Free download
The 32-point CMMC Level 2 readiness checklist
Get the checklist
Email me the readiness checklist
The full checklist is available as a printable PDF. The eight sections below summarize all 32 checkpoints.
Contract, Data, and Accountability
- ·1. Build a contract and clause applicability register
- ·2. Determine exactly what is FCI, CUI, and covered defense information
- ·3. Map the complete CUI lifecycle and business workflows
- ·4. Name accountable leaders and the affirming official
Assessment Scope and Architecture
- ·5. Define the OSA and each distinct CMMC assessment scope
- ·6. Categorize every relevant asset using the Level 2 scoping model
- ·7. Maintain current boundary, network, and CUI data-flow diagrams
- ·8. Validate the boundary against shadow CUI and real user behavior
SSP, Objectives, Evidence, and Gaps
- ·9. Maintain a current, approved, system-specific SSP
- ·10. Map all 110 requirements to every applicable assessment objective
- ·11. Reconcile policies, procedures, configurations, tickets, and interviews
- ·12. Score gaps correctly and separate remediation from allowable CMMC POA&Ms
Identity, Access, Configuration, and Cryptography
- ·13. Control the full identity and account lifecycle
- ·14. Implement and test MFA on the exact required access paths
- ·15. Establish secure configurations, change control, and least functionality
- ·16. Protect CUI in transit and at rest with validated cryptography where required
Monitoring, Vulnerability, Incident, and Recovery
- ·17. Generate, protect, review, and act on security logs
- ·18. Operate vulnerability, flaw remediation, patching, and malicious-code defenses
- ·19. Make cyber incident response and DFARS reporting executable
- ·20. Protect backup CUI and prove recoverability
Physical, Media, Personnel, and Maintenance
- ·21. Control physical access to systems, facilities, and CUI
- ·22. Control the full lifecycle of paper and digital media
- ·23. Integrate personnel screening, onboarding, training, transfer, and termination
- ·24. Control maintenance personnel, tools, media, and remote sessions
Cloud, ESPs, External Connections, and Supply Chain
- ·25. Verify the exact cloud service offering used to handle CUI
- ·26. Scope MSPs, MSSPs, SOCs, and other external service providers correctly
- ·27. Authorize and control external, remote, mobile, wireless, and collaboration paths
- ·28. Flow requirements to subcontractors based on the information they receive
Assessment Execution, SPRS, and Continuous Compliance
- ·29. Build an objective-level evidence repository that can survive scrutiny
- ·30. Run a true mock assessment using examine, interview, and test
- ·31. Make SPRS records, CAGE mappings, scores, status, and UIDs accurate
- ·32. Sustain annual affirmation and material-change governance
Working through the checklist and finding more gaps than you expected? That is the signal to engage a readiness consultant before a C3PAO. The 7-question routing engine takes about two minutes.
Find My CMMC Path →