CMMC 2.0 Compliance Checklist: What Defense Contractors Must Have Before Phase 2
A CMMC 2.0 compliance checklist for defense suppliers: scoping decisions, the 14 NIST SP 800-171 control families, the documents assessors open first, and the Phase 2 timeline.
This CMMC compliance checklist is built for the supplier who just received a flow-down letter from a prime, or who is reading a solicitation that carries DFARS 252.204-7021 for the first time. It covers the decisions that come before the 110 practices, the 14 control families the Level 2 assessment actually walks through, the documents an assessor opens first, and the timeline that decides whether you finish before your contract does. Save it, work through it in order, and hand it to whoever owns IT.
Before the checklist: three decisions that set the scope
- Which level does the contract require? Level 1 (Federal Contract Information only) is 17 practices and an annual self-assessment. Level 2 (Controlled Unclassified Information) is all 110 practices of NIST SP 800-171 and, for most contracts, a certification assessment by a CMMC Third-Party Assessment Organization (C3PAO). Level 3 adds NIST SP 800-172 and is assessed by the government. The contract sets the level; if you touch drawings, specifications, or technical data, plan on Level 2.
- Where does CUI actually live? Trace it from the prime’s portal or email, through engineering, quoting, the shop floor, and shipping. Every system in that path is in scope unless you deliberately move it out.
- Enclave or enterprise-wide? Scoping CUI to a defined enclave (a segmented network, Microsoft 365 GCC High, or a hosted environment) keeps the rest of the business out of the assessment. Most suppliers under 200 seats are better served by an enclave.
The CMMC Level 2 checklist: 14 control families
NIST SP 800-171 organizes its 110 practices into 14 families. The assessor scores every one of the 320 underlying objectives as met or not met. Use this table to find the families where suppliers most often fail.
| Family | Practices | What the assessor looks for | Common gap |
|---|---|---|---|
| Access Control (AC) | 22 | Least privilege, MFA on privileged and remote access, session controls, CUI flow control | Shared logins on shop-floor machines |
| Awareness & Training (AT) | 3 | Role-based security training with records, insider-threat awareness | No training records |
| Audit & Accountability (AU) | 9 | Centralized logs, retention, protected audit records, log review | Logs exist but nobody reviews them |
| Configuration Management (CM) | 9 | Baselines, change control, least functionality, software allow-listing | No documented baseline |
| Identification & Authentication (IA) | 11 | Unique IDs, MFA, password policy, replay-resistant authentication | MFA only on email |
| Incident Response (IR) | 3 | Tested IR plan, reporting path, DFARS 7012 72-hour reporting | Plan never exercised |
| Maintenance (MA) | 6 | Controlled maintenance, sanitized equipment, supervised remote maintenance | Vendor remote access unmonitored |
| Media Protection (MP) | 9 | CUI marking, encrypted removable media, sanitization before disposal | USB drives on the shop floor |
| Personnel Security (PS) | 2 | Screening before CUI access, offboarding procedures | Accounts survive terminations |
| Physical Protection (PE) | 6 | Visitor logs, escorting, physical access to CUI systems | No visitor control |
| Risk Assessment (RA) | 3 | Periodic risk assessment, vulnerability scanning, remediation | No scanning cadence |
| Security Assessment (CA) | 4 | System Security Plan, POA&M, periodic control assessment | SSP is a template, not a description |
| System & Communications Protection (SC) | 16 | Boundary protection, FIPS-validated encryption, network segmentation | Encryption not FIPS-validated |
| System & Information Integrity (SI) | 7 | Patching, malware protection, monitoring, alerting | Patches applied ad hoc |
The documents the assessor opens first
- System Security Plan (SSP). The narrative of how each of the 110 practices is implemented in your environment. A generic template with the company name changed is the single most common reason an assessment stalls on day one.
- Plan of Action and Milestones (POA&M). Only a limited set of lower-weighted practices may be open at assessment time, and they must close within 180 days. Any practice weighted three or five points must already be met.
- Network diagram and CUI data-flow diagram. Boundary, enclave, and every path CUI travels.
- Policies and procedures for every family, with evidence that they are followed: training records, change tickets, log reviews, visitor logs, vulnerability scan reports.
- SPRS score and affirmation. Your NIST SP 800-171 DoD Assessment Methodology score submitted to the Supplier Performance Risk System, affirmed annually by a senior official. A score submitted without the controls behind it is a False Claims Act exposure.
The timeline that matters
- November 10, 2025: the DFARS rule took effect. Phase 1 began: self-assessments required on new awards.
- November 10, 2026: Phase 2. Contracting officers can require C3PAO-certified Level 2 for CUI contracts. Primes are already flowing this down ahead of the date.
- November 10, 2027: Phase 3. Level 2 certification extends to option periods; Level 3 requirements begin.
- November 10, 2028: Phase 4. CMMC applies to all applicable solicitations and contracts.
A supplier starting from a typical commercial IT setup needs six to twelve months from gap assessment to assessment-ready, and C3PAO calendars fill months in advance. Counting back from Phase 2, the window to start is now.
Five mistakes that fail assessments
- Buying a compliance tool instead of building a program. A GRC platform tracks evidence; it does not create it.
- Treating the SPRS score as a goal. The score is a byproduct of implemented controls. Reporting 110 with open gaps is worse than reporting 70 honestly.
- Ignoring the shop floor. CNC controllers, CMMs, and engineering workstations hold CUI and rarely get patched, logged, or segmented.
- Using commercial cloud for CUI. DFARS 7012 requires FedRAMP Moderate or equivalent; ITAR data adds a US-persons requirement. Commercial Microsoft 365 does not satisfy either.
- Assuming the MSP is the assessor. No managed service provider certifies you. A managed security provider gets you assessment-ready and evidences the controls; an independent C3PAO conducts the certification assessment.
Working the checklist with a partner
For aerospace and defense suppliers in Los Angeles, Boom Logic delivers this as a program: CMMC compliance services that start with a gap assessment against all 110 practices and your current SPRS score, continue through remediation, the SSP and POA&M, and enclave design, and are sustained by a 24/7/365 SOC and Compliance as a Service with quarterly evidence refresh. Qualifying organizations with 25 or more staff or endpoints also receive a complimentary external penetration test and phishing simulation with their free security assessment, under a signed rules-of-engagement agreement.
Start with a free security assessment. You will get a NIST SP 800-171 gap snapshot and prioritized findings within one working day.
More from the blog. Security, infrastructure, and the business of IT.
What Is a Written Information Security Plan (WISP)? A Guide for Accounting and Tax Firms
A WISP is the FTC Safeguards Rule document every accounting and tax firm must keep. Here are the nine required elements, what the plan…
Read article →Cybersecurity for Law Firms: The 2026 Incident-Response Checklist
What cybersecurity for law firms requires in 2026: the ethics duties, the controls that matter, and a step-by-step incident-response checklist for partners.
Read article →Penetration Testing for Healthcare: What HIPAA Requires, What a Test Finds, and How Often to Run One
HIPAA doesn't name penetration testing today—the proposed Security Rule does. What a test finds in a healthcare environment, and how often to run one.
Read article →Have a question this article didn’t answer?
Talk to the engineers directly. Get a free security assessment and a clear, flat-rate plan from one accountable team.