Verizon’s 2025 Data Breach Investigations Report clocked the median time from disclosure to mass exploitation of critical edge-device vulnerabilities at zero days. Defenders answered at a median of 32 days, and only 54% of those exposed devices ever got fully remediated.

Remediate vulnerabilities in accordance with risk assessments is the control that closes that gap on paper: NIST SP 800-171 requirement 3.11.3, carried into CMMC Level 2 as practice RA.L2-3.11.3. Defense contractors now sign contracts against it in every new DoD award.

Remediate Vulnerabilities in Accordance With Risk Assessments, Distilled
The phrase is NIST SP 800-171 control 3.11.3 and CMMC practice RA.L2-3.11.3, contractual in new DoD solicitations since the acquisition rule took effect November 10, 2025.
Verizon’s 2025 DBIR: exploitation opens 20% of breaches, critical edge CVEs reach mass exploitation in a median of zero days, and defenders take 32 days.
Blend CVSS severity, EPSS probability, KEV listing, and asset criticality into a documented scoring method; CVSS alone is not a risk assessment.
Publish SLA tiers, 72 hours for internet-facing KEV entries down to 90 days for contained mediums, and let every deadline trace to the scoring.
Close tickets only on verification rescans, and carry what must wait on a POA&M with dated milestones and named owners.
Keep six artifacts assessment-ready: the risk assessment, SLA policy, scan reports, verified tickets, the POA&M, and a trending metrics pack.

The clock started November 10, 2025, when the CMMC acquisition rule took effect and the requirement began appearing in DoD solicitations. Exploitation math on one side, contract law on the other; the risk-based remediation program in between is the only thing that satisfies both.

What It Means to Remediate Vulnerabilities in Accordance With Risk Assessments

The control’s wording does two jobs in eight words. Remediate means fix, mitigate, or formally accept with justification, and in accordance with risk assessments means the order and the deadlines must trace back to a documented scoring of likelihood and impact.

Assessors read it exactly that way. A contractor patching everything alphabetically fails the control as surely as one patching nothing, because neither can show the risk assessment driving the sequence; NIST SP 800-30 supplies the assessment method the control assumes.

The Exploit Race That Forces You to Remediate Vulnerabilities Faster

Remediate Vulnerabilities in Accordance With Risk Assessments: The CMMC Control, Decoded

Figure 1. The race the control exists to win. Source: Verizon 2025 DBIR.

The DBIR numbers explain the urgency behind the paperwork. Exploitation of vulnerabilities now opens 20% of breaches, edge devices and VPNs took 22% of that action after growing eight-fold in a year, and our threat risk assessment guide maps the actors doing the exploiting.

The Compliance Stack That Enforces How You Remediate Vulnerabilities

NIST SP 800-171 states it, Revision 3 of May 2024 restructures it, the CMMC Program rule effective December 16, 2024 makes it assessable, and the acquisition rule wires it into contract clauses. Four documents, stacked into a single enforceable obligation.

Document Date What it does to the requirement
NIST SP 800-171 Rev 2, 3.11.3 2020; the current CMMC baseline States the control in eight words
NIST SP 800-171 Rev 3 May 14, 2024 Folds remediation into vulnerability monitoring, 3.11.2
CMMC Program rule, 32 CFR 170 Effective December 16, 2024 Makes the control assessable at Level 2
CMMC acquisition rule, 48 CFR Effective November 10, 2025 Puts CMMC clauses into new DoD contracts
CISA BOD 22-01 and the KEV catalog Ongoing since November 2021 Sets the federal reference deadlines for exploited CVEs
NIST SP 800-40 Rev 4 April 2022 The patch management planning guide behind it all

The CMMC Dates Behind How You Remediate Vulnerabilities

Remediate Vulnerabilities in Accordance With Risk Assessments: The CMMC Control, Decoded

Figure 2. Two final rules in thirteen months made the control a contract term. Sources: Federal Register; DoD CIO.

Non-defense readers still inherit the logic. BOD 22-01 binds federal civilian agencies to KEV catalog due dates, cyber insurers and customers copy the expectations into questionnaires, and our NIST CSF risk assessment guide shows the matching duty inside the CSF’s Respond function, with the CSF 2.0 implementation guide carrying the build-out.

