CMMC 2.0 COMPLIANCE CHECKLIST
CMMC 2.0 compliance checklist : Most CMMC compliance guides read like a copy of the NIST 800-171 control catalog with a company logo pasted on top. That’s not a checklist — it’s a reference document, and reference documents don’t tell you what to do Monday morning. This guide is built the other way around: it starts from the eight things you actually have to do, in order, to go from “we sell to the DoD” to “we’re MET in SPRS,” and fills in the detail — scope, documentation, cost, timeline — at each step along the way.
Quick Answer
Who needs it: any contractor or subcontractor that creates, receives, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for a DoD contract.
The core documents: a System Security Plan (SSP) describing how every required control is implemented, and — where gaps remain — a Plan of Action and Milestones (POA&M) with dated remediation targets.
The finish line: a MET score submitted to the Supplier Performance Risk System (SPRS), plus an annual executive affirmation, or a C3PAO certification where the contract requires one.
CMMC Compliance at a Glance
| Level 1 (Foundational) | Level 2 (Advanced) | |
|---|---|---|
| Applies if you handle | FCI only | CUI |
| Requirements to meet | 15 practices | 110 practices across 14 domains |
| Core documents needed | Basic policies, informal evidence | SSP + POA&M, formal policy per domain |
| Verification | Annual self-assessment | Self-assessment or C3PAO, per contract |
| Realistic runway | 4–8 weeks for a small business | 6–18 months |
Step 1: Determine the Level Your Contract Requires
Before any technical work starts, find the answer in your paperwork, not your assumptions. DFARS clause 252.204-7021 and the specific solicitation or contract will name the required CMMC level and, for Level 2, whether a self-assessment or a C3PAO certification applies. If you’re a subcontractor, check with your prime as well — CMMC requirements flow down the supply chain, and a prime’s Level 2 (C3PAO) status often obligates every CUI-handling subcontractor beneath it to match.
Step 2: Define Your Assessment Scope
Scope is where most budgets are won or lost. The CMMC Assessment Scope is the set of assets that process, store, or transmit FCI or CUI, plus the security tools that protect them — not your entire company network by default. A common and effective approach is building a CUI enclave: a deliberately separated, tightly controlled segment of your environment that isolates CUI-handling systems from the rest of the business, so departments that never touch government data don’t get pulled into the assessment boundary.
The Enclave Shortcut
Building a CUI enclave — a locked-down subset of your network dedicated to CUI work — is the single most common way small and mid-sized contractors keep Level 2 costs proportional.
Instead of bringing every laptop, file share, and legacy system into scope, only the enclave and the people who work inside it need to meet the full control set.
The trade-off is discipline: data has to actually stay inside the enclave, or the boundary you documented stops matching reality.
Step 3: Run a Gap Assessment
With scope defined, compare what you actually do today against the 15 (Level 1) or 110 (Level 2) required practices, and be specific about evidence — a policy that exists only as an unwritten habit won’t hold up in an assessment. Most organizations find gaps clustered in the same handful of areas: multi-factor authentication applied inconsistently across systems, audit logs that exist but aren’t reviewed, and incident response plans that were written once and never tested.
Step 4: Write the System Security Plan (SSP)
The SSP is the document an assessor — or your own future self — reads first. It describes your assessment boundary, every system inside it, and exactly how each required control is implemented: which tool enforces it, who owns it, and how it’s verified. For Level 2 in particular, a thin or generic SSP is one of the most common reasons organizations fail an assessment even when the underlying technical controls are reasonably solid — the documentation itself is graded, not just the technology.
Step 5: Remediate Gaps and Build a POA&M
Close what you can close now. For anything that can’t be resolved immediately, Level 2 allows a limited Plan of Action and Milestones — but only for certain lower-weighted requirements, and only with a hard 180-day closeout window; some higher-priority controls must be fully implemented before an assessment can even begin. Level 1 allows no POA&M at all: every one of the 15 requirements must be fully met.
SSP + POA&M: The Two Documents Everything Hinges On
The SSP is your factual record: what’s in scope, and how each control is actually implemented today.
