The CMMC compliance checklist, in the order that saves money.
This CMMC compliance checklist is sequenced rather than alphabetical, because the order you do this in decides what it costs. Scope first, then the System Security Plan, then the requirements, then evidence. Work through it and you will know which level applies to you, what is in scope, where you stand against the 110 requirements, and what has to be true before you affirm anything in SPRS.
Last reviewed
Before you start
1. Scope, before anything else
Every other cost on this page is a multiple of the answer to this section. Do not skip it and do not rush it.
- Identify the information, and name it correctlyFederal Contract Information and Controlled Unclassified Information are different obligations. FCI is non-public information generated for or provided by the government under a contract. CUI requires safeguarding under law, regulation or government-wide policy — technical data packages, drawings, specifications. If you hold CUI, you are at Level 2 or above.
- Trace where it actually goesHow it arrives, which mailboxes it lands in, which file shares hold it, whose laptop it gets copied to, which subcontractors receive it. Trace the real flow, not the intended one. This step reliably finds CUI somewhere nobody expected.
- Decide enclave or whole estateA segregated enclave that holds CUI and nothing else is usually far cheaper to assess and to run than the whole company. It is only cheaper if the segmentation is real — separate identity, separate network path, controlled data movement in and out.
- Categorize every asset in the boundaryAssets that process, store or transmit CUI; security protection assets; anything else inside the boundary. The categorization drives what gets assessed and what gets documented.
- List every external service provider inside the boundaryCloud platforms, managed service providers, the IT firm with administrative access. Their controls are inside your assessment whether or not you have examined them.
2. If you are Level 1: the 15 requirements
FCI only, no CUI. These are the basic safeguarding requirements from FAR 52.204-21, and all 15 must be met — Level 1 permits no plan of action.
- Limit access to authorized users, processes and devicesAccounts exist for people who should have them, and only those people.
- Limit access to the functions each user is authorized to performLeast privilege, applied and reviewed rather than declared.
- Control connections to external systemsIncluding personal devices and third-party services holding FCI.
- Control what is posted publiclySomeone reviews what goes on the website and social channels for FCI.
- Identify users, processes and devicesUnique identities, no shared logins.
- Authenticate before granting accessPasswords managed, defaults changed, multi-factor wherever you can reach.
- Sanitize or destroy media before disposal or reuseDrives, laptops, printers, USB media — with a record of it.
- Limit physical access to systems and equipmentLocked doors, controlled server space, escorted visitors.
- Escort visitors and monitor visitor activityAnd keep the log.
- Maintain audit logs of physical accessA visitor book counts, if it is kept properly.
- Control and manage physical access devicesKeys, badges, codes — issued, tracked and recovered.
- Monitor, control and protect communications at the boundaryA firewall, configured, at every boundary of the system.
- Separate publicly accessible systems from internal onesThe public website does not sit on the internal network.
- Identify, report and correct flaws in a timely mannerA patch cadence you can evidence.
- Provide protection from malicious code, and keep it currentDeployed everywhere in scope, updating, and actually running.
3. If you are Level 2: getting to 110
The full NIST 800-171 Revision 2 set. Rather than restate all 110, this is the readiness work that decides whether they go well — in the order that costs least.
- Write the System Security Plan firstOne entry per requirement: how it is implemented here, on which systems, who owns it, what the evidence is. The SSP is what an assessment is run against, and an SSP that does not match reality undermines every requirement after it.
- Score yourself using the SPRS method and post itStart at 110, deduct 5, 3 or 1 point per unimplemented requirement. Post the score in SPRS as DFARS 252.204-7019 requires. Be honest: the score is an attestation, and an inflated one is a False Claims Act exposure rather than a shortcut.
- Close every 5-point and 3-point gapThese cannot be carried on a plan of action, so they are the critical path. Multi-factor authentication for all privileged and network access, and FIPS-validated cryptography — in validated mode — are the two that most often turn out to be incomplete.
- Make logging reviewable, not just presentGenerated, retained, protected from tampering, and reviewed by a named person on a defined cadence with a record that it happened.
- Get the inventory accurateYou cannot defend a boundary you cannot enumerate, and every scoping dispute with an assessor is settled with the inventory.
- Run role-based training and keep the recordsThree requirements, cheap to satisfy, routinely lost for want of records.
- Test the incident response plan, and reconcile it with 72 hoursA tested capability, not a document — and it has to be able to meet the 72-hour reporting duty in DFARS 252.204-7012.
- Collect evidence continuously and date itConfiguration exports, screenshots, tickets, review notes, training records. A requirement is about operation over time; evidence assembled in the final fortnight proves a control existed once.
4. The CMMC self-assessment and affirmation
The step that carries personal accountability, and the one people treat as administrative.
- Assess against every requirement at your levelMET, NOT MET or NOT APPLICABLE for each, with the evidence recorded. There is no partial credit on an individual requirement.
- Record the result in SPRSScore, scope description, and the date of the assessment.
- Name an Affirming OfficialA senior person with the authority and the knowledge to affirm continuing compliance. They are named, and they are accountable for the claim.
- Affirm annually, and diarize itAffirmation is annual regardless of whether your assessment is triennial. A lapsed affirmation is an eligibility problem, not a paperwork one.
- Re-assess when the environment changes materiallyA migration, an acquisition, a new site or a new CUI flow can invalidate a score that was accurate when it was posted.
5. Your subcontractors
The section most checklists omit, and the one you are answerable for. Requirements flow down at every tier.
- Identify every subcontractor that will touch FCI or CUIIncluding the ones that receive a drawing once. Handling is handling.
- Determine the level each one owesFCI only means Level 1 (Self). CUI means Level 2 — and where your prime contract carries a Level 3 requirement, the minimum for that subcontractor is Level 2 with a C3PAO certification.
- Flow the requirement down in the subcontractIn writing, at the right level, before any covered information moves.
- Verify status before award, not afterConfirm the current status or self-assessment at the required level before the subcontract is awarded, and confirm they affirm annually.
- Monitor between attestationsAn attestation describes a network on the day it was signed. Continuous external monitoring shows what that network looks like now — new exposed services, expired certificates, infrastructure that appeared without warning. It is the only part of this list that tells you something has changed before an incident does.
Checklist questions.
What are the CMMC requirements?
How do I do a CMMC self-assessment?
Can I be compliant with gaps outstanding?
Where do I start if we have done nothing?
Does this checklist still apply after the July 2026 suspension?
Related reading.
Section 5 is the hard one. We can do it for you.
Book a 30-minute call and we will rate one of your CUI-handling subcontractors from the outside — no questionnaire, no cooperation needed, and an answer in minutes rather than an attestation cycle.