CMMC Checklist | Certifyi
Compliance checklist

CMMC Checklist

CMMC governs how defense contractors protect federal information. Here's the path to your required maturity level.

Book a 20-min deal readiness call
  1. Determine your required CMMC level

    Level 1, 2, or 3 depends on whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

  2. Scope your environment

    Identify every system that stores, processes, or transmits FCI or CUI.

  3. Map to NIST SP 800-171

    CMMC Level 2 aligns to the 110 controls of NIST SP 800-171, the backbone of the assessment.

  4. Run a gap assessment

    Compare current practices to the required practices for your level and list what's missing.

  5. Build a System Security Plan (SSP)

    Document how each control is implemented across your in-scope systems.

  6. Create a POA&M

    A Plan of Action and Milestones for any gaps you haven't closed yet.

  7. Implement controls

    Access control, incident response, media protection, configuration management, and the rest.

  8. Conduct your assessment

    Level 1 self-attests annually; Level 2 often requires a certified third-party assessor (C3PAO).

  9. Submit your score

    Report your assessment score to the Supplier Performance Risk System (SPRS) as required.

  10. Maintain and reassess

    Keep evidence current; CMMC requires demonstrable, ongoing adherence.

← Back to all checklists

What auditors actually ask for

  • Can you prove which systems store or transmit CUI?
  • Is your System Security Plan current and complete for all 110 controls?
  • Does your POA&M have realistic dates and named owners?
  • Can you evidence multifactor authentication on all CUI access?
  • Have you submitted a current score to SPRS?

Where teams most often trip up

  • Scoping too broadly and pulling the whole network into assessment
  • An SSP that describes intent rather than implemented reality
  • A POA&M used to defer controls indefinitely
  • Assuming Level 1 self-attestation covers CUI, it does not
  • Missing flow-down requirements to subcontractors

Realistic timeline

Level 1 self-assessment can be weeks. Level 2 with a C3PAO commonly takes 6-12 months including remediation.

Scroll to Top