CMMC compliance checklist: how to use these 32 checkpoints
Use this readiness checklist to organize the work before a CMMC Level 2 assessment: confirm the requirement, define the scope, assign evidence owners, close gaps, complete the appropriate assessment and reporting steps, and maintain the result.
These are 32 planning checkpoints, not 32 official controls. CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The checklist helps organize that work; completing it does not certify your company or replace the requirement-by-requirement assessment. Source: 32 CFR § 170.14.
The emailed download is the 32-point Level 2 readiness checklist PDF. It is not a 110-row spreadsheet, an automated scoring tool, or an assessment certificate. You can read the guidance below without submitting an email address. For the individual requirement identifiers, use our NIST SP 800-171 Revision 2 requirements reference.
How to work through it: keep your working records in an approved environment. For each checkpoint, assign an owner, record the next action, identify the evidence, and set an internal review date. The suggested outputs below are editorial planning aids; the applicable requirements and assessment objectives determine what your assessment needs.
Which checklist do you need?
| Your situation | Use this resource |
|---|---|
| You are preparing for CMMC Level 2 and need an ordered readiness workflow | Stay on this page. |
| Your work involves FCI only and your applicable requirement is Level 1 | Use the Level 1 self-assessment checklist. |
| You need the individual Revision 2 requirements | Use the NIST 800-171 requirements reference. |
| You need a document and evidence inventory | Use the Level 2 documentation checklist. |
| You need to understand the assessment process and reporting path | Use the Level 2 assessment guide. |
Confirm the actual solicitation, contract, and flow-down requirements before treating any checklist as applicable. Level 1 and Level 2 are different scopes of work; this PDF is not an all-level checklist. Source: CMMC Model.
Current implementation note — reviewed September 28, 2026
The Department announced the suspension of CMMC Phase II implementation on July 13, 2026; Phase I self-assessment requirements remain in place. The current official program guidance continues to identify NIST SP 800-171 Revision 2 as the Level 2 baseline. A change to rollout timing is not permission to stop protecting contract information or ignore applicable obligations. Check the official CMMC program notice and our current deadlines and implementation tracker before relying on a schedule.
This page does not give you a new assessment deadline. Build milestones from your actual obligation and starting point, not from old quarter-by-quarter targets.
1. Contract, Data, and Accountability
1. Build a contract and clause applicability register
Record the applicable solicitation, contract, subcontract, amendments, required CMMC status, and responsible contact in your own controlled records. Separate a requirement to safeguard information from a requirement to hold a particular assessment status. When wording conflicts with current implementation guidance, obtain clarification through the appropriate contracting channel instead of treating a general checklist as permission to ignore it.
Suggested evidence or output: An applicability register with the requirement, scope, source, owner, and unresolved questions.
2. Determine exactly what is FCI, CUI, and covered defense information
Confirm which information your organization receives or creates for the work, how it is designated, and which handling requirements apply. A contract with a federal customer does not make every business file CUI. Equally, a missing label is not a safe basis for dismissing a possible safeguarding obligation. Resolve ambiguous information categories with the customer or prime before selecting an architecture.
Suggested evidence or output: A documented information determination and a named route for classification questions.
3. Map the complete CUI lifecycle and business workflows
Follow a representative workflow from receipt through use, sharing, storage, backup, archiving, and disposal. Include ordinary workarounds: printing, remote access, collaboration tools, engineering files, and support tickets. Keep real diagrams, customer details, and controlled files in your approved environment; this website does not need them.
Suggested evidence or output: A CUI data-flow record that reflects how people actually work.
4. Name accountable leaders and the affirming official
Assign responsibility for scope, technology, evidence, remediation, and management decisions. Identify the senior representative who has authority to affirm compliance and make sure that person can review the underlying evidence. A consultant or software subscription does not take over the organization’s responsibility for its representations.
Suggested evidence or output: An ownership list and a management review process, including the affirming official.
Source framework: CMMC Model and affirmation requirements. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
2. Assessment Scope and Architecture
5. Define the OSA and each distinct CMMC assessment scope
Identify the Organization Seeking Assessment and the information systems included in each proposed assessment scope. Record the associated business units and CAGE codes where applicable. A boundary should follow the systems and workflows being assessed, not simply the company name on a sales proposal.
