Nice To E-Meet You!



    What marketing services do you need for your project?

    CMMC Compliance Checklist For 2026

    Short answer: To get CMMC compliant, confirm which level your contracts require, define exactly which systems handle federal contract information (FCI) or controlled unclassified information (CUI), meet every requirement for that level (15 for Level 1, 110 for Level 2), document it in a System Security Plan, score yourself honestly, post the result in SPRS and have a senior official affirm it. Then keep it current every year. The CMMC compliance checklist below walks through each of those steps in order.

    2026 status check (as of 27 September 2026): CMMC Phase 2 was suspended on 13 July 2026, and a 3 September 2026 class deviation removed third-party assessment requirements from contracts. The CMMC Reform Task Force delivered its recommendations to the Department of War CIO in mid-September, but they have not been made public yet. Self-assessments, SPRS entries, annual affirmations and the underlying security requirements still apply, so this checklist still applies in full. Third-party certification is voluntary for now.

    In This Guide

    What Is CMMC Compliance?

    CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that checks whether defense contractors actually protect the government information they handle. The program rules sit in 32 CFR Part 170, in force since 16 December 2024, and the contract clause that puts CMMC into solicitations, DFARS 252.204-7021, took effect on 10 November 2025.

    CMMC compliance means meeting every security requirement for your assigned level, proving it through the right type of assessment, recording the result in the Supplier Performance Risk System (SPRS) and reaffirming it every year. The CMMC requirements themselves are not new: Level 1 comes from FAR 52.204-21 and Level 2 from NIST SP 800-171, both of which contractors were already obliged to follow. CMMC adds the verification.

    CMMC Levels At A Glance

    Level Protects Requirements Assessment Frequency POA&M allowed?
    Level 1 FCI 15 (FAR 52.204-21) Self-assessment Every year, plus annual affirmation No
    Level 2 CUI 110 (NIST SP 800-171 Rev. 2) Self-assessment, or C3PAO (voluntary during the 2026 suspension) Every three years, plus annual affirmation Yes, limited, closed within 180 days
    Level 3 High-priority CUI 110 plus 24 from NIST SP 800-172 Government (DIBCAC), after a Level 2 C3PAO assessment Every three years, plus annual affirmation Yes, limited, closed within 180 days

    Level 3 is rare and assigned by the DoD for specific programs. DIBCAC assessments were also paused during the 2026 review.

    FCI vs CUI: Which Do You Handle?

      Federal contract information (FCI) Controlled unclassified information (CUI)
    What it is Information not meant for public release that is provided by or generated for the government under a contract Government information that law, regulation or policy says must be safeguarded, listed in the National Archives CUI Registry
    Typical examples Statements of work, delivery schedules, contract correspondence Technical drawings and specifications, export-controlled data, marked “CUI” documents
    CMMC level Level 1 Level 2 (or Level 3)

    Step 1: Determine Your CMMC Level

    • ☐ Read your current contracts and new solicitations for DFARS 252.204-7012, 252.204-7019, 252.204-7020 and 252.204-7021, and any stated CMMC level.
    • ☐ List the types of government information you receive: FCI only, or CUI as well.
    • ☐ Ask your prime contractor which level they are flowing down to you.
    • ☐ Record the answer: Level 1 (FCI only), Level 2 (CUI), or Level 3 (high-priority CUI, rare and set by DoD).

    Getting this step wrong is the most expensive mistake in CMMC. A company that only handles FCI does not need the 110 Level 2 requirements.

    Step 2: Scope Your Environment

    • ☐ Map where FCI and CUI enter the company (email, portals, file transfers, physical media).
    • ☐ List every system, cloud service, device and location that stores, processes or transmits it.
    • ☐ Identify security protection assets, such as firewalls, identity systems and logging tools, which are also in scope.
    • ☐ Decide whether to isolate CUI in an enclave (a separate, controlled environment) to shrink scope.
    • ☐ Confirm cloud services that hold CUI meet FedRAMP Moderate or an equivalent standard.
    • ☐ Draw a network diagram and build an asset inventory for the in-scope environment.

    Should You Use A CMMC Enclave?

