CMMC readiness checklist

Use this to gauge where you stand before a formal gap assessment. It is organized the way we actually run readiness — scope first, then the controls, then the paperwork an assessor expects, then how to stay ready. It is a starting point, not a substitute for assessing every control that applies to you. When you are ready for that, see how our CMMC readiness consulting works.

1. Scope — know what you are protecting

2. Foundational safeguards (Level 1)

3. The 110 controls (Level 2 / NIST 800-171)

Level 2 means assessing all 110 NIST 800-171 controls across 14 families. The high-value areas to check first:

4. Documentation assessors expect

5. Stay ready — continuous monitoring

Checked some boxes and not others? That gap is exactly what we close.

Book a free readiness call