CMMC Compliance Checklist: 12 Steps Before Your Assessment
A CMMC compliance checklist is the list of steps a defense contractor follows to meet the Cybersecurity Maturity Model Certification requirements in its DoD contracts. In short: identify whether you handle FCI or CUI, pick your level, scope your systems, implement the required controls (15 for Level 1, 110 for Level 2), document them in a System Security Plan, score yourself in SPRS, and pass your assessment.

I spent ten years doing IT inside the government contractor world before I started NSOCIT. Audits weren't an occasional headache there. It was a typical quarterly process. And here's the thing I learned that nobody tells you on the first day: the companies that struggled with compliance almost never failed on the technology. They failed on the paperwork describing a network that didn't exist anymore, written by someone who left two years earlier.
CMMC is the same test with higher stakes. Phase 2 starts November 10, 2026, and that's when third-party Level 2 assessments start showing up in contracts.
TL;DR: Figure out if you handle CUI. Shrink your scope. Implement the controls, then write down what you actually did (not what a template says). Score yourself honestly in SPRS. Close gaps within 180 days. Start now, because most small contractors need 12 to 18 months to get Level 2 ready.

Where CMMC Stands Right Now
A quick timeline, because the dates have moved a few times and a lot of old articles are wrong:
October 15, 2024: DoD published the CMMC Program rule (32 CFR Part 170) in the Federal Register. It took effect December 16, 2024.
September 10, 2025: the DFARS acquisition rule (48 CFR) was published. As PreVeil summarized it, "CMMC requirements can be added to DoD contracts, RFPs, & RFIs starting November 10, 2025."
November 10, 2025: Phase 1 began. Self-assessments for Level 1 and Level 2 appear in solicitations.
November 10, 2026: Phase 2 begins. Level 2 third-party (C3PAO) assessments start appearing in applicable contracts.
Phases 3 and 4 follow in later years, until CMMC applies across all applicable contracts.
If you're reading this in the fall of 2026, Phase 2 is weeks away, not years. We covered the bigger picture in the impact of CMMC on government contractors. This post is the working checklist.

The Three CMMC Levels in Plain English
Level 1 protects FCI only. 15 requirements from FAR 52.204-21. Annual self-assessment.
Level 2 protects CUI. 110 requirements from NIST SP 800-171 Rev 2. Self-assessment or a third-party (C3PAO) assessment, every 3 years.
Level 3 protects CUI facing advanced threats. Level 2 plus selected NIST SP 800-172 requirements. Government-led assessment (DIBCAC).
FCI (Federal Contract Information) is basic contract info not meant for the public. CUI (Controlled Unclassified Information) is the sensitive stuff: technical drawings, specs, export-controlled data. Most small manufacturers and engineering firms that touch drawings are Level 2.
Every level also requires an annual affirmation from a senior official that you're still compliant. That signature carries real legal weight. Don't let anyone sign it casually.

The 12-Step CMMC Compliance Checklist
Here's the order I'd work in. Steps 1 through 4 are where most of the savings are.
1. Find out exactly what data you handle
Read your contracts and look for DFARS 252.204-7012 and CUI markings. Ask your prime contractor directly: "Will you be sending us CUI?" Get the answer in writing. If you only handle FCI, you're a Level 1, and your life is much simpler.
2. Confirm your CMMC level
Match your data to the levels above. Your contract or solicitation will ultimately state the required level. If you're not sure, assume Level 2 until someone with authority tells you otherwise.
3. Assign an owner
One named person owns CMMC. Not "the IT company." Not "everyone." A person inside the business who can make decisions, get budget, and answer an assessor's questions. The MSP helps. The owner is accountable.
4. Scope your CUI boundary (and make it small)
This is the most underrated step on the whole CMMC compliance checklist. Every system that stores, processes, or transmits CUI is in scope, and so is everything that protects it. If CUI is sprinkled across every laptop and file share in the company, all of them are in scope.
The fix is to build a small, clean enclave. Put CUI in one place, like a dedicated, properly configured cloud environment or a segmented network, and give access only to the people who need it. Smaller scope means fewer systems to secure, fewer to document, and a cheaper assessment.
5. Choose where CUI will live
If you use a cloud provider for CUI, DFARS 7012 expects it to meet FedRAMP Moderate or equivalent. Standard commercial Microsoft 365 generally isn't it. Government-focused cloud offerings exist for exactly this reason. Check before you migrate, not after.
6. Run a gap assessment against NIST SP 800-171
Go control by control. NIST SP 800-171A breaks the 110 requirements into 320 assessment objectives, and an assessor will check each one. For every control, record: met, not met, or partially met, with the evidence.
The NIST SP 800-171 publication sets the tone right in the abstract: "The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies." Translation: they will look.
7. Write your System Security Plan (SSP)
The SSP describes your system boundary, how every control is implemented, and who's responsible. It's required, and it's the first document an assessor reads.
Write what you actually do. A copy-paste template that describes a network you don't have is worse than no SSP, because now it's a document proving you don't know your own environment.
8. Build a POA&M for the gaps, and know the rules
A Plan of Action and Milestones lists each gap, the fix, the owner, and the date. Under CMMC, the rules are strict:
You need a minimum score of 88 out of 110 to qualify for conditional Level 2 status with open items.
Open POA&M items must be closed within 180 days.
Some higher-weighted controls can't be on a POA&M at all. They must be met at assessment time.
Level 1 doesn't allow POA&Ms.
9. Fix the gaps
This is the actual security work: MFA, encryption, logging, patching, access reviews, training, incident response. The next section breaks it down by family.
10. Collect evidence as you go
Screenshots, config exports, policy documents, training records, access review logs, backup test results. Assessors want proof that controls operate over time, not a folder built the night before. Start a shared evidence folder on day one.
11. Score yourself and submit to SPRS
The DoD scoring method starts at 110 and subtracts points for each unmet control, down to a possible negative 203. Submit your score to the Supplier Performance Risk System (SPRS). Be honest. An inflated SPRS score is a False Claims Act problem waiting to happen, and the DOJ has been paying attention.
12. Prepare for the assessment
For a Level 2 self-assessment, repeat your review against all 320 objectives. For a C3PAO assessment, book early. Assessors are in short supply, and Phase 2 will make them busier. Prep your people too: assessors interview staff, and "I think IT handles that" is not a great answer.

