Start here: scope your Controlled Unclassified Information (CUI) footprint, decide whether you need a self-assessment or a Certified Third-Party Assessment Organization (C3PAO) review, and open your evidence collection today. Every other step in this cmmc compliance checklist depends on getting those three things moving first, because scoping mistakes are the single biggest driver of blown budgets and missed deadlines.
Here is where to start this week:
- Assign a CUI owner (usually the compliance officer or IT lead) to map every place Controlled Unclassified Information lives, moves, or gets stored.
- Build a live asset inventory covering laptops, servers, cloud tenants, and any external service provider touching your network.
- Draft a System Security Plan (SSP) skeleton so you have a container for evidence as you collect it.
- Pick your assessment route — Level 2 self-assessment or C3PAO certification — based on your contract language.
- Open a Plan of Action and Milestones (POA&M) tracker now, even if it is empty, so remediation items have somewhere to land.
Every item above maps back to 32 CFR Part 170, NIST SP 800-171, and the Supplier Performance Risk System (SPRS), the three reference points you will return to throughout this guide.
Key Takeaways
CMMC 2.0 compliance hinges on disciplined scoping, complete documentation, and evidence that survives assessor scrutiny, not just a submitted SPRS score.
| Point | Details |
|---|---|
| Scope before you spend | Isolate CUI into a defined enclave to keep your assessed environment small and control costs. |
| Level 2 means 110 practices | Every Level 2 contractor must implement and document all 110 NIST SP 800-171 Rev 2 practices. |
| Documentation carries the assessment | Your SSP, POA&M, and evidence artifacts matter as much as the technical controls themselves. |
| Retention and affirmation are ongoing | Retain artifacts for six years and file annual affirmations between three-year self-assessment cycles. |
| Securetechie supports readiness | Securetechie offers gap assessments, SSP development, and managed monitoring to prepare Southern California contractors for C3PAO or self-assessment. |
Table of Contents
- What Is CMMC 2.0 and Why Does the DoD Require It?
- How Do You Determine Whether You Need Level 1, Level 2, or Level 3?
- What Do CMMC Level 2 Requirements Actually Cover?
- How Do You Scope the CMMC Assessment Correctly?
- What Documentation and Evidence Do Assessors Expect?
- Self-Assessment, C3PAO, or DIBCAC: Which Applies to You?
- Your Step-by-Step CMMC 2.0 Compliance Checklist
- What Scoping Lessons Actually Save You Money?
- What Changed Between CMMC 1.0 and CMMC 2.0?
- How Do You Maintain CMMC Compliance After Certification?
- How Secure Techies Supports Your CMMC Readiness
- Frequently Asked Questions
- Sources
What Is CMMC 2.0 and Why Does the DoD Require It?
The Cybersecurity Maturity Model Certification (CMMC) 2.0 exists because the Department of Defense got tired of contractors self-attesting to cybersecurity controls they never actually implemented. CMMC 2.0 verifies, through third-party or self-assessment, that companies handling Federal Contract Information (FCI) or CUI actually protect it. The program runs on three tiers: Level 1 for basic FCI protection, Level 2 for CUI protection aligned to federal standards, and Level 3 for the highest-risk CUI facing advanced persistent threats.
The legal foundation sits in 32 CFR Part 170, the CMMC final rule, alongside DoD-published guidance including the CMMC Model Overview and the assessment guides for each level. These documents are not optional reading. C3PAOs and self-assessors both use them as the literal scoring rubric.
CMMC ties directly into two NIST publications you will hear constantly:
- NIST SP 800-171 Rev 2 supplies the 110 practices that define Level 2.
- NIST SP 800-172 adds enhanced requirements used for Level 3, aimed at contractors facing nation-state level threats.
The CMMC Model Overview confirms Level 2 maps directly to those 110 NIST practices, organized into 14 control domains. That number, 110, is the figure every Level 2 contractor should have memorized. It is the finish line for your entire control implementation effort, which consists of the practices specified in NIST SP 800-171 Rev 2.
