Built exclusively from official .gov sources · 32 CFR Part 170 · FAR 52.204-21 · NIST SP 800-171 Rev 2

CMMC Compliance Checklist:
Level 1 & Level 2, From Scratch

A step-by-step working checklist for achieving Cybersecurity Maturity Model Certification (CMMC) Level 1, then Level 2.

Level 1 · 15 reqs
0 / 15 met
Level 2 · 110 reqs
0 / 110 met
Process steps
0 / 0 done
Level 10%
Level 20%
PHASE 1

Understand what CMMC is and which level you need

Goal: before touching any technology, understand the program, the two kinds of protected information, and how your DoD contracts determine which level applies to you. Check off each step as you complete it.

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) Program is the Department's mechanism to verify that defense contractors and subcontractors actually implement the cybersecurity safeguards they were already required to have. It is codified in 32 CFR Part 170 and enforced through contracts: contractors entrusted with FCI or CUI must achieve a specific CMMC level as a condition of contract award. The program is tiered — Level 1 protects FCI, Level 2 protects CUI — and results are recorded in the DoD's Supplier Performance Risk System (SPRS).

Current implementation status: Phase 1 of CMMC began on November 10, 2025. On July 13, 2026, DoD suspended Phase II and paused the program in Phase 1, during which the Department enforces cybersecurity compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments. Level 1 and Level 2 may currently be satisfied by self-assessment. The suspension does not eliminate your obligation to protect covered information under DFARS 252.204-7012.

FCI — Federal Contract Information

Defined in FAR 4.1901: information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service — excluding information the Government releases publicly and simple transactional information (like payment processing data). If you hold any DoD contract, you almost certainly handle FCI. FCI is what Level 1 protects.

CUI — Controlled Unclassified Information

Defined in 32 CFR 2002.4(h): information the Government creates or possesses (or that an entity creates/possesses for the Government) that a law, regulation, or Government-wide policy requires or permits an agency to safeguard with dissemination controls. Examples in defense work include controlled technical information and export-controlled data. See the DoD CUI Registry for categories. CUI is what Level 2 protects.

How the two levels compare (from 32 CFR Part 170, summarized on the DoD CIO "About CMMC" page)

  • Level 1 (Self): 15 security requirements from FAR clause 52.204-21 · annual self-assessment · results entered into SPRS · affirmation after each assessment · POA&Ms (remediation plans) are not permitted — every requirement must be MET or Not Applicable.
  • Level 2 (Self): 110 security requirements from NIST SP 800-171 Rev 2 (required by DFARS 252.204-7012) · self-assessment every 3 years · results entered into SPRS · affirmation after each assessment and annually thereafter (status lapses if you fail to affirm) · limited POA&Ms permitted per 32 CFR 170.21(a)(2), which must be closed out within 180 days.
  • Level 2 (C3PAO): the same 110 requirements, but verified by a Certified Third-Party Assessment Organization when a contract requires certification rather than self-assessment. With Phase II suspended, broad rollout of this requirement is paused — but the assessment ecosystem exists and some contracts may still specify it.
PHASE 2

Lay the foundation: accounts, scope, and inventory

Goal: get the administrative machinery in place (SAM, PIEE, SPRS access), figure out exactly where FCI lives in your environment, and define your CMMC Assessment Scope. Scoping decisions made here determine how big — or how small — your compliance effort has to be.

Why scope matters more than anything else

Per 32 CFR 170.19 and the CMMC Level 1 Scoping Guide, the assets that process, store, or transmit FCI are in scope for a Level 1 self-assessment. Requirements may apply to your entire network or only to a particular enclave, depending on where FCI actually goes. A small, well-isolated enclave (a dedicated network segment, or a separate cloud environment) can dramatically shrink the number of systems you must secure and assess. The same logic applies at Level 2 for CUI, with a more detailed asset-categorization model in the Level 2 Scoping Guide.

PHASE 3

Implement the 15 Level 1 requirements

Goal: implement the 15 basic safeguarding requirements of FAR clause 52.204-21(b)(1) across every in-scope asset. Each card below shows the requirement exactly as stated in the CMMC Assessment Guide — Level 1 (v2.13, DoD-CIO-00002), a plain-language explanation, and the official assessment objectives you must satisfy. A requirement is only MET when all of its applicable objectives are satisfied with final (not draft) evidence. Check the box once the requirement is fully implemented and you can prove it.

Good practice while you implement

A System Security Plan (SSP) is not required for Level 1, but the Level 1 Assessment Guide recommends developing one as a best practice — and you will need one for Level 2 anyway (requirement CA.L2-3.12.4). Document as you go: final policies, configurations, and records are your assessment evidence.