Suggested evidence or output: A scope statement that can be reconciled with the asset inventory, SSP, and relevant records.
6. Categorize every relevant asset using the Level 2 scoping model
Use the five Level 2 categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Their assessment treatment is not identical. Classify security tools by their actual function and data handling; processing Security Protection Data alone does not automatically make a tool a CUI Asset.
Suggested evidence or output: An inventory with an asset category, rationale, owner, and relevant service dependencies.
7. Maintain current boundary, network, and CUI data-flow diagrams
Make the diagrams, inventory, and SSP describe the same environment. Show relevant connections, cloud services, remote access, security services, and separation from excluded systems. Where a single diagram serves several purposes, check that it still makes the assessment boundary and CUI flows understandable.
Suggested evidence or output: Version-controlled diagrams consistent with the current inventory and SSP.
8. Validate the boundary against shadow CUI and real user behavior
Test assumptions about where users can copy, print, download, or forward controlled information. Examine backup destinations and administrative access as well as the primary application. A network diagram is not sufficient evidence of separation when normal workflows cross the proposed boundary.
Suggested evidence or output: A documented boundary review, including exceptions and corrective actions.
Source framework: Level 2 scoping requirements. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
3. SSP, Objectives, Evidence, and Gaps
9. Maintain a current, approved, system-specific SSP
Describe the system boundary, operating environment, connections, and how the applicable security requirements are implemented. Replace generic template assertions with descriptions of the actual environment. Keep the SSP current as systems and responsibilities change. The SSP requirement cannot be deferred on a Conditional Level 2 POA&M.
Suggested evidence or output: A controlled SSP that agrees with the environment and points to supporting records.
10. Map all 110 requirements to every applicable assessment objective
Use the Revision 2 requirement identifiers and the applicable assessment procedures. Assign evidence and an owner to each applicable objective rather than treating a policy title as proof of an entire family. Our separate NIST requirement reference supplies the requirement-by-requirement lookup; this 32-point workflow organizes the work around it.
Suggested evidence or output: A requirement/objective register with evidence references, owners, findings, and review dates.
11. Reconcile policies, procedures, configurations, tickets, and interviews
Check that the written process, technical settings, operating records, and responsible person describe the same practice. A signed policy that is not followed and a configured tool that no one operates leave different gaps. Use evidence from the relevant scope, not an unrelated business unit or demonstration tenant.
Suggested evidence or output: A traceable evidence record with discrepancies assigned for resolution.
12. Score gaps correctly and separate remediation from allowable CMMC POA&Ms
Keep the full remediation backlog separate from the narrow set of findings permitted on a Conditional CMMC POA&M. Record findings and apply the current scoring method; do not invent partial credit for a nearly completed task. The scoring rule contains limited partial-implementation cases, so use its actual provisions rather than a blanket shortcut.
Suggested evidence or output: A defensible assessment record and a separately checked conditional-status eligibility review.
Source framework: NIST SP 800-171 Rev. 2 and CMMC findings and scoring. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
4. Identity, Access, Configuration, and Cryptography
13. Control the full identity and account lifecycle
Connect account creation, approval, privilege changes, reviews, and removal to real ownership. Include service accounts, administrators, temporary access, and external support. Check that a person leaving a role loses access through all relevant systems rather than only the primary email account.
Suggested evidence or output: Access authorizations, account inventories, role reviews, and removal records.
14. Implement and test MFA on the exact required access paths
Map the privileged, non-privileged, network, remote, and maintenance access paths to the applicable requirements. Do not equate MFA on email with MFA everywhere it is required. Verify enforcement on the actual paths and account types, including exceptions, rather than relying only on a product’s advertised capability.
Suggested evidence or output: An access-path matrix, configuration evidence, and relevant enforcement test results.
15. Establish secure configurations, change control, and least functionality
Define approved configurations and control changes to them. Review installed software, unnecessary functions, ports, protocols, and services against the system’s needs. Keep a record of approvals and security-impact reviews so the configuration can be explained and maintained after the initial implementation project.
Suggested evidence or output: Baselines, configuration records, change approvals, and exception reviews.
