IR.L2-3.6.3 · NIST SP 800-171 3.6.3

Incident Response Testing

Test the organizational incident response capability.

1 point if not metPOA&M eligible1 assessment objective

What an assessor scores, the objectives

IR.L2-3.6.3 is met only when every one of these 1 objectives, from NIST SP 800-171A, is satisfied. A single missed objective makes the whole requirement not met.

  • a.the incident response capability is tested

How a C3PAO checks it

NIST SP 800-171A defines three assessment methods. For IR.L2-3.6.3, an assessor uses these:

Examine

Incident response policy; contingency planning policy; procedures addressing incident response testing; procedures addressing contingency plan testing; incident response testing material; incident response test results; incident response test plan; incident response plan; contingency plan; system security plan; other relevant documents or records

Interview

Personnel with incident response testing responsibilities; personnel with information security responsibilities; personnel with responsibilities for testing plans related to incident response

Test

Mechanisms and processes for incident response

What it means, in context

Organizations test incident response capabilities to determine the effectiveness of the capabilities and to identify potential weaknesses or deficiencies . Incident response testing includes the use of checklists, walk-through or tabletop exercises, simulations (both parallel and full interrupt), and comprehensive exercises. Incident response testing can also include a determination of the effects on organizational operations (e.g., reduction in mission capabilities), organizational assets, and individuals due to incident response. NIST SP 800 -84 provides guidance on testing programs for information technology capabilities.

Testing incident response capability validates existing plans and highlights potential deficiencies. The test should address questions such as what happens during an incident ; who is responsible for incident management; what tasks are assigned within the IT organization; what support is needed from legal, public affairs, or other business components; how resources are added if needed during the incident ; and how law enforcement is involved. Any negative impacts to the normal day -to-day operations when responding to an incident should also be identified and documented. Example You decide to conduct an incident response table top exercise that simulates an attacker gaining access to the network through a compromised server. You include relevant IT staff such as security, database, network, and system administrators as par ticipants. You also request representatives from legal, human resources, and communications. You provide a scenario to the group and have prepared key questions aligned with the response plans to guide the exercise. During the exercise, you focus on how the team executes the incident response plan. Afterward, you conduct a debrief with everyone that was involved to provide feedback and develop improvements to the incident response plan [a]. Potential Assessment Considerations • Does the in cident response policy outline requirements for regular incident response plan testing and reviews of incident response capabilities [a]?

What passing evidence looks like

A dated record of testing the incident response capability: the tabletop exercise write up (scenario, participants, what worked, what changed in the plan).

Common ways contractors fail IR.L2-3.6.3

  • !Testing means exercised, not just written. One annual tabletop with a two paragraph record satisfies it; zero exercises means NOT MET no matter how good the plan reads.

The step by step walkthrough for Microsoft 365 GCC High, Google Workspace, and on premises setups, plus the exact evidence to capture, lives inside the Level 2 Accelerator.

Prove IR.L2-3.6.3, and the other 109

The Level 2 Accelerator walks all 110 requirements with you, generates your SSP, POA&M, and Audit Room from real evidence, includes the full Level 1 platform, and puts a credentialed officer alongside you for 180 days. Filed in 180 days, or we work free until you are.

No credit card. Phase 2 begins Nov 10, 2026, when applicable DoD solicitations start requiring a current Level 2 status to win the award.

IR.L2-3.6.3 questions, answered

How many points is CMMC requirement IR.L2-3.6.3 worth?+

IR.L2-3.6.3 is worth 1 point in the CMMC Level 2 score under 32 CFR 170.24. If it is not met, you lose 1 from your total of 110.

Can IR.L2-3.6.3 be placed on a POA&M?+

Yes. A gap on IR.L2-3.6.3 can be deferred to a Plan of Action and Milestones, provided your overall score is 88 or better and the item closes within 180 days.

What family does IR.L2-3.6.3 belong to?+

IR.L2-3.6.3 is in the Incident Response (IR) family, one of the 14 families of NIST SP 800-171 that make up CMMC Level 2.

Key references
  • NIST SP 800-171 Rev. 2 3.6.3