Example, read only. A sample account that shows what finished CMMC looks like.

← Back to the 15 safeguards
SI · System and Information IntegrityMET

Safeguard 12 of 15 · SI.L1-b.1.xii

SI.L1-3.14.1 · FAR 52.204-21 (b)(1)(xii) · NIST SP 800-171 3.14.1

Flaw Remediation

Identify, report, and correct information and information system flaws in a timely manner

What it means

When your software or computers have security updates available, install them, and keep a log showing you did.

Why it matters

'I installed updates' without proof isn't enough. A screenshot of update history, a patch log, or an endpoint-management dashboard showing patched devices all work, pick one and be consistent.

How to do it, Microsoft 365 / Intune

  1. 1Go to Intune / Endpoint Manager → Reports → Device compliance or Update compliance
  2. 2Screenshot the dashboard showing devices patched within policy
  3. 3Also screenshot the Update rings / policies page showing the patch cadence

Capture: Dashboard screenshot plus update-policy screenshot.

The proof on file

  • intune-patch-compliance.pngReviewed, sufficient

Every file is checked by Charlie the moment it is uploaded, so a gap is caught on the spot, not at the assessment.

The narrative on file

Microsoft Defender and Windows Update for Business keep every managed workstation patched and current. Intune reports patch status, and the owner reviews the compliance dashboard weekly to confirm all covered devices are up to date.

You answer in plain English; Charlie writes the official narrative for your System Security Plan.

What makes it pass

  • Patch policy clearly states critical updates within 30 days, others at least monthly
  • Recent patch log entries cover every device in scope (no missing devices)
  • Per-device update history screenshots show recent install dates (within policy window)
  • For Intune path: dashboard shows compliant device count vs total in scope

Assessment objectives, NIST SP 800-171A

[a] The time within which to identify system flaws is specified
MET
[b] System flaws are identified within that time frame
MET
[c] The time within which to report system flaws is specified
MET
[d] System flaws are reported within that time frame
MET
[e] The time within which to correct system flaws is specified
MET
[f] System flaws are corrected within that time frame
MET

This is one of 15

Answer in plain English, drop the proof, confirm it MET.

Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.