How Do You Determine Whether You Need Level 1, Level 2, or Level 3?
Your contract, not your ambition, decides your level. Read the Defense Federal Acquisition Regulation Supplement (DFARS) clauses in your solicitation or existing task order before assuming anything.
- Level 1 applies if you only handle FCI, information not intended for public release but not CUI either. Think basic contract details, not technical drawings or export-controlled data.
- Level 2 applies once you generate, store, or transmit CUI, which covers most subcontractors working on weapons systems, logistics data, or technical specifications.
- Level 3 applies to a small slice of contractors handling CUI tied to programs the DoD flags as high-value targets for foreign adversaries.
Primes frequently flow down Level 2 requirements to subcontractors even when the prime itself sits at a different tier, so a sub cannot assume its size or role exempts it from the full 110-practice requirement. If your contract touches CUI anywhere in the supply chain, expect the flow-down clause.
Pro Tip: Do not guess at your level from a vendor's marketing page. Pull the actual DFARS 252.204-7012 and CMMC clauses from your contract, and if the language is ambiguous, call your contracting officer directly. That five-minute conversation can save six figures in unnecessary Level 3 preparation.
What Do CMMC Level 2 Requirements Actually Cover?
Level 2 requirements are not a mystery. They are the 110 practices published in NIST SP 800-171 Rev 2, organized across 14 domains, and every one of them traces back to FAR 52.204-21 baseline protections plus the fuller NIST 800-171 set.
The security domains span various areas including Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

For most mid-size contractors, the heaviest lift concentrates in a handful of domains. Multi-factor authentication (MFA) under Access Control, centralized log retention under Audit and Accountability, and documented configuration baselines under Configuration Management typically eat the most implementation hours. Level 3 contractors add a further subset of controls drawn from NIST SP 800-172, which targets protections against advanced persistent threats rather than routine risk.
The 110-practice figure from the CMMC Model Overview is worth repeating here because it is the number that should drive your budget conversation, not a vague sense of "a lot of controls." Every practice needs an owner, an implementation, and an evidence artifact, and that arithmetic is what turns an abstract compliance mandate into a real project plan.
How Do You Scope the CMMC Assessment Correctly?
Scoping decides your cost more than any other single decision in this process. The CMMC Scoping Guide for Level 2 breaks your environment into five asset categories, and how you sort your systems into them determines how much of your network actually gets assessed.
- CUI Assets process, store, or transmit CUI directly and receive the full 110-practice assessment.
- Security Protection Assets provide security functions (firewalls, SIEM tools) for the CUI environment and get assessed against relevant practices.
- Contractor Risk Managed Assets could touch CUI but are managed through the organization's risk-based security policy rather than direct CUI handling.
- Specialized Assets include IoT devices, test equipment, or government-furnished equipment that need documented handling but face limited assessment.
- Out-of-Scope Assets never handle CUI and are physically or logically separated from anything that does.
Documenting the scope means producing an asset inventory and a network diagram that shows exactly how CUI flows through your environment. The Scoping Guide treats these two artifacts as non-negotiable evidence, and assessors will ask for them before they ask for anything else.
The practical move here is isolation. Segment CUI into a defined enclave, whether that is a virtual desktop environment, a separate VLAN, or a dedicated cloud tenant, so the rest of your network can plausibly sit in the Out-of-Scope category. If you use an External Service Provider (ESP) or Cloud Service Provider (CSP) to host or process CUI, that provider's own security posture becomes part of your assessment scope, so vet them the way partners like Seven's security and compliance resources recommend before you sign a services agreement.

Pro Tip: The most expensive scoping mistake is letting CUI touch your general business network "just this once" for convenience. One unsegmented file share can pull your entire domain into scope. Isolate first, document second, and exclude everything you can defend excluding.
What Documentation and Evidence Do Assessors Expect?
Your System Security Plan (SSP) is the master document assessors read first, and it needs to describe every in-scope asset, every implemented control, and how each of the 110 practices gets satisfied in your specific environment. The asset inventory and network diagram support the SSP, but they do not replace it. Assessors expect the SSP to read as a coherent narrative of your security posture, not a checkbox form.