16. Protect CUI in transit and at rest with validated cryptography where required
Identify where cryptography is used to protect CUI and check the applicable requirements for those uses. Verify the cryptographic module, version, operating mode, and validation evidence where FIPS validation is required. A familiar encryption algorithm or a general vendor claim is not the same as evidence for the deployed configuration.
Suggested evidence or output: A cryptography inventory tied to CUI flows, configurations, and applicable validation records.
Source framework: NIST SP 800-171 Rev. 2, families 3.1, 3.4, 3.5 and 3.13. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
5. Monitoring, Vulnerability, Incident, and Recovery
17. Generate, protect, review, and act on security logs
Identify the required log sources, protect the records, establish accountability for review, and show what happens when a relevant event is found. Collecting logs without review or follow-up does not demonstrate the whole operating process. Match the evidence to the systems inside your scope.
Suggested evidence or output: Logging configurations, protected records, review evidence, and follow-up tickets.
18. Operate vulnerability, flaw remediation, patching, and malicious-code defenses
Connect scanning and alerts to triage, corrective work, verification, and exception handling. Record how the organization determines priorities and timing under its applicable requirements and risk. A dashboard showing installed agents does not, by itself, establish that flaws and alerts are being addressed.
Suggested evidence or output: Scan results, remediation tickets, patch records, and evidence of review and closure.
19. Make cyber incident response and DFARS reporting executable
Assign incident roles, escalation paths, contact methods, and reporting responsibilities. Test the incident-handling capability and reconcile it with applicable contractual reporting duties. For incidents covered by DFARS 252.204-7012, the clause requires rapid reporting within 72 hours of discovery; confirm applicability and follow the official reporting process.
Suggested evidence or output: An incident response plan, test records, current contacts, and a contractual reporting checklist.
20. Protect backup CUI and prove recoverability
Include backup copies in your CUI handling and service review. Check who can access them, where they are stored, and how confidentiality is protected. A restore exercise is a useful operational readiness check; do not mislabel a particular exercise frequency as a universal CMMC requirement when the cited control does not prescribe it.
Suggested evidence or output: Backup protection records and relevant recovery test results retained in the approved environment.
Source framework: NIST SP 800-171 Rev. 2, families 3.3, 3.6, 3.8, 3.11 and 3.14 and DFARS 252.204-7012. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
6. Physical, Media, Personnel, and Maintenance
21. Control physical access to systems, facilities, and CUI
Identify protected locations, authorize access, and keep the relevant visitor and physical-access records. Include alternate work locations where applicable. Check the actual practices for visitors, escorting, and access management rather than assuming a locked office resolves the entire physical protection family.
Suggested evidence or output: Physical access authorizations, visitor records, and applicable location procedures.
22. Control the full lifecycle of paper and digital media
Account for storage, access, marking, transport, use, sanitization, and disposal of media containing CUI. Include printed material and removable storage, not only the main file server. Match disposal and sanitization evidence to the media and information involved.
Suggested evidence or output: Media-handling procedures, inventories where used, transfer records, and sanitization or disposal records.
23. Integrate personnel screening, onboarding, training, transfer, and termination
Connect personnel actions to the relevant access and awareness processes. Confirm that people with security duties understand their roles and that training records match the workforce in scope. Review transfers as well as departures: an employee can remain with the company while no longer needing the same access.
Suggested evidence or output: Applicable screening records, training evidence, and access-change or termination tickets.
24. Control maintenance personnel, tools, media, and remote sessions
Account for on-site and remote maintenance, including external technicians and the equipment or media they introduce. Verify the required authorization, supervision, authentication, and session termination practices. A maintenance vendor’s general security statement is not evidence that a particular session was controlled.
Suggested evidence or output: Maintenance authorizations, relevant logs, and records of tools, media, and remote access controls.
Source framework: NIST SP 800-171 Rev. 2, families 3.2 and 3.7–3.10. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
7. Cloud, ESPs, External Connections, and Supply Chain
25. Verify the exact cloud service offering used to handle CUI
Identify the specific service, offering, and configuration—not just the cloud provider’s brand. Apply the relevant FedRAMP authorization or equivalency requirements for a cloud service processing, storing, or transmitting CUI, and document your own responsibilities. Buying a government-branded environment does not establish your organization’s CMMC status.
