The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base
Free download

The 32-point CMMC Level 2 readiness checklist

A structured checklist that walks small DoD contractors through scope, SSP, SPRS, enclave, MSP, and pre-assessment evidence. We email you the PDF.

The Defense Compliance Report Editorial TeamIndependent CMMC and DIB compliance research
Published: Last reviewed:
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a Registered Practitioner before acting.
Get the checklist

Email me the readiness checklist

One email. No contract uploads, no CUI, no sensitive files — ever. See our privacy policy.

We will email the checklist to the address you provide. Do not upload, enter, or send contracts, CUI, controlled technical data, export-controlled content, system diagrams, vulnerabilities, incident details, employee personal information, or other sensitive security information through this form.

Do not submit CUI, drawings, export-controlled content, or sensitive contract details. This intake is for buyer-need routing only. Sensitive information should be shared only through appropriate secure channels after you have independently verified and engaged a provider.

The checklist request does not require subscribing to the weekly briefing. You can unsubscribe from the weekly briefing at any time.

Last reviewed

The full checklist is available as a printable PDF. The eight sections below summarize all 32 checkpoints.

Contract, Data, and Accountability

  • ·1. Build a contract and clause applicability register
  • ·2. Determine exactly what is FCI, CUI, and covered defense information
  • ·3. Map the complete CUI lifecycle and business workflows
  • ·4. Name accountable leaders and the affirming official

Assessment Scope and Architecture

  • ·5. Define the OSA and each distinct CMMC assessment scope
  • ·6. Categorize every relevant asset using the Level 2 scoping model
  • ·7. Maintain current boundary, network, and CUI data-flow diagrams
  • ·8. Validate the boundary against shadow CUI and real user behavior

SSP, Objectives, Evidence, and Gaps

  • ·9. Maintain a current, approved, system-specific SSP
  • ·10. Map all 110 requirements to every applicable assessment objective
  • ·11. Reconcile policies, procedures, configurations, tickets, and interviews
  • ·12. Score gaps correctly and separate remediation from allowable CMMC POA&Ms

Identity, Access, Configuration, and Cryptography

  • ·13. Control the full identity and account lifecycle
  • ·14. Implement and test MFA on the exact required access paths
  • ·15. Establish secure configurations, change control, and least functionality
  • ·16. Protect CUI in transit and at rest with validated cryptography where required

Monitoring, Vulnerability, Incident, and Recovery

  • ·17. Generate, protect, review, and act on security logs
  • ·18. Operate vulnerability, flaw remediation, patching, and malicious-code defenses
  • ·19. Make cyber incident response and DFARS reporting executable
  • ·20. Protect backup CUI and prove recoverability

Physical, Media, Personnel, and Maintenance

  • ·21. Control physical access to systems, facilities, and CUI
  • ·22. Control the full lifecycle of paper and digital media
  • ·23. Integrate personnel screening, onboarding, training, transfer, and termination
  • ·24. Control maintenance personnel, tools, media, and remote sessions

Cloud, ESPs, External Connections, and Supply Chain

  • ·25. Verify the exact cloud service offering used to handle CUI
  • ·26. Scope MSPs, MSSPs, SOCs, and other external service providers correctly
  • ·27. Authorize and control external, remote, mobile, wireless, and collaboration paths
  • ·28. Flow requirements to subcontractors based on the information they receive

Assessment Execution, SPRS, and Continuous Compliance

  • ·29. Build an objective-level evidence repository that can survive scrutiny
  • ·30. Run a true mock assessment using examine, interview, and test
  • ·31. Make SPRS records, CAGE mappings, scores, status, and UIDs accurate
  • ·32. Sustain annual affirmation and material-change governance

Working through the checklist and finding more gaps than you expected? That is the signal to engage a readiness consultant before a C3PAO. The 7-question routing engine takes about two minutes.

Find My CMMC Path →