Where controls are not yet fully implemented, a Plan of Action and Milestones (POA&M) tracks the gap and the remediation timeline. For Level 2 self-assessments, a Conditional status requires POA&M closeout within 180 days, and that clock starts the moment you submit your score to SPRS. Miss the window and your Conditional status can lapse.
Evidence expectations vary by domain, but a defensible package typically includes:
| Domain | Typical evidence artifact |
|---|---|
| Access Control | MFA configuration screenshots, access control lists |
| Audit and Accountability | Log retention policy, sample audit logs |
| Awareness and Training | Training completion records, curriculum outline |
| Configuration Management | Baseline configuration documents, change tickets |
| Incident Response | Incident response plan, tabletop exercise records |
| Risk Assessment | Vulnerability scan reports, risk register |
Retain every artifact for six years, a requirement spelled out directly in 32 CFR § 170.16, since DIBCAC or SPRS audits can reach back well past your original assessment date. An SPRS score by itself proves nothing to an assessor. The community-maintained checklist tracking practice common among compliance teams treats the score as the last step, not the deliverable, because a number with no supporting SSP or configuration baseline behind it collapses the moment anyone asks a follow-up question.
Pro Tip: Build your evidence folder structure around the 14 domains from day one, not around whatever document naming convention your IT team already uses. When a C3PAO assessor asks for Configuration Management evidence, you want to hand over a folder in ten seconds, not spend an afternoon searching shared drives.
Self-Assessment, C3PAO, or DIBCAC: Which Applies to You?
Level 2 contractors face a fork in the road: self-assessment or third-party certification through a C3PAO. Level 3 always requires a government-led review through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Which one you land on depends on contract language, not preference.
| Dimension | Level 2 self-assessment | Level 2 C3PAO certification | Level 3 DIBCAC |
|---|---|---|---|
| Who performs it | Your own designated affirming official | An accredited C3PAO assessor | Government DIBCAC assessors |
| Contract trigger | Contracts specifying Level 2 (Self) | Contracts specifying Level 2 (C3PAO) | Contracts specifying Level 3 |
| Evidence required | Full SSP, POA&M, artifacts | Full SSP, POA&M, artifacts, live testing | SSP plus NIST SP 800-172 enhanced evidence |
| Typical timeline | Weeks to a few months | Two to six months including scheduling | Several months, government-paced |
| Remediation option | POA&M with 180-day closeout | POA&M with defined closeout window | Limited POA&M allowance |
Assessors, whether internal for self-assessment or from a C3PAO, use the examine, interview, and test methods defined in NIST SP 800-171A. Examine means reviewing documents. Interview means talking to your staff about how a control actually works day to day. Test means watching the control function in real time, like confirming MFA actually blocks an unauthorized login attempt. Each assessment objective under a practice gets scored MET, NOT MET, or Not Applicable, and those individual scores roll up into your overall SPRS submission.
Level 2 self-assessments must be conducted and submitted to SPRS every three years, with an annual affirmation in between confirming your posture has not changed materially. Miss an affirmation and your certification status can be questioned even mid-cycle.
Your Step-by-Step CMMC 2.0 Compliance Checklist
This is the working document to hand your IT lead, compliance officer, or MSP. Assign owners immediately; a task with no owner is a task that does not get done.
Phase 1: Plan and scope
- Designate a CUI owner and an executive sponsor (Owner: Compliance Officer; Target: Week 1).
- Build the asset inventory across on-premises, cloud, and mobile endpoints (Owner: IT Lead; Target: Weeks 1 to 3).
- Draw the network diagram showing CUI flow and enclave boundaries (Owner: IT Lead or MSP; Target: Weeks 2 to 4).
- Confirm your CMMC level from contract language (Owner: Compliance Officer; Target: Week 1).
Phase 2: Document and evidence
- Draft the SSP covering all 110 practices for in-scope assets (Owner: Compliance Officer with MSP support; Target: Weeks 3 to 8).