Suggested evidence or output: Offering-specific evidence and a documented customer/provider responsibility split.
26. Scope MSPs, MSSPs, SOCs, and other external service providers correctly
Identify the services supplied, the data they handle, and the security functions they perform. Use the applicable CMMC scoping and external-service-provider rules instead of assuming every provider must follow the same assessment path. Reconcile the Customer Responsibility Matrix, service descriptions, and your SSP.
Suggested evidence or output: A service inventory and responsibility matrix with evidence access and ownership defined.
27. Authorize and control external, remote, mobile, wireless, and collaboration paths
Review approved connections and ways of accessing or sharing CUI, including remote work and mobile devices. Confirm that actual use matches the authorized configuration and information flow. Pay particular attention to convenience tools adopted outside the documented process.
Suggested evidence or output: Connection approvals, relevant configurations, and a review of information-sharing workflows.
28. Flow requirements to subcontractors based on the information they receive
Identify which subcontractors receive FCI or CUI and which contractual flow-down requirements apply. Verify the required status and scope through the appropriate process; do not treat a public marketing badge as a substitute. Keep controlled subcontract information out of public matching and newsletter forms.
Suggested evidence or output: A subcontractor applicability record, required clauses, and the relevant verification evidence.
Source framework: CMMC scope and external services and flow-down requirements. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
8. Assessment Execution, SPRS, and Continuous Compliance
29. Build an objective-level evidence repository that can survive scrutiny
Organize evidence so a reviewer can connect an objective to a final artifact, its owner, the system it covers, and its date. Control access to sensitive records. Use references and artifact identifiers rather than copying confidential security information into general-purpose tools or this website.
Suggested evidence or output: A protected evidence index with access controls and an update process.
30. Run a true mock assessment using examine, interview, and test
Use a practice review to test whether the evidence and responsible staff can support the findings. A mock assessment is an editorial readiness recommendation, not a separate certification requirement. It should expose unsupported assertions before the formal self-assessment or applicable certification assessment, not manufacture a passing score.
Suggested evidence or output: A practice-review record with gaps, owners, and corrective actions.
31. Make SPRS records, CAGE mappings, scores, status, and UIDs accurate
Identify the specific record your requirement calls for. A NIST SP 800-171 DoD Assessment record and a CMMC status record are not interchangeable simply because both use SPRS. Enter the required fields for the applicable process and reconcile the scope and associated identifiers with your evidence. Do not upload an entire SSP merely because a general article says to.
Suggested evidence or output: The appropriate submission record and a documented reconciliation with the assessed scope.
32. Sustain annual affirmation and material-change governance
Assign an owner for the required affirmation and reassessment calendar. Review changes that could affect the scope, implementation, or supporting evidence. Apply the record-retention rules to the artifacts they actually cover; do not assume that a single retention period is appropriate for every business record.
Suggested evidence or output: An ongoing review calendar, change-review process, and applicable evidence-retention schedule.
Source framework: Level 2 self-assessment, affirmation and assessment findings. The sequence and suggested outputs are DCR editorial guidance, not additional official requirements.
Email me the 32-point checklist PDF
Scope reference: five asset categories, not one treatment
Apply the current Level 2 scoping rule to the assets in your environment. The table below is a summary, not a substitute for the rule’s category-specific treatment.
| Category | What to establish |
|---|---|
| CUI Assets | Identify assets that process, store, or transmit CUI and include them in the applicable assessment work. |
| Security Protection Assets | Identify the security functions they provide. Assessment addresses requirements relevant to those functions. |
| Contractor Risk Managed Assets | Document why assets capable of handling CUI are not intended to do so and how policy, procedure, and practice manage the risk. They are not simply ignored. |
| Specialized Assets | Identify and document these assets and the applicable risk-based treatment in the inventory, SSP, and diagrams. Do not treat specialized status as a blanket exclusion. |
| Out-of-Scope Assets | Establish that the assets cannot process, store, or transmit CUI and do not provide protection for CUI Assets. Document the basis for exclusion. |
An external service can affect scope even when the provider never receives a controlled drawing. Conversely, a product handling security logs is not automatically a CUI Asset. Record the actual data and security functions, then apply the relevant rule. For a fuller explanation, see the CMMC scoping guide.
