CMMC Compliance Checklist: Expert Roadmap to Certification Success

CMMC Compliance Checklist showing steps to achieve DoD certification

CMMC Compliance Checklist: 10 Steps to Level 2 Certification

Updated July 2026: On July 13, 2026, the Department of War suspended CMMC Phase 2 pending a 60-day Reform Task Force review. The Phase 2 dates and framing below are kept for historical context — see our breakdown of the CMMC Phase 2 suspension for what’s actually in effect right now.

If you are a defense subcontractor who has been told you need CMMC certification and you are not sure where to begin, this is where you begin.

The CMMC framework and its compliance requirements are sequential — each phase of the compliance journey builds on the one before it. Working through the steps in order, and not skipping ahead to the C3PAO selection conversation before your environment is ready, is what separates contractors who achieve CMMC compliance on their first attempt from those who do not.

This checklist covers the ten steps that take a defense contractor from initial determination through certified compliance, followed by what maintaining that certification actually requires.

Step 1: Determine Which CMMC Level Applies to Your Organization

Before any compliance work begins, you need to know what you are complying with.

The Department of Defense developed CMMC 2.0 to enforce cybersecurity standards across the defense industrial base. The CMMC framework organizes compliance requirements around three maturity levels based on the type of information your DoD contracts require you to handle:

  • CMMC Level 1 applies to organizations handling Federal Contract Information. It covers 15 foundational security practices and requires annual self-assessment submitted to the Supplier Performance Risk System (SPRS).
  • CMMC Level 2 applies to organizations handling Controlled Unclassified Information (CUI). It requires implementation of all 110 security requirements in NIST SP 800-171 and, for most DoD contracts, a third-party assessment by a C3PAO.
  • CMMC Level 3 applies to organizations supporting the most sensitive DoD programs. It adds requirements from NIST SP 800-172 and requires government-led assessment by DIBCAC.

The distinction between Level 1 and Level 2 is not organizational size — it is data type. Your required CMMC level is determined by your contracts, specifically whether they include DFARS 252.204-7012 language referencing CUI protection obligations. If that clause appears in your contract or flows down through contractors and subcontractors from your prime’s agreement, Level 2 applies to your organization.

Most defense subcontractors in the manufacturing supply chain fall under Level 2. If you receive technical drawings, engineering specifications, or CAD files related to defense programs, you likely handle controlled unclassified information whether or not it has been formally identified as such.

Step 2: Conduct a Comprehensive Gap Assessment

Once you know your required level, the next step is understanding the distance between where your security posture is today and where it needs to be.

A gap assessment evaluates your current environment against all applicable CMMC compliance requirements — the 15 practices for CMMC Level 1, or all 110 NIST SP 800-171 requirements for CMMC Level 2. For each control, you document whether it is fully implemented, partially implemented, or not yet in place.

This assessment establishes your SPRS baseline score and drives every subsequent decision — what to prioritize, what to document, and how long the remediation work will take. Contractors who skip or minimize this step typically encounter surprises during assessment preparation that could have been addressed earlier and less expensively.

The gap assessment should cover every system, person, and process involved in handling CUI. Getting the scope right at this stage matters: too narrow and you leave systems inside your CUI environment unprotected; too wide and you expand the compliance burden unnecessarily.

Step 3: Define Your Scope and Assign a Compliance Coordinator

The CUI boundary you establish in Step 2 defines your compliance scope. Document it clearly before any remediation work begins.

Scope definition answers four questions: what systems store or process CUI, what users have access to it, what networks transmit it, and what third parties or vendors handle it on your behalf. Every system inside that boundary is subject to CMMC requirements.

Designate one compliance coordinator internally — someone responsible for tracking progress, owning documentation, and serving as the primary point of contact for your C3PAO when that engagement begins. Large compliance programs can diffuse accountability. One named owner prevents that.

Narrowing your scope where technically defensible reduces both your remediation workload and your assessment burden. A segmented CUI environment that isolates CUI on dedicated systems is an engineering advantage, not just a compliance strategy.