    A CMMC enclave puts CUI in a walled-off set of systems, often a dedicated cloud tenant, so only the people and devices inside it fall under the 110 Level 2 requirements. It suits companies where CUI touches one engineering team or one contract rather than the whole business. The trade-off is workflow: staff have to work on CUI inside the enclave and nowhere else, and any copy that leaks onto a regular laptop drags that laptop back into scope. The DoD’s CMMC scoping guides for Level 1 and Level 2 set out the asset categories an assessor will use.

    Step 3: CMMC Level 1 Checklist (15 Requirements)

    The CMMC Level 1 requirements are the 15 basic safeguarding requirements in FAR 52.204-21. Every one must be fully met: POA&Ms are not allowed at Level 1. (Some assessment guides split the physical access item into separate practices, which is why you may see the number 17.) Level 1 results go into SPRS as met or not met; there is no numerical score.

    # Requirement Checklist item
    1 Limit system access to authorized users ☐ Accounts exist only for current, approved staff and devices
    2 Limit access to permitted transactions and functions ☐ Users can only do what their role needs
    3 Verify and control connections to external systems ☐ Personal devices and outside systems are controlled or blocked
    4 Control information posted on public systems ☐ Someone reviews what goes on the website and social media
    5 Identify users, processes and devices ☐ No shared or generic accounts
    6 Authenticate identities before access ☐ Passwords (or stronger) on every account; default passwords changed
    7 Sanitize or destroy media before disposal or reuse ☐ Drives and paper with FCI are wiped or shredded
    8 Limit physical access to systems and facilities ☐ Offices and equipment are locked to authorized people
    9 Escort visitors, log physical access and control keys and badges ☐ Visitor log kept, visitors escorted, keys and badges tracked
    10 Monitor and protect communications at system boundaries ☐ Firewall in place and configured
    11 Separate publicly accessible systems from internal networks ☐ Public-facing servers sit in their own network segment
    12 Identify, report and correct flaws promptly ☐ Patches applied on a set schedule
    13 Protect against malicious code ☐ Antivirus or endpoint protection on every device
    14 Update malicious code protection ☐ Definitions update automatically
    15 Scan systems periodically and files in real time ☐ Scheduled scans plus real-time scanning of downloads and attachments

    Step 4: CMMC Level 2 Checklist By Family

    Level 2 requires all 110 requirements of NIST SP 800-171 Rev. 2. CMMC is still tied to Rev. 2, even though NIST published Rev. 3 in May 2024. The CMMC Level 2 checklist below covers the core items an assessor looks for in each of the 14 families. Use it with the full requirement text in NIST SP 800-171 and the assessment objectives in NIST SP 800-171A.

    Access Control (22 requirements)

    • ☐ Least privilege enforced; admin rights separated from daily accounts
    • ☐ Session lock after inactivity; account lockout after failed logins
    • ☐ Remote access controlled, monitored and encrypted
    • ☐ Wireless and mobile devices controlled; CUI on mobile devices encrypted
    • ☐ CUI flow controlled between systems and users

    Awareness And Training (3)

    • ☐ Annual security awareness training for all users
    • ☐ Role-based training for admins and security staff
    • ☐ Insider threat awareness included

    Audit And Accountability (9)

    • ☐ Logs created for defined events and tied to individual users
    • ☐ Logs reviewed and correlated; alerts on logging failures
    • ☐ Logs protected from change; time sources synchronized

    Configuration Management (9)

    • ☐ Baseline configurations and an inventory for all in-scope systems
    • ☐ Change control process with security review
    • ☐ Unneeded functions, ports and software disabled; software allow-listing or deny-listing in place

    Identification And Authentication (11)

    • ☐ Multifactor authentication for privileged accounts and network access
    • ☐ Password complexity, reuse limits and encrypted storage
    • ☐ Inactive accounts disabled; replay-resistant authentication

    Incident Response (3)

    • ☐ Written incident response plan covering detection, analysis, containment and recovery
    • ☐ Process to report cyber incidents to DoD within 72 hours (DFARS 252.204-7012)
    • ☐ Incident response capability tested

    Maintenance (6)

    • ☐ Maintenance performed and logged; tools controlled
    • ☐ Remote maintenance sessions use MFA and are terminated after use
    • ☐ Equipment sanitized before off-site repair; maintenance staff supervised

    Media Protection (9)

    • ☐ CUI media marked, stored securely and access-limited
    • ☐ Media sanitized before disposal; removable media controlled
    • ☐ CUI encrypted on portable media and during transport

    Personnel Security (2)