The POA&M is your honesty record: what isn’t done yet, who owns fixing it, and by when.
Assessors — and increasingly contracting officers reviewing SPRS scores — read these two documents as a pair. A polished SSP next to an empty or vague POA&M reads as incomplete, not as “fully compliant.”
Step 6: Train Your Workforce
Security awareness training isn’t a side item — it’s itself a required, assessed practice under the Awareness and Training domain. Everyone with access to FCI or CUI needs role-appropriate training on recognizing threats and following your documented security procedures, refreshed on a regular cycle and with attendance evidence kept on file.
Step 7: Self-Assess or Schedule Your C3PAO
For Level 1 and self-assessed Level 2 contracts, this is an internal exercise: score yourself against every requirement, using the assessment objectives in NIST SP 800-171A as your rubric. For Level 2 (C3PAO) contracts, this step means booking an accredited Certified Third-Party Assessment Organization — and booking early, since the assessor pool is still growing relative to demand and lead times can stretch for months.
Step 8: Submit Your Score and Affirm in SPRS
Whichever path you took, the finish line is the same: report your score in the Supplier Performance Risk System, sign the annual executive affirmation confirming continued compliance, and calendar your next reassessment — annually for self-assessments, every three years for C3PAO certifications, with an affirmation due in the interim years either way.
Budget and Timeline by Path
| Typical Cost | Typical Timeline | |
|---|---|---|
| Level 1 (Self) | Largely internal effort; low direct cost | 4–8 weeks |
| Level 2 (Self) | $15,000–$40,000 in gap remediation and documentation | 4–9 months |
| Level 2 (C3PAO) | $20,000–$100,000+ depending on scope and maturity | 6–18 months |
Common Mistakes to Avoid
- Scoping the assessment boundary too broadly, pulling in systems that never touch FCI or CUI and inflating both cost and assessment time.
- Treating the SSP as a one-time deliverable instead of a living document that needs updating whenever systems or vendors change.
- Waiting until a contract deadline is close to book a C3PAO — availability is limited, and rushed scheduling rarely goes smoothly.
- Assuming cloud tools are automatically compliant without confirming they meet FedRAMP-equivalent standards for handling CUI.
- Leaving security awareness training as an afterthought — it’s a scored practice, not a formality.
Why Getting This Right Matters
Contracting officers check SPRS before award, and a missing, expired, or mismatched CMMC status can remove a business from consideration entirely — not just delay the decision. At the same time, over-scoping a Level 2 assessment against systems that never touch CUI wastes budget that could go toward the work itself. A disciplined, well-scoped checklist keeps both risks in check: it protects contract eligibility without turning compliance into a bigger project than it needs to be.
How B4Q Assurance Helps
B4Q Assurance works with defense contractors and subcontractors through every step in this checklist — scoping the assessment boundary, running the gap assessment, writing the SSP and POA&M, closing technical gaps, and preparing for a self-assessment or C3PAO certification — so contract eligibility is backed by evidence, not guesswork.
Resources
FAQs
Do we need a C3PAO if we're not sure our data counts as CUI?
Not yet — first confirm the classification. A documented data-flow review, ideally done with your contracting officer or prime, should settle whether you’re handling FCI, CUI, or both before you commit to a C3PAO engagement.
Can a small business realistically afford Level 2?
Yes, especially with a tightly scoped enclave — self-assessed Level 2 for a small business with a well-defined boundary often lands well under the higher end of typical ranges. Scope discipline matters more than company size.
How often does the SSP need to be updated?
Whenever your environment changes in a way that affects the assessment boundary — a new system, a new vendor, a cloud migration — and at minimum, reviewed annually alongside your affirmation.
How often does the SSP need to be updated?
Whenever your environment changes in a way that affects the assessment boundary — a new system, a new vendor, a cloud migration — and at minimum, reviewed annually alongside your affirmation.
What's the single most common reason organizations fail a Level 2 assessment?
Inconsistent multi-factor authentication coverage and thin SSP documentation are the two most frequently cited gaps — not necessarily missing technology, but missing evidence that the technology is applied everywhere it needs to be.