Step 4: Implement the Required NIST SP 800-171 Security Controls

With scope defined and gaps identified, remediation begins. To meet CMMC Level 2 requirements, organizations must implement all 110 controls across NIST SP 800-171’s 14 control families — across every family, not just the highest-risk areas.

Not all controls require equal effort or carry the same risk if unimplemented. Work from your gap assessment findings, prioritizing controls that protect CUI confidentiality directly — access control, identification and authentication, system and communications protection — before moving to the supporting families.

Practical implementation involves three layers: technical configuration (multi-factor authentication, network segmentation, encryption, audit logging), policy development (written procedures for each control family), and evidence creation (configuration records, access logs, training documentation). DoD assessors verify that controls are implemented, not just documented. CMMC standards do not accept documented intention as a substitute for operational evidence.

Controls your environment cannot fully implement before assessment go into your Plan of Action and Milestones.

Step 5: Develop Your System Security Plan

Your System Security Plan is the primary document assessors review before and during your C3PAO evaluation. It maps every applicable NIST SP 800-171 requirement to your specific environment — describing how each control is implemented, who owns it, and what systems it applies to.

The SSP is not a template you download and fill in. It is a document that reflects your actual environment. An SSP that describes how controls are supposed to work, rather than how they currently work, is a problem assessors identify quickly. The gap between the SSP and live configurations is one of the most common CMMC documentation findings.

Start the SSP early in the process, update it as remediation progresses, and treat it as a working document rather than a final deliverable. It will evolve through every subsequent step.

Step 6: Create Your Plan of Action and Milestones

A Plan of Action and Milestones (POA&M) documents every CMMC control that is not yet fully implemented, along with a realistic timeline and responsible owner for closing each gap.

Under CMMC 2.0, Level 2 compliance allows organizations to pursue certification with open POA&M items for certain controls, provided they meet minimum score thresholds and demonstrate a credible remediation plan with a 180-day close-out timeline. Not all controls are POA&M-eligible — some must be fully implemented before assessment.

A well-managed POA&M converts an overwhelming gap list into a tracked project. One that stalls or lacks ownership becomes a liability in the assessment room.

Step 7: Establish Compliance Policies and Procedures

Each NIST SP 800-171 control family requires documented policies describing your organization’s approach to that control area, and procedures that explain specifically how those policies are carried out. Policy alone is not sufficient — assessors look for evidence that procedures are followed in practice.

Common areas where policy documentation stalls compliance programs: incident response (a written plan that has never been tested), personnel security (onboarding and offboarding procedures that exist on paper but not in practice), and media protection (policies that describe CUI handling without evidence of training or enforcement).

Each policy area needs a named owner and a review cycle. Stale policies that predate your current CUI environment create findings.

Step 8: Conduct Your NIST SP 800-171 Self-Assessment

Before engaging a C3PAO for formal certification, complete a rigorous NIST 800-171 self-assessment using NIST SP 800-171A assessment objectives. This process evaluates each control honestly — met, partially met, or not met — and generates your SPRS score.

Submit your self-assessment score to the Supplier Performance Risk System (SPRS). The DoD uses SPRS data to evaluate contractor cybersecurity posture across the defense supply chain, and submitting an inaccurate or unsubstantiated score carries legal risk under the False Claims Act. CMMC 2.0 requirements also mandate annual affirmations by senior leadership confirming score accuracy.

The self-assessment is not a formality. It is your last opportunity to identify gaps before a paid CMMC audit surfaces them under higher stakes. Contractors who test actual system configurations rather than reviewing documentation arrive at their C3PAO assessment with fewer surprises.

Step 9: Select and Engage a C3PAO

For Level 2 DoD contracts requiring third-party certification, you must engage a CMMC Third-Party Assessment Organization — a C3PAO authorized by the Cyber Accreditation Body (Cyber AB) to conduct official CMMC certification assessments. The CMMC certification process requires working with an accredited assessor; no other entity can certify your organization.

Verify your C3PAO’s credentials in the Cyber AB Marketplace before signing any engagement agreement. Only C3PAOs listed there are authorized to conduct CMMC assessments. Your managed service provider or compliance partner cannot also serve as your C3PAO — conflict of interest rules prohibit assessing an environment the assessor helped build.