CMMC Controls by Family: The 14 Domains at a Glance
Level 2 maps directly to the 110 requirements in NIST SP 800-171 Rev 2, grouped into 14 families. Here's the short version of what each one asks for:
Access Control (22 requirements): only authorized people and devices get in, with least privilege, session limits, and controlled remote access.
Awareness and Training (3): security training for all users, plus role-based training for admins and insider threat awareness.
Audit and Accountability (9): log security events, protect the logs, review them, and tie actions to individual users.
Configuration Management (9): baseline configurations, change control, and turning off what you don't need.
Identification and Authentication (11): unique IDs, MFA for privileged and network access, and strong password rules.
Incident Response (3): a tested plan, tracking, and reporting. DFARS 7012 requires reporting cyber incidents to DoD within 72 hours.
Maintenance (6): controlled maintenance, including supervision of outside technicians and remote maintenance with MFA.
Media Protection (9): protect, mark, and sanitize media containing CUI, including USB drives.
Personnel Security (2): screen people before access and remove access when they leave.
Physical Protection (6): limit physical access, escort visitors, and keep access logs.
Risk Assessment (3): assess risk regularly and scan for vulnerabilities.
Security Assessment (4): assess your controls, fix deficiencies, and maintain the SSP.
System and Communications Protection (16): boundary protection, network segmentation, and FIPS-validated encryption for CUI.
System and Information Integrity (7): patch flaws, run malware protection, and monitor for attacks.
For Level 1, the 15 requirements come from six of these families (access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity). Think of it as basic hygiene: know who's on your network, use passwords properly, patch, run antivirus, and lock the door.

CMMC Level 1 Checklist: The 15 Basics
If you only handle FCI, this is your whole CMMC compliance checklist. Here's the plain-English version of the basic safeguarding requirements in FAR 52.204-21:
Only authorized users, processes, and devices can access your systems.
Users can only do the transactions and functions they're allowed to do.
Connections to outside systems are verified and controlled.
Information posted on public websites is controlled, so FCI doesn't end up there.
Every user, process, and device is identified.
Identities are verified (passwords, at minimum) before access is granted.
Media with FCI is sanitized or destroyed before disposal or reuse.
Physical access to systems and equipment is limited to authorized people.
Visitors are escorted and their activity is monitored.
Physical access logs are kept.
Physical access devices (keys, badges, fobs) are controlled and managed.
Communications at your network boundaries are monitored and protected, usually with a properly configured firewall.
Publicly accessible systems are separated from internal networks.
System flaws are found, reported, and fixed on time. In other words, patch.
Malware protection is in place, updated, and scanning.
That's it. Nothing exotic. Most of it is what a well-run office should already be doing. Level 1 still requires an annual self-assessment, an SPRS entry, and an annual affirmation, and no open POA&M items are allowed. It's 15 items. Get all 15.

Documentation and Evidence Checklist
Assessors don't take your word for it. They read, they interview, and they test. Here's the paperwork to have ready before anyone shows up:
System Security Plan (SSP) with a clear boundary diagram and how each requirement is met
Network diagram and data flow diagram showing where CUI goes and how it moves
Asset inventory of every in-scope device, user, and cloud service, with categories (CUI assets, security protection assets, and so on)
Policies and procedures for each of the 14 families, written for your company, not someone else's
POA&M with owners and dates for every open item
SPRS score and the date it was submitted
Training records for every user in scope
Incident response plan and records of at least one test or tabletop exercise
Access reviews showing who has access to CUI and when that was last checked
Vulnerability scan results and proof the findings were fixed
Backup and restore test records
Vendor and subcontractor list showing which ones touch FCI or CUI, and their CMMC status
Customer Responsibility Matrix from your cloud provider and your MSP, showing who does what
Rule of thumb: if a control has no evidence, assume the assessor will treat it as not met.

