Boom Logic

Boom Logic

Boom Logic

Blog··5 min read

CMMC 2.0 Compliance Checklist: What Defense Contractors Must Have Before Phase 2

A CMMC 2.0 compliance checklist for defense suppliers: scoping decisions, the 14 NIST SP 800-171 control families, the documents assessors open first, and the Phase 2 timeline.

This CMMC compliance checklist is built for the supplier who just received a flow-down letter from a prime, or who is reading a solicitation that carries DFARS 252.204-7021 for the first time. It covers the decisions that come before the 110 practices, the 14 control families the Level 2 assessment actually walks through, the documents an assessor opens first, and the timeline that decides whether you finish before your contract does. Save it, work through it in order, and hand it to whoever owns IT.

Before the checklist: three decisions that set the scope

  1. Which level does the contract require? Level 1 (Federal Contract Information only) is 17 practices and an annual self-assessment. Level 2 (Controlled Unclassified Information) is all 110 practices of NIST SP 800-171 and, for most contracts, a certification assessment by a CMMC Third-Party Assessment Organization (C3PAO). Level 3 adds NIST SP 800-172 and is assessed by the government. The contract sets the level; if you touch drawings, specifications, or technical data, plan on Level 2.
  2. Where does CUI actually live? Trace it from the prime’s portal or email, through engineering, quoting, the shop floor, and shipping. Every system in that path is in scope unless you deliberately move it out.
  3. Enclave or enterprise-wide? Scoping CUI to a defined enclave (a segmented network, Microsoft 365 GCC High, or a hosted environment) keeps the rest of the business out of the assessment. Most suppliers under 200 seats are better served by an enclave.

The CMMC Level 2 checklist: 14 control families

NIST SP 800-171 organizes its 110 practices into 14 families. The assessor scores every one of the 320 underlying objectives as met or not met. Use this table to find the families where suppliers most often fail.

FamilyPracticesWhat the assessor looks forCommon gap
Access Control (AC)22Least privilege, MFA on privileged and remote access, session controls, CUI flow controlShared logins on shop-floor machines
Awareness & Training (AT)3Role-based security training with records, insider-threat awarenessNo training records
Audit & Accountability (AU)9Centralized logs, retention, protected audit records, log reviewLogs exist but nobody reviews them
Configuration Management (CM)9Baselines, change control, least functionality, software allow-listingNo documented baseline
Identification & Authentication (IA)11Unique IDs, MFA, password policy, replay-resistant authenticationMFA only on email
Incident Response (IR)3Tested IR plan, reporting path, DFARS 7012 72-hour reportingPlan never exercised
Maintenance (MA)6Controlled maintenance, sanitized equipment, supervised remote maintenanceVendor remote access unmonitored
Media Protection (MP)9CUI marking, encrypted removable media, sanitization before disposalUSB drives on the shop floor
Personnel Security (PS)2Screening before CUI access, offboarding proceduresAccounts survive terminations
Physical Protection (PE)6Visitor logs, escorting, physical access to CUI systemsNo visitor control
Risk Assessment (RA)3Periodic risk assessment, vulnerability scanning, remediationNo scanning cadence
Security Assessment (CA)4System Security Plan, POA&M, periodic control assessmentSSP is a template, not a description
System & Communications Protection (SC)16Boundary protection, FIPS-validated encryption, network segmentationEncryption not FIPS-validated
System & Information Integrity (SI)7Patching, malware protection, monitoring, alertingPatches applied ad hoc

The documents the assessor opens first

  • System Security Plan (SSP). The narrative of how each of the 110 practices is implemented in your environment. A generic template with the company name changed is the single most common reason an assessment stalls on day one.
  • Plan of Action and Milestones (POA&M). Only a limited set of lower-weighted practices may be open at assessment time, and they must close within 180 days. Any practice weighted three or five points must already be met.
  • Network diagram and CUI data-flow diagram. Boundary, enclave, and every path CUI travels.
  • Policies and procedures for every family, with evidence that they are followed: training records, change tickets, log reviews, visitor logs, vulnerability scan reports.
  • SPRS score and affirmation. Your NIST SP 800-171 DoD Assessment Methodology score submitted to the Supplier Performance Risk System, affirmed annually by a senior official. A score submitted without the controls behind it is a False Claims Act exposure.

The timeline that matters

  • November 10, 2025: the DFARS rule took effect. Phase 1 began: self-assessments required on new awards.
  • November 10, 2026: Phase 2. Contracting officers can require C3PAO-certified Level 2 for CUI contracts. Primes are already flowing this down ahead of the date.
  • November 10, 2027: Phase 3. Level 2 certification extends to option periods; Level 3 requirements begin.
  • November 10, 2028: Phase 4. CMMC applies to all applicable solicitations and contracts.

A supplier starting from a typical commercial IT setup needs six to twelve months from gap assessment to assessment-ready, and C3PAO calendars fill months in advance. Counting back from Phase 2, the window to start is now.

Five mistakes that fail assessments

  1. Buying a compliance tool instead of building a program. A GRC platform tracks evidence; it does not create it.
  2. Treating the SPRS score as a goal. The score is a byproduct of implemented controls. Reporting 110 with open gaps is worse than reporting 70 honestly.
  3. Ignoring the shop floor. CNC controllers, CMMs, and engineering workstations hold CUI and rarely get patched, logged, or segmented.
  4. Using commercial cloud for CUI. DFARS 7012 requires FedRAMP Moderate or equivalent; ITAR data adds a US-persons requirement. Commercial Microsoft 365 does not satisfy either.
  5. Assuming the MSP is the assessor. No managed service provider certifies you. A managed security provider gets you assessment-ready and evidences the controls; an independent C3PAO conducts the certification assessment.

Working the checklist with a partner

For aerospace and defense suppliers in Los Angeles, Boom Logic delivers this as a program: CMMC compliance services that start with a gap assessment against all 110 practices and your current SPRS score, continue through remediation, the SSP and POA&M, and enclave design, and are sustained by a 24/7/365 SOC and Compliance as a Service with quarterly evidence refresh. Qualifying organizations with 25 or more staff or endpoints also receive a complimentary external penetration test and phishing simulation with their free security assessment, under a signed rules-of-engagement agreement.

Start with a free security assessment. You will get a NIST SP 800-171 gap snapshot and prioritized findings within one working day.

Keep Reading

More from the blog. Security, infrastructure, and the business of IT.

All articles →
Ready When You Are

Have a question this article didn’t answer?

Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.