CMMC Readiness Checklist
A 43-point CMMC 2.0 readiness checklist.
Mapped to NIST 800-171 control families, written for medium and large Pacific defense subcontractors. Use it as a self-assessment, a remediation roadmap, or a conversation starter with your prime.
Free download
Get the checklist as a PDF
We’ll email a formatted PDF you can print, share with your IT lead, or drop into your POA&M workflow. The full checklist is also below on this page.
How to use this
Walk this list with your IT lead. For each item, mark In place / Partial / Gap. Anything not "In place" goes onto the POA&M with an owner, a target date, and a budget estimate. Most organizations tackling this for the first time find a meaningful share of the 43 items partial or missing, that's the point of a gap analysis, not a red flag. The 9–12 month remediation runway below exists to close what's open.
Scope & Boundary
- CUI boundary diagrammed and approved by leadership
- In-scope users, systems, and data flows inventoried
- Federal Contract Information (FCI) vs CUI classification confirmed
- GCC High (or equivalent FedRAMP-Mod) tenant in place for CUI in M365
- Network segmentation between CUI enclave and general business systems
Access Control (AC)
- Multi-factor authentication on all CUI-adjacent accounts
- Conditional Access policies enforce device + location restrictions
- Privileged Identity Management (PIM) for admin roles
- Quarterly user access review documented
- Session controls and automatic logoff configured
Audit & Accountability (AU)
- Centralized SIEM with all CUI system logs ingested
- Audit log retention of at least 1 year (longer where contract requires)
- Audit failure alerting configured and tested
- Time synchronization (NTP) hardened across all systems
- Audit record review on a documented cadence
Identification & Authentication (IA)
- No shared accounts in the CUI environment
- Password complexity + history + lockout policies enforced
- Service accounts managed under PIM or equivalent
- PIV / smartcard / FIDO2 support where DoW contract requires
Incident Response (IR)
- Written incident response plan, signed by leadership
- Annual tabletop exercise completed and documented
- 72-hour DFARS 252.204-7012 reporting workflow operational
- IR retainer or in-house IR capability in place
- Post-incident review process with corrective action tracking
System & Information Integrity (SI)
- Endpoint detection and response (EDR) on all CUI-handling endpoints
- Continuous vulnerability scanning with prioritized remediation
- Malware protection updated and centrally monitored
- System monitoring for unauthorized changes
- Flaw remediation tracked through ticketing with SLAs
Configuration Management (CM)
- Documented baseline configurations for all CUI systems
- Change management process with approvals and rollback
- Asset inventory current and reconciled to scans
- Software whitelisting / allowlisting where feasible
Personnel & Physical (PE / PS)
- US-persons access controls documented in personnel handling section
- Background checks for personnel with CUI access
- Physical access controls to CUI-processing facilities
- Visitor logs and escort procedures
- Media handling and sanitization procedures
Documentation & Governance
- System Security Plan (SSP) authored and current
- Plan of Action & Milestones (POA&M) live and reviewed quarterly
- Annual NIST 800-171 self-assessment scored in SPRS
- Evidence library organized and assessor-ready
- C3PAO mock assessment completed
Sources & further reading
This checklist maps to the 110 security requirements in NIST SP 800-171 Revision 2, the control baseline referenced by the DoD’s CMMC 2.0 program and by DFARS 252.204-7012, the clause that requires safeguarding covered defense information and 72-hour cyber incident reporting. For the official alignment between the two frameworks, see the DoD’s CMMC-to-NIST alignment guide.
Frequently asked questions
How many controls does CMMC Level 2 actually require?
CMMC Level 2 requires all 110 security requirements from NIST SP 800-171 Revision 2, organized into 14 control families. This 43-point checklist groups those requirements into practical, checkable categories for a faster self-assessment; it complements, but doesn't replace, the full NIST SP 800-171 control set your System Security Plan has to address.
What's the difference between FCI and CUI?
Federal Contract Information (FCI) is government-provided or government-generated information not intended for public release; it triggers the 15 basic safeguarding requirements in FAR 52.204-21 and CMMC Level 1. Controlled Unclassified Information (CUI) is more sensitive and requires the full 110-control NIST SP 800-171 baseline and CMMC Level 2. Most defense subcontractors handle both, which is why scoping the CUI boundary correctly is the first item on this checklist.
Do I need GCC High for CMMC 2.0?
Not always. DoD guidance allows a FedRAMP Moderate (or higher) equivalent cloud environment for CUI, and GCC High is Microsoft's common option for meeting that bar. Whether you specifically need it depends on your CUI data flows, your prime's flow-down requirements, and whether commercial Microsoft 365 with compensating controls can meet your scope instead.
What is a POA&M and how long can I keep one open?
A Plan of Action and Milestones (POA&M) documents security requirements you haven't fully implemented, with an owner, a remediation date, and required resources. Under the CMMC 2.0 final rule (32 CFR Part 170.21), only lower-weighted, 1-point requirements are generally POA&M-eligible, several CUI-critical controls can never be deferred, and open items must be closed within 180 days of your Conditional CMMC Status Date or your certification lapses.
How long does CMMC remediation typically take?
For a mid-market subcontractor with meaningful gaps, 9–12 months is a realistic runway from initial gap assessment through remediation, System Security Plan documentation, and a mock assessment. Timelines shrink for organizations with mature IT operations already in place and expand for those still building basic asset inventory and access control.
Do I need a C3PAO assessment, or can I self-assess?
It depends on your specific contracts. Under CMMC 2.0, many organizations handling CUI can self-assess for Level 2, while contracts involving the most critical information require a third-party assessment from a Certified Third-Party Assessment Organization (C3PAO), and select higher-risk programs add further government oversight. Your contracting officer or prime can confirm which tier your specific contract requires.
Aloha, let's talk
Want this as a working POA&M instead of a checklist?
A 30-minute scoping call gives you a fixed-scope CMMC plan, every gap with an owner, a date, and a remediation cost.
Further reading
Analysis from the team that runs the SOC.