Where the 110 Level 2 requirements fit
The 32 checkpoints above organize readiness work across the 14 requirement families. They do not replace the individual requirements. Use the complete NIST requirement reference alongside your own evidence register; the controlling wording is in the NIST Revision 2 publication.
| Family | Requirement identifiers | Count |
|---|---|---|
| Access Control | 3.1.1–3.1.22 | 22 |
| Awareness and Training | 3.2.1–3.2.3 | 3 |
| Audit and Accountability | 3.3.1–3.3.9 | 9 |
| Configuration Management | 3.4.1–3.4.9 | 9 |
| Identification and Authentication | 3.5.1–3.5.11 | 11 |
| Incident Response | 3.6.1–3.6.3 | 3 |
| Maintenance | 3.7.1–3.7.6 | 6 |
| Media Protection | 3.8.1–3.8.9 | 9 |
| Personnel Security | 3.9.1–3.9.2 | 2 |
| Physical Protection | 3.10.1–3.10.6 | 6 |
| Risk Assessment | 3.11.1–3.11.3 | 3 |
| Security Assessment | 3.12.1–3.12.4 | 4 |
| System and Communications Protection | 3.13.1–3.13.16 | 16 |
| System and Information Integrity | 3.14.1–3.14.7 | 7 |
| Total | Revision 2 requirement set | 110 |
Use the assessment procedures incorporated into the applicable CMMC process. Do not silently substitute Revision 3 because it is a newer NIST publication. CMMC’s incorporated baseline and a separate contract’s safeguarding requirements must each be checked against their own governing text. Sources: CMMC Model, Level 2 self-assessment procedures and DFARS 252.204-7012.
What an evidence record should make clear
A useful working record identifies the requirement and objective, the system or service covered, the evidence location, the responsible owner, the review date, the finding, and any next action. Store sensitive evidence in the approved environment, not in this page or a general web form.
| Example | Incomplete readiness assertion | More useful evidence trail |
|---|---|---|
| MFA | “Our email uses MFA.” | Applicable access paths and account types, configuration evidence, and relevant enforcement tests. |
| SSP | “We bought a template.” | Current system-specific description, boundary and asset references, implementation narratives, and controlled version history. |
| Logging | “We have a SIEM.” | Relevant sources, settings, protected records, review activity, and follow-up on identified events. |
These are examples, not universal evidence packages. The scoring rule defines MET around satisfying all applicable objectives with final evidence; draft or unapproved material is not equivalent. It also addresses N/A findings, enduring exceptions, and temporary deficiencies under defined conditions. A checklist should not override those distinctions.
Scoring and POA&M: check eligibility, not just the number
Use the current CMMC scoring methodology and POA&M requirements. Do not calculate a CMMC score by counting checked boxes in this 32-point workflow.
For Conditional Level 2, the score threshold is at least 80% of the 110 requirements—88 points—but the score alone is insufficient. The POA&M rules also restrict which findings may remain open. A generally ineligible finding is not made eligible by a high total score.
Most requirements worth more than one point cannot be included. The rule contains a specific exception for SC.L2-3.13.11 when encryption is employed but is not FIPS-validated, producing the specified three-point condition. It also bars these six requirements by name: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. A permitted POA&M must be closed and confirmed through the applicable closeout assessment within 180 days of the Conditional CMMC Status Date. Source: § 170.21.
Practical sequence: establish defensible findings, apply the scoring method, screen every remaining gap against the eligibility rules, and plan the applicable closeout. Do not treat ordinary remediation planning as permission to obtain Conditional status. Do not use a blanket “no partial credit” rule: § 170.24 provides limited partial-implementation scoring cases, distinct from calling a requirement MET.
Assessment, SPRS, and ongoing affirmation
Readiness work and an assessment result are different things. CMMC Level 2 (Self) is assessed by the organization; the certification-assessment process uses a CMMC Third-Party Assessment Organization, or C3PAO. Which process is applicable must be reconciled with current implementation guidance and the actual requirement. This guide does not recommend purchasing a third-party assessment simply because you downloaded a checklist.