Scoring: How Risk Assessments Choose Where You Remediate Vulnerabilities First

Prioritization is where most programs quietly stop being risk-based. The NVD published over 40,000 CVEs in 2024 alone, no team patches that, and the scoring stack below exists to shrink the number to a defensible fix list your assessor can follow.

Signal What it tells you How to use it in the risk assessment
CVSS 4.0 Technical severity of the flaw itself Baseline severity input, never the whole answer
EPSS Probability of exploitation in the next 30 days Multiply against severity to sort the backlog
CISA KEV Confirmed exploitation in the wild Automatic top tier; treat listing as a deadline
SSVC Decision tree blending exploitation, exposure, impact Turns scores into act, track, or defer decisions
Asset criticality What the vulnerable system touches CUI systems and crown jewels jump the queue
Compensating controls Whether the exposure is actually reachable Downgrades what segmentation already contains

The Funnel That Decides Where You Remediate Vulnerabilities First

Remediate Vulnerabilities in Accordance With Risk Assessments: The CMMC Control, Decoded

Figure 3. Each stage shrinks the work; the documentation of each cut is the risk assessment. Sources: NVD; CISA.

Blend at least two signals and write the recipe down. CVSS alone drowns you; forty-plus percent of CVEs score high or critical. EPSS and the KEV catalog cut the urgent set to hundreds, and first.org publishes both scoring systems free.

Context is the part only you can supply. Asset criticality and reachability come from your inventory and architecture, which is why our cybersecurity risk management guide and CISA’s SSVC decision model both anchor scores to the system’s mission, and the vulnerabilities on internet-facing CUI systems outrank everything.

SLA Tiers to Remediate Vulnerabilities in Accordance With Risk Assessments

BOD 22-01 gives the pattern, KEV-listed flaws due in two weeks when newly cataloged, and a contractor SLA table that tiers everything else by score and exposure is the single strongest artifact you can hand an assessor; NIST SP 800-40 calls it enterprise patch planning. Deadlines are what make the risk assessment operational.

Tier Definition Remediation deadline
KEV, internet-facing On CISA’s catalog, reachable from outside 72 hours to mitigate, 14 days to remediate
Critical, exposed CVSS 9+, high EPSS, no compensating control 7 days
High CVSS 7-8.9 on production systems 30 days
Medium CVSS 4-6.9, or contained by segmentation 90 days
Low Minimal exposure, difficult exploitation Next maintenance cycle, documented
Cannot remediate Legacy or vendor-blocked POA&M entry with milestones and compensating controls

Verification closes the loop the control implies. Rescan after every fix, record the before-and-after, and when a fix has to wait, the POA&M carries it with dated milestones; our incident response plan walkthrough covers the day a deferred item detonates, and the cyber security risk management plan guide frames the budget case.

Evidence That You Remediate Vulnerabilities in Accordance With Risk Assessments

Assessment day rewards receipts over narratives. A CMMC assessor working the control will sample vulnerabilities from your scans and walk each one to a closed ticket, a rescan, or a POA&M line, so the evidence below should exist before anyone books the assessment.

Artifact What it proves Refresh
Scored risk assessment The rules that rank vulnerabilities Annually and on major change
SLA policy with tiers Deadlines trace to the assessment On policy review
Authenticated scan reports Coverage of the full asset inventory Per scan cadence
Remediation tickets with rescans Fixes verified, never just claimed Continuous
POA&M with milestones Deferred items managed, never ignored Monthly review
Metrics pack for leadership The program runs between assessments Monthly or quarterly

Four Metrics That Prove You Remediate Vulnerabilities on Risk-Based Deadlines

Remediate Vulnerabilities in Accordance With Risk Assessments: The CMMC Control, Decoded

Figure 4. Trend these monthly; direction beats any single value.

Track the four numbers on the panel and trend them, because assessors and boards both read direction before absolute values. Our cybersecurity KRI examples and the mid-size company KRI template wire those metrics into a monthly pack, and zero-trust platform comparisons cover the tooling.

Remediate Vulnerabilities in Accordance With Risk Assessments FAQs

What does remediate vulnerabilities in accordance with risk assessments mean in CMMC?

