Short answer: To get CMMC compliant, confirm which level your contracts require, define exactly which systems handle federal contract information (FCI) or controlled unclassified information (CUI), meet every requirement for that level (15 for Level 1, 110 for Level 2), document it in a System Security Plan, score yourself honestly, post the result in SPRS and have a senior official affirm it. Then keep it current every year. The CMMC compliance checklist below walks through each of those steps in order.
2026 status check (as of 27 September 2026): CMMC Phase 2 was suspended on 13 July 2026, and a 3 September 2026 class deviation removed third-party assessment requirements from contracts. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in mid-September, but they have not been made public yet. Self-assessments, SPRS entries, annual affirmations and the underlying security requirements still apply, so this checklist still applies in full. Third-party certification is voluntary for now.
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that checks whether defense contractors actually protect the government information they handle. The program rules sit in 32 CFR Part 170, in force since 16 December 2024, and the contract clause that puts CMMC into solicitations, DFARS 252.204-7021, took effect on 10 November 2025.
CMMC compliance means meeting every security requirement for your assigned level, proving it through the right type of assessment, recording the result in the Supplier Performance Risk System (SPRS) and reaffirming it every year. The CMMC requirements themselves are not new: Level 1 comes from FAR 52.204-21 and Level 2 from NIST SP 800-171, both of which contractors were already obliged to follow. CMMC adds the verification.
| Level | Protects | Requirements | Assessment | Frequency | POA&M allowed? |
| Level 1 | FCI | 15 (FAR 52.204-21) | Self-assessment | Every year, plus annual affirmation | No |
| Level 2 | CUI | 110 (NIST SP 800-171 Rev. 2) | Self-assessment, or C3PAO (voluntary during the 2026 suspension) | Every three years, plus annual affirmation | Yes, limited, closed within 180 days |
| Level 3 | High-priority CUI | 110 plus 24 from NIST SP 800-172 | Government (DIBCAC), after a Level 2 C3PAO assessment | Every three years, plus annual affirmation | Yes, limited, closed within 180 days |
Level 3 is rare and assigned by the DoD for specific programs. DIBCAC assessments were also paused during the 2026 review.
| Federal contract information (FCI) | Controlled unclassified information (CUI) | |
| What it is | Information not meant for public release that is provided by or generated for the government under a contract | Government information that law, regulation or policy says must be safeguarded, listed in the National Archives CUI Registry |
| Typical examples | Statements of work, delivery schedules, contract correspondence | Technical drawings and specifications, export-controlled data, marked “CUI” documents |
| CMMC level | Level 1 | Level 2 (or Level 3) |
Getting this step wrong is the most expensive mistake in CMMC. A company that only handles FCI does not need the 110 Level 2 requirements.
A CMMC enclave puts CUI in a walled-off set of systems, often a dedicated cloud tenant, so only the people and devices inside it fall under the 110 Level 2 requirements. It suits companies where CUI touches one engineering team or one contract rather than the whole business. The trade-off is workflow: staff have to work on CUI inside the enclave and nowhere else, and any copy that leaks onto a regular laptop drags that laptop back into scope. The DoD’s CMMC scoping guides for Level 1 and Level 2 set out the asset categories an assessor will use.
The CMMC Level 1 requirements are the 15 basic safeguarding requirements in FAR 52.204-21. Every one must be fully met: POA&Ms are not allowed at Level 1. (Some assessment guides split the physical access item into separate practices, which is why you may see the number 17.) Level 1 results go into SPRS as met or not met; there is no numerical score.
| # | Requirement | Checklist item |
| 1 | Limit system access to authorized users | ☐ Accounts exist only for current, approved staff and devices |
| 2 | Limit access to permitted transactions and functions | ☐ Users can only do what their role needs |
| 3 | Verify and control connections to external systems | ☐ Personal devices and outside systems are controlled or blocked |
| 4 | Control information posted on public systems | ☐ Someone reviews what goes on the website and social media |
| 5 | Identify users, processes and devices | ☐ No shared or generic accounts |
| 6 | Authenticate identities before access | ☐ Passwords (or stronger) on every account; default passwords changed |
| 7 | Sanitize or destroy media before disposal or reuse | ☐ Drives and paper with FCI are wiped or shredded |
| 8 | Limit physical access to systems and facilities | ☐ Offices and equipment are locked to authorized people |
| 9 | Escort visitors, log physical access and control keys and badges | ☐ Visitor log kept, visitors escorted, keys and badges tracked |
| 10 | Monitor and protect communications at system boundaries | ☐ Firewall in place and configured |
| 11 | Separate publicly accessible systems from internal networks | ☐ Public-facing servers sit in their own network segment |
| 12 | Identify, report and correct flaws promptly | ☐ Patches applied on a set schedule |
| 13 | Protect against malicious code | ☐ Antivirus or endpoint protection on every device |
| 14 | Update malicious code protection | ☐ Definitions update automatically |
| 15 | Scan systems periodically and files in real time | ☐ Scheduled scans plus real-time scanning of downloads and attachments |
Level 2 requires all 110 requirements of NIST SP 800-171 Rev. 2. CMMC is still tied to Rev. 2, even though NIST published Rev. 3 in May 2024. The CMMC Level 2 checklist below covers the core items an assessor looks for in each of the 14 families. Use it with the full requirement text in NIST SP 800-171 and the assessment objectives in NIST SP 800-171A.