Your IT Provider Is Part of Your Assessment
This one catches people off guard. If an outside IT company manages your in-scope systems, their people, tools, and remote access are part of your CMMC scope. The monitoring agent, the remote support tool, the admin accounts they log in with. All of it.
So ask your provider three questions before the assessment, not during it:
Can you give us a shared responsibility matrix showing which controls you handle and which we handle?
Do your remote access tools and admin accounts use MFA and log every session?
Will you sit in on the assessment and answer questions about the controls you run?
If the answer to any of those is a long pause, you have a gap. Better to find it now than with an assessor watching.

A CMMC Certificate Is Not the Same as Being Secure
Here's my one hot take, and it comes straight from a decade of audits. A compliance badge is not the same thing as being secure. Plenty of providers will sell a contractor a policy binder, an SSP template, and a nice SPRS number, while the patching, monitoring, and tested backups behind them are thin.
The certificate satisfies the contracting officer. It doesn't stop a phishing email from walking into your engineering share. The assessment is a snapshot on one day. Attackers don't schedule around it.
The practical version: build the program so it would still work if nobody was ever going to check. Then the assessment is just a formality, and the 110 controls are actually protecting your drawings instead of decorating a binder.

Five CMMC Mistakes I See Small Contractors Make
Scoping everything. CUI is on every laptop because someone emailed a drawing once. Now the whole company is in scope. Build the enclave.
Template SSPs. The assessor asks about a control the SSP says you have, and nobody's heard of it.
Optimistic SPRS scores. A 110 on paper with MFA missing on half the accounts is a legal risk wearing a gold star.
Forgetting subcontractors. If you flow CUI down to a machine shop or a consultant, they need the right CMMC level too.
Starting in the last 90 days. Most small contractors need 12 to 18 months to be Level 2 ready. The calendar doesn't care how busy the shop floor is.
(I speak six languages and none of them has a polite word for an SSP written the night before an assessment.)

What CMMC Compliance Costs
Honestly, it varies widely with scope, which is why step 4 matters so much. The main buckets:
Gap assessment and remediation: the security work itself, often the largest cost.
Tools and licensing: MFA, EDR, logging, and possibly a government-focused cloud environment.
Documentation: SSP, policies, procedures, and evidence.
The assessment: C3PAO fees for Level 2 certification.
Ongoing work: monitoring, patching, annual affirmations, and reassessment every three years.
A small enclave with 10 users in scope costs far less than a 60-person company with CUI everywhere. Shrinking the scope is the single biggest cost lever you have.

When You Don't Need an MSP for CMMC
I'd rather be straight with you than sell you a project:
You only handle FCI. Level 1 is 15 basic requirements and an annual self-assessment. A competent in-house IT person can usually handle it with a good checklist.
You don't handle any FCI or CUI. Then CMMC doesn't apply to you. Confirm with your prime, and keep the email.
You already have a strong internal security team. You may only need a C3PAO and a readiness review.
Where we help: small and mid-sized defense contractors, manufacturers, and engineering firms that handle CUI, don't have a dedicated security team, and need the work done and kept running. Our government IT services and managed cybersecurity services pages cover how we do it. If you're a defense manufacturer, our manufacturing IT services page goes deeper on NIST 800-171 for the shop floor.

Straight Answers About CMMC Compliance
What is a CMMC compliance checklist?
It's a step-by-step list for meeting CMMC requirements: identify FCI and CUI, confirm your level, scope your systems, implement the controls, document them in an SSP, track gaps in a POA&M, score yourself in SPRS, and prepare for assessment.
How many controls are in CMMC Level 2?
Level 2 requires all 110 security requirements in NIST SP 800-171 Rev 2, organized into 14 families and assessed through 320 assessment objectives.
When is the CMMC compliance deadline?
CMMC requirements began appearing in DoD contracts on November 10, 2025. Phase 2, which adds Level 2 third-party assessments to applicable contracts, starts November 10, 2026. Your specific deadline is set by the contract you're bidding on.
How long does it take to get CMMC Level 2 ready?
Most small and mid-sized contractors need 12 to 18 months, depending on scope and how much security is already in place. Starting with a gap assessment shows you where you stand.
What happens if you fail to close POA&M items in time?
Under CMMC, open POA&M items must be closed within 180 days of conditional status. If they aren't, the conditional status expires and you're no longer eligible for contracts requiring that level.
Do subcontractors need CMMC certification?
Yes, if they handle FCI or CUI for the contract. The required level flows down with the data, so a subcontractor receiving CUI generally needs Level 2.
Can I use regular Microsoft 365 for CUI?
Usually not. DFARS 7012 expects cloud services storing CUI to meet FedRAMP Moderate or equivalent, so contractors typically use government-focused cloud environments for CUI.

Still Stuck? Give Us A Call
If you've got a DoD contract, a folder of drawings, and a sinking feeling about November 10, give us a call at 410-703-3857 or send us a note. We'll help you figure out your level, shrink your scope, and build a plan with a flat price attached.
And if it turns out you only need Level 1, I'll tell you that too. Consider it the shortest CMMC consultation you'll ever have.



Comments