    • ☐ Staff screened before access to CUI
    • ☐ Access removed promptly on termination or transfer

    Physical Protection (6)

    • ☐ Physical access limited and monitored; visitor escorts and logs
    • ☐ Access devices (keys, badges) managed
    • ☐ Safeguards for CUI at alternate work sites, including home offices

    Risk Assessment (3)

    • ☐ Periodic risk assessments
    • ☐ Regular vulnerability scanning
    • ☐ Vulnerabilities remediated by risk

    Security Assessment (4)

    • ☐ Controls assessed periodically
    • ☐ POA&M maintained for any gaps
    • ☐ Continuous monitoring in place
    • ☐ System Security Plan written and current

    System And Communications Protection (16)

    • ☐ Boundary protection and network segmentation for CUI systems
    • ☐ Deny-by-default network rules; split tunneling prevented
    • ☐ FIPS-validated encryption for CUI in transit and at rest
    • ☐ Collaborative devices (cameras, microphones) controlled
    • ☐ Sessions terminated after inactivity

    System And Information Integrity (7)

    • ☐ Flaws patched promptly
    • ☐ Malware protection updated and scanning
    • ☐ Security alerts monitored and acted on
    • ☐ Systems monitored for attacks and unauthorized use

    Step 5: Documentation Checklist

    • ☐ System Security Plan (mandatory at Level 2; cannot be on a POA&M)
    • ☐ Policies and procedures for each family
    • ☐ Network diagram and asset inventory
    • ☐ Data flow diagram showing how CUI moves
    • ☐ POA&M for any open items
    • ☐ Incident response plan and test records
    • ☐ Training records
    • ☐ Visitor and physical access logs
    • ☐ Customer responsibility matrix from each cloud or managed service provider
    • ☐ Evidence folder: configuration screenshots, log samples, scan results

    What Goes In A System Security Plan?

    The system security plan (SSP) is the one document every Level 2 assessment starts from. It should describe the system boundary and environment, list the in-scope assets, explain how each of the 110 requirements is implemented (or why it does not apply), show connections to other systems and say how often the plan is reviewed. Without an SSP, a Level 2 assessment cannot be scored at all.

    Step 6: Assessment, SPRS And Affirmation Checklist

    • ☐ Run a gap assessment against every requirement and assessment objective
    • ☐ Score Level 2 using the DoD Assessment Methodology (start at 110, subtract 1, 3 or 5 points per unmet requirement)
    • ☐ Confirm the score is at least 88 if you plan to use a POA&M; confirm only allowed items are on it
    • ☐ Enter the score, assessment date and scope in SPRS
    • ☐ Have a senior official submit the affirmation
    • ☐ If choosing a voluntary C3PAO assessment, select an accredited C3PAO that did not help you prepare
    • ☐ Close any POA&M items within 180 days

    How The SPRS Score Works

    SPRS (the Supplier Performance Risk System) is the DoD database where contractors post their NIST SP 800-171 and CMMC results. The Level 2 SPRS score follows the DoD Assessment Methodology: every contractor starts at 110 and loses points for each requirement that is not met.

    Item What it means
    Maximum score 110, every requirement met
    Lowest possible score -203, nothing met
    5-point requirements High-impact controls, such as multifactor authentication and FIPS-validated encryption of CUI
    3-point requirements Controls whose absence has a significant but narrower effect
    1-point requirements The remainder; the only type most POA&Ms can carry
    Minimum to use a POA&M 88 (80% of 110)

    A lower SPRS score is not a failure in itself, but only a score of 110, or 88 or more with an allowed POA&M, meets the CMMC Level 2 requirement. The number has to be honest: it is a representation to the government.

    POA&M Rules Under CMMC

    A POA&M (plan of action and milestones) lists requirements that are not yet met and when they will be. CMMC limits them tightly. None are allowed at Level 1. At Level 2, the score must be at least 88, most items on the POA&M must be 1-point requirements, and the SSP requirement can never be on it. Passing with open items gives Conditional status, which lasts 180 days; close every item and pass a closeout assessment within that window to reach Final status, or the conditional status lapses.

    C3PAO Assessments And CMMC Consultants In 2026

    A C3PAO (CMMC Third-Party Assessment Organization) is an assessor authorized by the Cyber AB and listed on the Cyber AB Marketplace. Under the 2026 suspension, a C3PAO assessment is voluntary, but some primes still ask for one and a certificate carries over when mandatory assessments return. Registered Provider Organizations (RPOs) and independent CMMC consultants help with preparation; keep that role separate from the assessor, since a C3PAO cannot assess a company it has also advised.

