CMMC readiness checklist
Use this to gauge where you stand before a formal gap assessment. It is organized the way we actually run readiness — scope first, then the controls, then the paperwork an assessor expects, then how to stay ready. It is a starting point, not a substitute for assessing every control that applies to you. When you are ready for that, see how our CMMC readiness consulting works.
1. Scope — know what you are protecting
- Identify whether you handle Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or both.
- Map where that information lives — servers, cloud apps, email, laptops, and any third parties who touch it.
- Draw your assessment boundary: what is in scope, and what you can carve out.
- Confirm the CMMC level your contracts actually require (Level 1, 2, or 3).
2. Foundational safeguards (Level 1)
- Every user and device is uniquely identified and authenticated.
- Access is limited to the people and systems that need it (least privilege).
- Antivirus / endpoint protection is deployed and kept current.
- You have a routine way to apply security patches and updates.
- Physical access to systems and media is controlled.
3. The 110 controls (Level 2 / NIST 800-171)
Level 2 means assessing all 110 NIST 800-171 controls across 14 families. The high-value areas to check first:
- Account management, least privilege, and automatic session lock are in place.
- Multi-factor authentication is enforced for remote and privileged access.
- Security events are logged — and the logs are actually reviewed, not just collected.
- CUI is encrypted at rest and in transit with FIPS-validated cryptography.
- Removable media and mobile devices are controlled or restricted.
- You have an incident-response plan, and you have tested it.
- Security awareness training is delivered and tracked.
- Configuration baselines exist and changes are managed.
- Vulnerabilities are scanned for and remediated on a schedule.
4. Documentation assessors expect
- A System Security Plan (SSP) that is written, current, and matches reality.
- A Plan of Action & Milestones (POA&M) for every unmet control, with owners and dates.
- An evidence inventory mapped to the controls it supports.
- Your SPRS score calculated and submitted in the DoD system.
5. Stay ready — continuous monitoring
- Control reviews are scheduled on a recurring basis, not one-and-done.
- Logs and alerts are reviewed by a named person.
- Your change process keeps the SSP current as systems evolve.
- You have a plan for annual affirmation and reassessment.
Checked some boxes and not others? That gap is exactly what we close.
Book a free readiness call