It is NIST SP 800-171 requirement 3.11.3, assessed in CMMC Level 2 as RA.L2-3.11.3. The control demands that patching order and deadlines follow a documented risk assessment, so fixing at random, or purely by CVSS score, technically fails even when the patching itself is fast.

How fast must you remediate vulnerabilities under CMMC and NIST 800-171?

Neither document sets universal day counts; your risk assessment does. BOD 22-01’s two-week KEV deadline is the accepted federal reference point, and the SLA tiers above, 72 hours to 90 days by risk, hold up in front of assessors because each tier traces to scoring.

Does a POA&M count when you cannot remediate vulnerabilities on time?

Yes, when it is honest. A POA&M entry needs the risk score, compensating controls, dated milestones, and an owner; assessors accept deferral as risk management and read an undated, unowned backlog as the opposite. CMMC also caps which controls may sit on a POA&M at assessment.

Which scores should drive how you remediate vulnerabilities: CVSS, EPSS, or KEV?

All three, in layers. KEV listing is an automatic act-now, EPSS sorts the remainder by exploitation probability, and CVSS supplies the severity input; blending them inside your documented method is exactly what in accordance with risk assessments means in practice.

What evidence shows assessors you remediate vulnerabilities in accordance with risk assessments?

Six artifacts: the scored risk assessment, a tiered SLA policy, authenticated scan reports, closed tickets with verification rescans, a maintained POA&M, and a trending metrics pack. Sampling is standard, so any vulnerability from any scan should walk cleanly to one of those endings.

Can small contractors remediate vulnerabilities in accordance with risk assessments without a SOC?

Yes; the control scales down gracefully. A monthly authenticated scan, the KEV catalog as the priority feed, one SLA page, and a spreadsheet POA&M satisfy the logic at small scale, and our guidance on how often risk assessments should be conducted sets a cadence you can defend.

Ways Teams Fail to Remediate Vulnerabilities in Accordance With Risk Assessments

Scanning without remediating is the most common way contractors fail this control, and the pattern shows up long before assessment day. The failures below recur across engagements, and every fix assumes the SLA table above already exists; the ISO 27001 risk assessment guide covers the sibling duty outside CMMC. Fix them while they are still tickets.

Failure Why it happens Fix
Scan-and-shelve Reports generated, tickets never cut Auto-create tickets from scan findings, with SLA dates
CVSS-only queues Severity mistaken for risk Add EPSS and KEV; document the blend
Inventory blind spots Unscanned assets stay unremediated Reconcile scans against the asset inventory monthly
Perpetual POA&M Deferrals without milestones age silently Monthly POA&M review with named owners
No verification rescans Fixed means someone said so Close tickets only on clean rescan evidence
SLA copied, never resourced Deadlines fail from day one Size tiers to actual patch-window capacity

The Road to 2028: CMMC Phase-In and How You Remediate Vulnerabilities

CMMC’s phase-in gives the control teeth on a schedule. The acquisition rule started Phase 1 with self-assessments in new solicitations on November 10, 2025, certification requirements escalate through the phases over three years, and primes are already flowing the clauses down to subcontractors ahead of the calendar. Waiting for your phase number is how subcontractors lose primes.

Rev 3 adoption is the next paperwork wave. DoD still assesses against Revision 2, the transition to Revision 3’s consolidated vulnerability management control will arrive by rulemaking, and mapping your program to both texts now costs an afternoon instead of a re-audit later.

AI is joining both sides of the race. Attackers already use LLMs to weaponize disclosures faster, defenders get machine-suggested prioritization in every major scanner, and the supply chain angle our NIST C-SCRM guide covers becomes the control’s next frontier as SBOMs expose inherited CVEs.

The zero-day median from the 2025 DBIR is the number to build against. When mass exploitation starts before your scanner’s next scheduled run, the risk assessment stops being a compliance artifact and becomes the only mechanism deciding what gets fixed while it still matters.

 

Get Help to Remediate Vulnerabilities in Accordance With Risk Assessments

Contractors rarely fail this control for lack of scanning; they fail it for lack of traceability. Risk Publishing builds the scoring method, SLA tiers, and evidence pack that make remediate vulnerabilities in accordance with risk assessments auditable; scope is on the services page, and the contact form gets you a reply this week.

Index