat as a starting point for your own analysis.

IT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
IT-01Phishing-resistant MFAIA.L2-3.5.3DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-02Asset inventoryCM.L2-3.4.1DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-03Technical debt reductionCM.L2-3.4.1 / SI.L2-3.14.1SupportingModerateSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-04Flexible technology stackCM.L2-3.4.2SupportingModerateSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-05Logical segmentationSC.L2-3.13.1 / SC.L2-3.13.5DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-06Risk-based vulnerability managementRA.L2-3.11.2 / RA.L2-3.11.3DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-07Security in the development lifecycleCM.L2-3.4.3SupportingModerateSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-08Secure AI adoptionAC.L2-3.1.3 / AC.L2-3.1.20SupportingModerateSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-09Backup and disaster recoveryMP.L2-3.8.9DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.
IT-10Technical workforce readinessAT.L2-3.2.1 / AT.L2-3.2.2DirectHighSupports the requirement; it does not satisfy it on its own and does not establish an assessment outcome. Scope, implementation quality, and evidence decide that.

CMMC Level 2 Influence Matrix · version 1.0 · reviewed 2026-07-28 · file name batb-cmmc-level-2-influence-matrix

Generated from Framework crosswalk at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-cmmc-level-2-influence-matrix to keep filenames consistent across your team.