PHASE 4

Level 1 self-assessment, SPRS submission & affirmation

Goal: formally self-assess against the objectives in NIST SP 800-171A (with "FCI" substituted for "CUI"), record the result in SPRS, and have your senior official affirm compliance. This is what produces the CMMC Status of Final Level 1 (Self) under 32 CFR 170.15.

How findings work (32 CFR 170.24 / Level 1 Assessment Guide)

  • Each requirement is scored MET, NOT MET, or NOT APPLICABLE. To demonstrate Level 1 compliance, every requirement must be MET or N/A.
  • Assessment is done at the objective level: one NOT MET objective fails the entire requirement.
  • Evidence must be in final form — drafts, working papers, and unapproved policies don't count.
  • Assessment methods are examine (documents, configs, mechanisms), interview (staff), and test (demonstrate it working). You choose the mix that gives sufficient confidence.
  • No POA&Ms at Level 1. If anything is NOT MET, fix it, then assess again.
  • A requirement can be satisfied by an External Service Provider (e.g., MSP, cloud provider) if you have adequate evidence they implement the objectives.
PHASE 5

Prepare for Level 2: CUI scope, SSP, and gap analysis

Goal: Level 2 protects CUI against all 110 requirements of NIST SP 800-171 Rev 2. Before implementing, you need to know exactly what CUI you handle, scope and categorize your assets per the Level 2 Scoping Guide, write your System Security Plan, and measure your starting gap. Note: if any current contract already carries DFARS 252.204-7012, you are already contractually required to implement NIST SP 800-171 — CMMC Level 2 is the verification layer on top.

Level 2 asset categories (CMMC Level 2 Scoping Guide, summarized)

  • CUI Assets — process, store, or transmit CUI. Fully assessed against all applicable requirements.
  • Security Protection Assets — provide security functions to the scope (e.g., your SIEM, firewall management, identity provider). In scope and assessed for relevant capabilities.
  • Contractor Risk Managed Assets — can, but are not intended to, handle CUI because of how you've policed them. Documented in the SSP; not assessed against every requirement if properly separated.
  • Specialized Assets — IoT, OT, test equipment, government-furnished equipment. Documented in the SSP and managed via your risk-based policies.
  • Out-of-Scope Assets — cannot handle CUI (physically or logically separated). No assessment requirement.

Read the actual scoping guide before finalizing anything — separation technique (physical or logical, e.g., VLANs, firewalls) is what keeps assets out of scope.

PHASE 6

Implement the 110 Level 2 requirements

Goal: implement all 110 security requirements of NIST SP 800-171 Rev 2 across your CUI scope, organized into 14 families (domains). Each card shows the CMMC requirement ID and short name from the CMMC Assessment Guide — Level 2 (v2.13, DoD-CIO-00003), the requirement statement from NIST SP 800-171 Rev 2, and a plain-language explanation. The 15 Level 1 requirements you already implemented map directly onto Level 2 counterparts (marked below), so your Level 1 work carries forward — but at Level 2 the same practices must now cover CUI, not just FCI. Assessment objectives for every requirement are in NIST SP 800-171A and the Level 2 Assessment Guide.

PHASE 7

Level 2 self-assessment, SPRS, POA&M rules & affirmation

Goal: conduct the Level 2 self-assessment under 32 CFR 170.16 using the NIST SP 800-171A objectives, submit results to SPRS, close any permitted POA&M within 180 days, and affirm. This produces a CMMC Status of Conditional or Final Level 2 (Self), valid for three years from the status date.

POA&M rules at Level 2 (32 CFR 170.21)

Unlike Level 1, a limited Plan of Action & Milestones is permitted after a Level 2 assessment — but only within strict boundaries set by 32 CFR 170.21(a)(2): your assessment score must meet the regulatory minimum (at least 80% of the 110-point maximum under the 32 CFR 170.24 scoring methodology), and only certain lower-weighted requirements are POA&M-eligible; the regulation enumerates specific requirements that may never be on a POA&M. A POA&M gives you Conditional Level 2 (Self); you must pass a POA&M closeout self-assessment within 180 days to reach Final Level 2 (Self), or the conditional status expires. Read § 170.21 itself before relying on a POA&M — this is the one area where getting the details wrong voids your status.

PHASE 8

Maintain compliance year over year

Goal: compliance is continuous, not a one-time event. Statuses lapse without annual affirmations, environments drift, and DFARS 252.204-7012 obligations (like 72-hour cyber incident reporting) apply all the time.

REFS

Official sources (all .gov)

Everything on this page is derived from the documents below. Where this page and an official document ever disagree, the official document governs — regulations and guides are updated over time, so verify against the current versions.