- Stand up evidence folders by domain (Owner: IT Lead; Target: Week 4).
- Document ESP/CSP responsibilities in a shared responsibility matrix (Owner: IT Lead; Target: Week 5).
Phase 3: Implement controls
- Deploy MFA across all in-scope systems (Owner: IT Lead or MSP; Target: Weeks 4 to 6).
- Establish centralized logging and retention policy (Owner: IT Lead; Target: Weeks 5 to 7).
- Build configuration baselines and change control process (Owner: IT Lead; Target: Weeks 6 to 9).
- Run security awareness training for all staff touching CUI (Owner: HR with Compliance Officer; Target: Weeks 7 to 8).
- Update physical security controls at facilities storing CUI (Owner: Facilities; Target: Weeks 6 to 10).
Phase 4: Internal review
- Run a mock assessment against all 110 practices (Owner: Compliance Officer or MSP; Target: Weeks 10 to 12).
- Log every gap found in the POA&M with a remediation date (Owner: Compliance Officer; Target: Week 12).
Phase 5: Remediate and assess
- Close high-priority POA&M items before scheduling the real assessment (Owner: IT Lead; Target: Weeks 12 to 16).
- Engage a C3PAO if certification is required, or finalize the self-assessment package (Owner: Compliance Officer; Target: Weeks 14 to 20).
- Submit the score to SPRS and file the annual affirmation (Owner: Compliance Officer; Target: Week 20 onward).
Phase 6: Maintain
- Schedule quarterly control reviews and annual re-training (Owner: IT Lead and HR; Target: Ongoing).
| Phase | Primary owner | Support role | Target window |
|---|---|---|---|
| Plan and scope | Compliance Officer | IT Lead, MSP | Weeks 1 to 4 |
| Document and evidence | Compliance Officer | IT Lead, MSP | Weeks 3 to 8 |
| Implement controls | IT Lead | MSP, HR, Facilities | Weeks 4 to 10 |
| Internal review | Compliance Officer | MSP | Weeks 10 to 12 |
| Remediate and assess | Compliance Officer | IT Lead, C3PAO | Weeks 12 to 20 |
| Maintain | IT Lead | HR, Compliance Officer | Ongoing |
If you engage an MSP or C3PAO partway through, hand them the asset inventory, network diagram, and SSP draft first. Community-built resources like the open-source CMMC checklist repository can help structure the 110 practices into a taskable spreadsheet before that handoff, which saves your assessor from reconstructing your scope from scratch.
What Scoping Lessons Actually Save You Money?
Scoping is where the real budget conversation happens, and it is where most first-time Level 2 contractors overspend without realizing it. The DoD's own Scoping Guide exists precisely because unscoped assessments balloon in cost and duration.
A few things worth doing before you touch a single control:
- Map every entry point where CUI enters your organization, whether by email, file transfer, or a government portal.
- Isolate those entry points into a defined enclave rather than letting CUI mingle with general business traffic.
- Determine early whether your ESP or CSP will need to provide its own attestation or documentation for your assessment.
- Resist the urge to submit an SPRS score before your SSP and evidence package are actually complete.
Practitioner experience consistently shows that a poorly scoped environment does not just cost more. It also takes longer, because assessors flag gaps in the broader network that a well-scoped enclave would never have surfaced.
Pro Tip: Never submit to SPRS as a placeholder to "get it on record." A submitted score with no supporting SSP or evidence behind it is worse than no submission, because it invites scrutiny you cannot yet answer.
What Changed Between CMMC 1.0 and CMMC 2.0?
CMMC 2.0 replaced the original five-tier model with three levels, cutting a significant amount of assessment complexity contractors had complained about since the program's 2020 debut.
- Levels dropped from five to three, eliminating the maturity-process requirements unique to the old model.
- Level 2 now aligns directly and exclusively with the 110 NIST SP 800-171 practices, rather than a hybrid CMMC-specific control set.
- Self-assessment became a legitimate path for many Level 2 contracts, not just Level 1.
