CMMC compliance checklist

The CMMC compliance checklist, in the order that saves money.

This CMMC compliance checklist is sequenced rather than alphabetical, because the order you do this in decides what it costs. Scope first, then the System Security Plan, then the requirements, then evidence. Work through it and you will know which level applies to you, what is in scope, where you stand against the 110 requirements, and what has to be true before you affirm anything in SPRS.

Last reviewed

Before you start

CMMC Phase 2 was suspended on 13 July 2026 and a reform task force reports in mid-September. Phase 1 was not suspended, and neither was DFARS 252.204-7012. Level 1 and Level 2 self-assessment requirements are in solicitations now, and the 110 NIST 800-171 requirements remain a contract term. Everything on this checklist is work you owe today.

1. Scope, before anything else

Every other cost on this page is a multiple of the answer to this section. Do not skip it and do not rush it.

  • Identify the information, and name it correctly
    Federal Contract Information and Controlled Unclassified Information are different obligations. FCI is non-public information generated for or provided by the government under a contract. CUI requires safeguarding under law, regulation or government-wide policy — technical data packages, drawings, specifications. If you hold CUI, you are at Level 2 or above.
  • Trace where it actually goes
    How it arrives, which mailboxes it lands in, which file shares hold it, whose laptop it gets copied to, which subcontractors receive it. Trace the real flow, not the intended one. This step reliably finds CUI somewhere nobody expected.
  • Decide enclave or whole estate
    A segregated enclave that holds CUI and nothing else is usually far cheaper to assess and to run than the whole company. It is only cheaper if the segmentation is real — separate identity, separate network path, controlled data movement in and out.
  • Categorize every asset in the boundary
    Assets that process, store or transmit CUI; security protection assets; anything else inside the boundary. The categorization drives what gets assessed and what gets documented.
  • List every external service provider inside the boundary
    Cloud platforms, managed service providers, the IT firm with administrative access. Their controls are inside your assessment whether or not you have examined them.

2. If you are Level 1: the 15 requirements

FCI only, no CUI. These are the basic safeguarding requirements from FAR 52.204-21, and all 15 must be met — Level 1 permits no plan of action.

  • Limit access to authorized users, processes and devices
    Accounts exist for people who should have them, and only those people.
  • Limit access to the functions each user is authorized to perform
    Least privilege, applied and reviewed rather than declared.
  • Control connections to external systems
    Including personal devices and third-party services holding FCI.
  • Control what is posted publicly
    Someone reviews what goes on the website and social channels for FCI.
  • Identify users, processes and devices
    Unique identities, no shared logins.
  • Authenticate before granting access
    Passwords managed, defaults changed, multi-factor wherever you can reach.
  • Sanitize or destroy media before disposal or reuse
    Drives, laptops, printers, USB media — with a record of it.
  • Limit physical access to systems and equipment
    Locked doors, controlled server space, escorted visitors.
  • Escort visitors and monitor visitor activity
    And keep the log.
  • Maintain audit logs of physical access
    A visitor book counts, if it is kept properly.
  • Control and manage physical access devices
    Keys, badges, codes — issued, tracked and recovered.
  • Monitor, control and protect communications at the boundary
    A firewall, configured, at every boundary of the system.
  • Separate publicly accessible systems from internal ones
    The public website does not sit on the internal network.
  • Identify, report and correct flaws in a timely manner
    A patch cadence you can evidence.
  • Provide protection from malicious code, and keep it current
    Deployed everywhere in scope, updating, and actually running.

3. If you are Level 2: getting to 110

The full NIST 800-171 Revision 2 set. Rather than restate all 110, this is the readiness work that decides whether they go well — in the order that costs least.