Engage your C3PAO early. Assessment scheduling is competitive, and experienced firms book out months in advance. Confirm the scope of the engagement, the documentation they need before the assessment start date, and the process for addressing findings.

Step 10: Prepare for and Defend the Third-Party Assessment

Preparing for CMMC assessment is not a documentation exercise — it is an operational readiness exercise. Level 2 assessment involves four phases: documentation review, technical testing, personnel interviews, and artifact validation. Assessors do not take your word for implementation — they test it.

Prepare your evidence package before the assessment begins: SSP, POA&M, configuration exports, access logs, training records, incident response documentation, and any other artifacts that demonstrate your controls are implemented and consistently followed.

Conduct a pre-assessment walkthrough with your internal team. Every person who may be interviewed should be able to explain how the controls they own work in practice, not just describe what the policy says. Assessors ask operational questions. Confident, specific answers reflect genuine implementation. Vague answers reflect documentation written for the assessment.

Maintaining CMMC Compliance After Certification

Certification is the milestone, not the finish line.

Phase 1 enforcement has been active since November 2025. Phase 2, which would have expanded mandatory third-party Level 2 certification across a broader range of DoD contracts, was scheduled to take effect November 10, 2026, but is currently suspended pending a Department of War Reform Task Force review. Defense contractors who achieve compliance and then fail to maintain it still risk losing contract eligibility once enforcement resumes in whatever form it takes.

CMMC Level 2 requires annual affirmation by a senior company official confirming that controls remain in place and the security posture has not degraded. Every three years, organizations with third-party certification undergo full reassessment by a C3PAO.

Between assessment cycles, configuration drift — new software, staff turnover, expanded vendor access, system changes — can introduce gaps that were not present at certification. Working with a managed service provider that continuously monitors your environment makes it substantially easier to maintain compliance between assessment windows. Treat maintenance as an ongoing program, not a project that concludes at certification.

Right Hand Technology Group works with defense subcontractors through every stage of this compliance journey — gap assessment, control implementation, SSP development, and C3PAO preparation. As a certified CMMC-aligned partner who has completed its own Level 2 assessment, our team has achieved compliance with NIST 800-171 and defended those controls through a formal DoD-recognized process. Review our CMMC compliance services to understand how we structure an engagement, or schedule a free assessment to talk through where your organization stands before your next customer questionnaire or contract renewal.

 

Frequently Asked Questions

What is a passing CMMC score at Level 2?

CMMC Level 2 does not use a numeric pass/fail score in the traditional sense. To achieve CMMC certification, an organization must demonstrate that all 110 NIST SP 800-171 requirements are either fully implemented or covered by an approved Plan of Action and Milestones with a 180-day close-out timeline. Assessors determine each practice as met or not met. Controls that are not met and not covered by an approved POA&M will prevent certification.

What happens if you fail a CMMC assessment?

A failed CMMC assessment means the C3PAO identified one or more controls as not met that cannot be addressed through a POA&M. The organization cannot receive certification until those gaps are remediated and a follow-up assessment is completed. Outstanding compliance gaps can affect DoD contract eligibility during the remediation period. A failed assessment does not permanently disqualify a contractor — it identifies what must be fixed before certification can proceed.

What are the 14 CMMC domains?

CMMC Level 2 is built on NIST SP 800-171 Revision 2, which organizes its 110 security requirements across 14 control families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each family contains specific requirements that must be addressed in your System Security Plan and demonstrated during CMMC assessment.

Our Blog

CMMC Compliance Timeline: How Long Does It Take?

CMMC Compliance Timeline: How Long Does It Take?

The CMMC rollout has always been phased  moving from self-assessment toward mandatory third-party certification…

How to Meet CUI Marking Requirements: A Guide for the Defense Industrial Base

How to Meet CUI Marking Requirements: A Guide for the Defense Industrial Base

CUI marking means putting a banner marking at the top of a document identifying…

CMMC Compliance for Manufacturers: What You Need to Know

CMMC Compliance for Manufacturers: What You Need to Know

CMMC compliance for a manufacturer means the same NIST 800-171 controls as any other…