- POA&Ms are now explicitly allowed for Level 2, with defined closeout timelines, where CMMC 1.0 offered far less remediation flexibility.
| Factor | CMMC 1.0 | CMMC 2.0 |
|---|---|---|
| Number of levels | 5 | 3 |
| Level 2 practice source | Hybrid CMMC-specific set | NIST SP 800-171 Rev 2 (110 practices) |
| Assessment options | Third-party only for most levels | Self-assessment or C3PAO depending on contract |
| POA&M allowance | Very limited | Allowed with 180-day closeout for Conditional status |
How Do You Maintain CMMC Compliance After Certification?
Passing your assessment is not the finish line. Level 2 self-assessments require resubmission to SPRS every three years, plus an annual affirmation confirming your security posture has not degraded in between.
Build these into your standing operations:
- Continuous monitoring of the in-scope network, including automated alerting on configuration drift.
- Quarterly vulnerability scans with documented remediation.
- Log retention consistent with your Audit and Accountability policy.
- Annual security awareness refreshers for all staff with CUI access.
- Ongoing POA&M tracking for any control that regresses or a new gap that emerges.
- SSP updates whenever your environment changes, whether through a new vendor, a new office, or a system migration.
- Assign the IT lead or MSP to own monthly technical monitoring tasks.
- Assign the compliance officer to own the annual affirmation filing and the artifact retention schedule.
- Retain every artifact, log, and scan report for six years as required under 32 CFR § 170.16.
- Recheck your scope any time you add a system, vendor, or facility that could touch CUI.
A Practical Note From a Managed IT and Compliance Provider
Most contractors underestimate how much of CMMC readiness is organizational, not technical. Clients typically walk in assuming they need new firewalls, when what they actually need is a documented process nobody has written down yet. A structured engagement usually runs gap analysis first, then SSP construction, then control implementation, then a mock assessment before ever scheduling the real one. That order matters. Skipping the mock assessment is the single most common reason contractors get blindsided by findings they could have caught themselves.
How Secure Techies Supports Your CMMC Readiness
Securetechie works with Southern California defense contractors and subcontractors who need a compliance partner that understands both the technical controls and the documentation assessors actually scrutinize. Rather than handing you a generic controls list, Securetechie runs gap assessments against your specific 14 domains, builds out your SSP, collects and organizes evidence artifacts, and provides the managed monitoring and cybersecurity support that keeps your controls defensible long after the assessment ends.

If you are heading toward a C3PAO engagement or a Level 2 self-assessment deadline, Securetechie's compliance and security audit services cover the readiness work, including the network segmentation and infrastructure hardening a strong CMMC scope depends on through managed infrastructure services. Backed by a 99.9% uptime guarantee and a track record supporting HIPAA, SOC 2, and CMMC audits across Southern California, Securetechie's team knows what a C3PAO expects to see before the assessor ever asks. Book a readiness call to get your scoping and documentation gaps mapped before your next contract deadline forces the issue.
Frequently Asked Questions
What is the fastest way to start a CMMC compliance checklist? Start by identifying your CUI owner, building an asset inventory, and confirming your required level from your contract language, all in week one.
Does every subcontractor need Level 2 certification? Only if the sub generates, stores, or transmits CUI. Subs handling only Federal Contract Information typically need Level 1, though prime contractors can flow down higher requirements.
How long does a Level 2 self-assessment take? Timelines vary by organization size and existing control maturity, but most contractors need several weeks to a few months for documentation, remediation, and the assessment itself.
What happens if we submit to SPRS before our SSP is finished? A score with no supporting documentation invites scrutiny you cannot yet answer. Complete your SSP and evidence package before submitting.
Do we need a C3PAO for every Level 2 contract? No. Contract language determines whether a self-assessment or C3PAO certification is required for Level 2. Check your specific DFARS clauses.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Ecfr
- Cybersecurity Maturity Model Certification (CMMC) Model Overview | Version 2.13
- NIST Special Publication 800-172, Final