For Level 2 (Self), the regulation identifies the information to enter into SPRS, including the CMMC level, status date, scope, associated CAGE codes, score, and POA&M usage and compliance status where applicable. Keep the underlying SSP and evidence available as required; do not confuse reporting fields with an instruction to upload all sensitive evidence. Level 2 assessment requirements operate on a three-year cycle, with affirmation at the required assessment points and annually thereafter. Sources: § 170.16 and § 170.22.
A NIST SP 800-171 DoD Assessment summary and a CMMC status record serve related but different requirements. Review the SPRS guide and Level 2 assessment guide before treating one as the other.
What to do with the gaps you find
Start with the blocker, not a provider category chosen in advance. An unclear contractual requirement needs clarification through the appropriate contracting or advisory channel. Missing scope or implementation records call for readiness work. Missing technical controls call for implementation. A formal assessment is a separate step when it is applicable and the organization is prepared.
You do not have to hire a consultant to use this checklist. When outside help is useful, ask for defined deliverables, evidence ownership, and a clear division between preparation and assessment. Read what a CMMC consultant does before requesting a proposal.
Need help deciding what type of provider fits your situation? Use Find My CMMC Path for educational routing based on your level, scope, environment, and timeline. Do not submit CUI, drawings, system details, or sensitive contract information.
Email me the 32-point checklist PDF
CMMC readiness checklist questions
Is this a CMMC compliance checklist or a readiness checklist?
It is a readiness workflow for organizing work toward applicable CMMC Level 2 requirements. “Compliance checklist” is a common search description, but this editorial resource is not proof of compliance. Use the source requirements and applicable assessment process to determine status.
Does the PDF contain a 110-row requirement tracker?
No. The emailed resource is the 32-point Level 2 readiness checklist PDF. For the individual requirement identifiers, use our NIST SP 800-171 Revision 2 reference. A 32-point planning workflow and the 110 official requirements are different resources.
Can I use the page without providing an email address?
Yes. The guidance on this page is available to read without submitting the form. The form emails the existing printable PDF for convenient offline use. Requesting it does not require subscribing to the optional weekly briefing.
Is it suitable for Level 1?
The workflow and PDF are specifically for Level 2. An organization preparing for Level 1 should use our Level 1 self-assessment checklist and verify its applicable requirement.
Does a self-assessment need less implementation evidence?
Do not treat self-assessment as permission to make unsupported findings. The applicable Level 2 self-assessment requirements still use the Revision 2 baseline and the prescribed procedures. Keep evidence that supports the findings and the records required for the process. Source: § 170.16.
Does the Phase II suspension remove the need to prepare?
The July 2026 suspension did not remove Phase I self-assessment requirements or the duty to safeguard covered information under applicable contracts. Check the current official notice and your actual obligation. Avoid assuming either that every company must immediately buy a C3PAO assessment or that all cybersecurity work can stop.
Will completing the checklist get us certified?
No. It helps organize readiness work. Certification, self-assessment status, contract eligibility, and continuing compliance depend on the applicable requirements and process—not on completing this page or downloading a PDF.
Sources, scope, and limitations
The Defense Compliance Report is an independent publication. This workflow is editorial research, not a government checklist, a certification service, or legal, contractual, or official assessment advice. No named subject-matter review is claimed. The 32 checkpoint titles preserve the existing readiness resource; the explanations and evidence examples are editorial implementation aids.
Substantive source review: September 28, 2026. The eCFR pages consulted displayed Title 32 as current through September 25, 2026. Rollout information should be rechecked against the official program notice before a compliance decision. A later website deployment date is not a new substantive verification date.
The key primary references are the CMMC Model, Level 2 self-assessment requirements, scoping rule, POA&M rule, affirmation rule, flow-down rule, scoring methodology, NIST SP 800-171 Revision 2, NIST SP 800-171A, DFARS 252.204-7012, and the official CMMC program page.
See our methodology and corrections policy. For deeper work, use the documentation checklist, assessment guide, scoping guide, and Level 2 cost guide.