CMMC Checklist
CMMC governs how defense contractors protect federal information. Here's the path to your required maturity level.
Book a 20-min deal readiness callDetermine your required CMMC level
Level 1, 2, or 3 depends on whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Scope your environment
Identify every system that stores, processes, or transmits FCI or CUI.
Map to NIST SP 800-171
CMMC Level 2 aligns to the 110 controls of NIST SP 800-171, the backbone of the assessment.
Run a gap assessment
Compare current practices to the required practices for your level and list what's missing.
Build a System Security Plan (SSP)
Document how each control is implemented across your in-scope systems.
Create a POA&M
A Plan of Action and Milestones for any gaps you haven't closed yet.
Implement controls
Access control, incident response, media protection, configuration management, and the rest.
Conduct your assessment
Level 1 self-attests annually; Level 2 often requires a certified third-party assessor (C3PAO).
Submit your score
Report your assessment score to the Supplier Performance Risk System (SPRS) as required.
Maintain and reassess
Keep evidence current; CMMC requires demonstrable, ongoing adherence.
What auditors actually ask for
- Can you prove which systems store or transmit CUI?
- Is your System Security Plan current and complete for all 110 controls?
- Does your POA&M have realistic dates and named owners?
- Can you evidence multifactor authentication on all CUI access?
- Have you submitted a current score to SPRS?
Where teams most often trip up
- Scoping too broadly and pulling the whole network into assessment
- An SSP that describes intent rather than implemented reality
- A POA&M used to defer controls indefinitely
- Assuming Level 1 self-attestation covers CUI, it does not
- Missing flow-down requirements to subcontractors
Realistic timeline
Level 1 self-assessment can be weeks. Level 2 with a C3PAO commonly takes 6-12 months including remediation.