  • Write the System Security Plan first
    One entry per requirement: how it is implemented here, on which systems, who owns it, what the evidence is. The SSP is what an assessment is run against, and an SSP that does not match reality undermines every requirement after it.
  • Score yourself using the SPRS method and post it
    Start at 110, deduct 5, 3 or 1 point per unimplemented requirement. Post the score in SPRS as DFARS 252.204-7019 requires. Be honest: the score is an attestation, and an inflated one is a False Claims Act exposure rather than a shortcut.
  • Close every 5-point and 3-point gap
    These cannot be carried on a plan of action, so they are the critical path. Multi-factor authentication for all privileged and network access, and FIPS-validated cryptography — in validated mode — are the two that most often turn out to be incomplete.
  • Make logging reviewable, not just present
    Generated, retained, protected from tampering, and reviewed by a named person on a defined cadence with a record that it happened.
  • Get the inventory accurate
    You cannot defend a boundary you cannot enumerate, and every scoping dispute with an assessor is settled with the inventory.
  • Run role-based training and keep the records
    Three requirements, cheap to satisfy, routinely lost for want of records.
  • Test the incident response plan, and reconcile it with 72 hours
    A tested capability, not a document — and it has to be able to meet the 72-hour reporting duty in DFARS 252.204-7012.
  • Collect evidence continuously and date it
    Configuration exports, screenshots, tickets, review notes, training records. A requirement is about operation over time; evidence assembled in the final fortnight proves a control existed once.

4. The CMMC self-assessment and affirmation

The step that carries personal accountability, and the one people treat as administrative.

  • Assess against every requirement at your level
    MET, NOT MET or NOT APPLICABLE for each, with the evidence recorded. There is no partial credit on an individual requirement.
  • Record the result in SPRS
    Score, scope description, and the date of the assessment.
  • Name an Affirming Official
    A senior person with the authority and the knowledge to affirm continuing compliance. They are named, and they are accountable for the claim.
  • Affirm annually, and diarize it
    Affirmation is annual regardless of whether your assessment is triennial. A lapsed affirmation is an eligibility problem, not a paperwork one.
  • Re-assess when the environment changes materially
    A migration, an acquisition, a new site or a new CUI flow can invalidate a score that was accurate when it was posted.

5. Your subcontractors

The section most checklists omit, and the one you are answerable for. Requirements flow down at every tier.

  • Identify every subcontractor that will touch FCI or CUI
    Including the ones that receive a drawing once. Handling is handling.
  • Determine the level each one owes
    FCI only means Level 1 (Self). CUI means Level 2 — and where your prime contract carries a Level 3 requirement, the minimum for that subcontractor is Level 2 with a C3PAO certification.
  • Flow the requirement down in the subcontract
    In writing, at the right level, before any covered information moves.
  • Verify status before award, not after
    Confirm the current status or self-assessment at the required level before the subcontract is awarded, and confirm they affirm annually.
  • Monitor between attestations
    An attestation describes a network on the day it was signed. Continuous external monitoring shows what that network looks like now — new exposed services, expired certificates, infrastructure that appeared without warning. It is the only part of this list that tells you something has changed before an incident does.

Checklist questions.

What are the CMMC requirements?
They depend on level. Level 1 is 15 basic safeguarding requirements from FAR 52.204-21, covering Federal Contract Information. Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, covering CUI. Level 3 adds 24 requirements selected from NIST SP 800-172.
How do I do a CMMC self-assessment?
Scope the systems that handle FCI or CUI, assess each requirement at your level as MET, NOT MET or NOT APPLICABLE with evidence, calculate the score using the SPRS method, post it in SPRS, and have a named Affirming Official affirm it. Level 1 is annual; Level 2 (Self) follows the same method against all 110 requirements.
Can I be compliant with gaps outstanding?
At Level 2, a score of at least 88 of 110 can support a Conditional status with the remainder on a plan of action closed within 180 days — but only the 1-point requirements are eligible for that plan. Level 1 permits no plan of action: all 15 must be met.
Where do I start if we have done nothing?
Find the CUI and decide the boundary. Every other cost scales from that decision, and starting with tooling before scope is the most common way to overspend on this.
Does this checklist still apply after the July 2026 suspension?
Yes. The suspension covers CMMC Phase 2 and the phases after it. Phase 1 self-assessment requirements continue, and the NIST 800-171 obligation under DFARS 252.204-7012 is unchanged.

Section 5 is the hard one. We can do it for you.

Book a 30-minute call and we will rate one of your CUI-handling subcontractors from the outside — no questionnaire, no cooperation needed, and an answer in minutes rather than an attestation cycle.