    Step 7: Ongoing Compliance Checklist

    • ☐ Level 1 self-assessment every year
    • ☐ Level 2 assessment every three years
    • ☐ Annual affirmation at every level
    • ☐ Update the SSP whenever systems change
    • ☐ Review logs, patch and scan on schedule
    • ☐ Refresh training annually
    • ☐ Watch for CMMC program changes once the 2026 task force recommendations are published

    Common Mistakes

    1. Scoping the whole company when only one team handles CUI. An enclave can cut the work substantially.
    2. Inflating the SPRS score. Self-assessments carry legal weight, and the Department of Justice pursues False Claims Act cases over misrepresented cybersecurity.
    3. Using commercial cloud for CUI. Standard Microsoft 365 and Google Workspace tenants generally do not meet the requirement for CUI.
    4. Writing an SSP that does not match reality. Assessors test what is running, not what the document says.
    5. Assuming the 2026 suspension means CMMC is over. Only mandatory third-party assessment was paused; the requirements remain.

    For the full Level 2 breakdown, see our CMMC Level 2 requirements guide, and for budgets, see how much CMMC certification costs. Vulnerability scanning and testing come up at every level, so it helps to know what penetration testing costs and to compare the top penetration testing companies. For broader outside help, REVERB’s list of the top cybersecurity companies is a good place to start.

    Frequently Asked Questions

    What is on a CMMC compliance checklist?

    Determining your level, scoping systems that handle FCI or CUI, meeting every requirement for that level, writing a System Security Plan, scoring yourself, posting the result in SPRS, submitting an annual affirmation and maintaining it all over time.

    What are the CMMC levels?

    Level 1 protects FCI with 15 requirements, Level 2 protects CUI with the 110 requirements of NIST SP 800-171, and Level 3 adds 24 requirements from NIST SP 800-172 for high-priority CUI.

    How many requirements are in CMMC Level 1?

    15, from FAR 52.204-21. Some guides count 17 practices because the physical access requirement is split into parts.

    How many requirements are in CMMC Level 2?

    110, from NIST SP 800-171 Rev. 2, across 14 families.

    Is CMMC the same as NIST 800-171?

    No. NIST SP 800-171 is the list of security requirements; CMMC is the DoD program that verifies contractors meet them. At Level 2, the requirements are identical, and CMMC adds assessment, SPRS reporting and annual affirmation.

    Can I self-assess for CMMC?

    Yes for Level 1, and yes for Level 2 where the contract calls for a self-assessment. Since September 2026, third-party assessment requirements have been removed from contracts, so a CMMC self-assessment is the current mandatory route.

    Where do I submit my CMMC score?

    In the Supplier Performance Risk System (SPRS), together with the affirmation from a senior company official.

    What is a good SPRS score?

    110 is full compliance. For CMMC Level 2, 88 is the minimum that allows a POA&M, and those open items must close within 180 days.

    What is a POA&M in CMMC?

    A plan of action and milestones listing unmet requirements and the dates they will be fixed. CMMC allows it only at Level 2 and 3, only for limited items, and only for 180 days.

    Does CMMC apply to small businesses?

    Yes. There is no size exemption. Any company, including a subcontractor, that handles FCI or CUI on a DoD contract needs the level that contract requires, and primes must flow the requirement down.

    Can I use Microsoft 365 for CUI?

    Not the standard commercial tenant in most cases. Cloud services holding CUI must meet FedRAMP Moderate or equivalent, which is why many contractors use Microsoft 365 GCC High or a dedicated CUI enclave.

    Do I still need CMMC after the 2026 suspension?

    Yes. Self-assessments, SPRS entries, annual affirmations and the underlying FAR and DFARS security requirements are all still in force.

    The Short Version

    • Confirm your level and scope before spending money.
    • Level 1: 15 requirements, all fully met, self-assessed every year.
    • Level 2: 110 requirements, an SSP, a scored assessment every three years and an annual affirmation.
    • Post scores in SPRS honestly and close any POA&M within 180 days.
    • The 2026 pause removed mandatory third-party audits, not the requirements.

      Once a week you will get the latest articles delivered right to your inbox