The system security plan (SSP) is the one document every Level 2 assessment starts from. It should describe the system boundary and environment, list the in-scope assets, explain how each of the 110 requirements is implemented (or why it does not apply), show connections to other systems and say how often the plan is reviewed. Without an SSP, a Level 2 assessment cannot be scored at all.
SPRS (the Supplier Performance Risk System) is the DoD database where contractors post their NIST SP 800-171 and CMMC results. The Level 2 SPRS score follows the DoD Assessment Methodology: every contractor starts at 110 and loses points for each requirement that is not met.
| Item | What it means |
| Maximum score | 110, every requirement met |
| Lowest possible score | -203, nothing met |
| 5-point requirements | High-impact controls, such as multifactor authentication and FIPS-validated encryption of CUI |
| 3-point requirements | Controls whose absence has a significant but narrower effect |
| 1-point requirements | The remainder; the only type most POA&Ms can carry |
| Minimum to use a POA&M | 88 (80% of 110) |
A lower SPRS score is not a failure in itself, but only a score of 110, or 88 or more with an allowed POA&M, meets the CMMC Level 2 requirement. The number has to be honest: it is a representation to the government.
A POA&M (plan of action and milestones) lists requirements that are not yet met and when they will be. CMMC limits them tightly. None are allowed at Level 1. At Level 2, the score must be at least 88, most items on the POA&M must be 1-point requirements, and the SSP requirement can never be on it. Passing with open items gives Conditional status, which lasts 180 days; close every item and pass a closeout assessment within that window to reach Final status, or the conditional status lapses.
A C3PAO (CMMC Third-Party Assessment Organization) is an assessor authorized by the Cyber AB and listed on the Cyber AB Marketplace. Under the 2026 suspension, a C3PAO assessment is voluntary, but some primes still ask for one and a certificate carries over when mandatory assessments return. Registered Provider Organizations (RPOs) and independent CMMC consultants help with preparation; keep that role separate from the assessor, since a C3PAO cannot assess a company it has also advised.
For the full Level 2 breakdown, see our CMMC Level 2 requirements guide, and for budgets, see how much CMMC certification costs. Vulnerability scanning and testing come up at every level, so it helps to know what penetration testing costs and to compare the top penetration testing companies. For broader outside help, REVERB’s list of the top cybersecurity companies is a good place to start.
Determining your level, scoping systems that handle FCI or CUI, meeting every requirement for that level, writing a System Security Plan, scoring yourself, posting the result in SPRS, submitting an annual affirmation and maintaining it all over time.
Level 1 protects FCI with 15 requirements, Level 2 protects CUI with the 110 requirements of NIST SP 800-171, and Level 3 adds 24 requirements from NIST SP 800-172 for high-priority CUI.
15, from FAR 52.204-21. Some guides count 17 practices because the physical access requirement is split into parts.
110, from NIST SP 800-171 Rev. 2, across 14 families.
No. NIST SP 800-171 is the list of security requirements; CMMC is the DoD program that verifies contractors meet them. At Level 2, the requirements are identical, and CMMC adds assessment, SPRS reporting and annual affirmation.
Yes for Level 1, and yes for Level 2 where the contract calls for a self-assessment. Since September 2026, third-party assessment requirements have been removed from contracts, so a CMMC self-assessment is the current mandatory route.
In the Supplier Performance Risk System (SPRS), together with the affirmation from a senior company official.
110 is full compliance. For CMMC Level 2, 88 is the minimum that allows a POA&M, and those open items must close within 180 days.
A plan of action and milestones listing unmet requirements and the dates they will be fixed. CMMC allows it only at Level 2 and 3, only for limited items, and only for 180 days.
Yes. There is no size exemption. Any company, including a subcontractor, that handles FCI or CUI on a DoD contract needs the level that contract requires, and primes must flow the requirement down.
Not the standard commercial tenant in most cases. Cloud services holding CUI must meet FedRAMP Moderate or equivalent, which is why many contractors use Microsoft 365 GCC High or a dedicated CUI enclave.
Yes. Self-assessments, SPRS entries, annual affirmations and the underlying FAR and DFARS security requirements are all still in force.