Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
☰
Compliance and security

CMMC compliance checklist

Avatar photo Maja Popovska
Last Updated: October 6, 2026

A CMMC compliance checklist lists every security practice a Department of Defense (DoD) contractor must meet for Cybersecurity Maturity Model Certification (CMMC). That means 15 practices at Level 1 and 110 at Level 2, each tracked with a status, evidence, an owner, and a sign-off date.

Our free template below follows that structure, domain by domain. It also covers the three documents assessors review alongside it. Those are the System Security Plan (SSP), the Plan of Action and Milestones (POA&M), and your Supplier Performance Risk System (SPRS) score.

Work through it before you book an assessment. Every unmet practice costs SPRS points, and conditional Level 2 status needs at least 88 of 110.

Found our content helpful?

Download your free CMMC compliance checklist

A fill-in checklist for CMMC Level 1 and Level 2, organized by domain. It covers CUI and FCI scope boundaries, required documentation, and assessment readiness.

Download template
Key takeaways

Key takeaways

A CMMC compliance checklist tracks the 15 Level 1 practices and 110 Level 2 practices, grouped into 14 NIST SP 800-171 domains.

Level 1 protects Federal Contract Information (FCI), while Level 2 protects Controlled Unclassified Information (CUI).

The checklist must record scope boundaries, the SSP and POA&M, and whether you face a self-assessment or a C3PAO assessment.

Your SPRS score runs from -203 to 110, and conditional Level 2 status needs at least 88 with POA&M items closed within 180 days.

Level 1 allows no POA&M, so all 15 practices must be met before you affirm compliance in SPRS.

What is CMMC compliance, and why does a checklist matter?

CMMC compliance means meeting the Cybersecurity Maturity Model Certification rules for DoD contractors in the Defense Industrial Base (DIB). The Federal Register’s CMMC Program rule (32 CFR Part 170, effective December 16, 2024) sets three levels. Contracts start requiring them in phases.

A checklist turns those requirements into tasks you can assign and close. It keeps evidence organized and shows assessors that each control is deliberate. It also stops a contractor from discovering unmet practices during the assessment itself, when a contract award is on the line.

CMMC 2.0 framework: Three levels and 14 domains

CMMC 2.0 defines three levels. Level 1 and Level 2 already appear in DoD contracts. Level 3 (Expert) enters contracts later in the phased rollout.

Level Scope Practices Assessment type
Level 1 Foundational (FCI) 15 practices across 6 domains Annual self-assessment
Level 2 Advanced (CUI) 110 practices across 14 domains C3PAO third-party assessment, or self-assessment (depends on the contract)
Level 3 Expert (CUI, higher-priority programs; NIST SP 800-172 subset) Level 2 practices plus a subset of NIST SP 800-172 DoD assessment by DIBCAC

What is a CMMC compliance checklist?

A CMMC compliance checklist is a structured table that lists every security practice CMMC 2.0 requires, organized by domain and level. It records that you assessed each control, documented its current state, and planned a fix for each unmet practice.

Your compliance program is the controls themselves. The checklist is the record assessors review to confirm those controls are intentional. It maps to NIST SP 800-171 Rev 2, the standard underpinning Level 2. It also maps to the Defense Federal Acquisition Regulation Supplement (DFARS 252.204-7021), which flows CMMC obligations into prime contracts.

How to fill out the checklist

Step 1: Define the assessment scope. Identify the systems, networks, and data flows that handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Document the boundary clearly so assessors know what is in scope.

Step 2: Assign responsibility. Give each practice a named owner in IT, security, or management. Record that owner on the checklist row, so every open item has someone accountable for closing it.

Step 3: Assess the current state. Mark each practice as met (✓), partially met (~), or not met (✗). Cite evidence such as screenshots, configuration files, policy documents, or audit logs. Assessors score only met or not met, so treat a partial as not met.

Step 4: Record unmet practices in the POA&M. Every practice that is not fully met gets a Plan of Action and Milestones (POA&M) entry. Record what is missing, why, when it will be fixed, and who owns the fix. At Level 1 the POA&M is a working tool only, because every practice must be met before you affirm.

Step 5: Prepare the documentation. Bundle the completed checklist with your System Security Plan (SSP), POA&M, and SPRS score. Post the score in the Supplier Performance Risk System before contract award if the contract carries the DFARS CMMC clause.

CMMC Level 1: 15 foundational practices

Level 1 protects Federal Contract Information (FCI) with 15 practices across six domains. They are the minimum baseline for any DoD contractor that handles FCI.

  • Access Control (AC): Limit system access to authorized users and devices, and control what is posted on publicly accessible systems.
  • Identification and Authentication (IA): Verify user and device identity before granting access, with unique user IDs and password standards.
  • Media Protection (MP): Sanitize or destroy media that holds FCI, such as USB drives and hard drives, before disposal or reuse.
  • Physical Protection (PE): Restrict physical access to facilities and equipment, escort visitors, and keep physical access logs.
  • System and Communications Protection (SC): Monitor and control communications at system boundaries, and separate publicly accessible systems into their own subnetworks.
  • System and Information Integrity (SI): Fix system flaws promptly, protect against malicious code, keep that protection updated, and run periodic and real-time scans.

A Level 1 checklist usually has one row per practice, with columns for current state, evidence, and sign-off date. Level 1 needs no third-party audit. A senior official still affirms compliance in SPRS every year, so the documentation has to hold up.

CMMC Level 2: 110 advanced practices

Level 2 protects Controlled Unclassified Information (CUI) with 110 practices across 14 domains, aligned to NIST SP 800-171. Certified Third-Party Assessment Organizations (C3PAOs) assess prioritized contracts. Other contracts allow a self-assessment.

Level 2 adds the remaining NIST SP 800-171 families on top of Level 1. These include audit logging, incident response, risk assessment, security awareness training, configuration management, and maintenance. A Level 2 checklist runs to several rows per domain, with detailed evidence and remediation deadlines tracked in the POA&M.

Critical Level 2 domains for first-time assessments

Access Control (AC): Least privilege and role-based access control (RBAC) for systems handling CUI, plus controlled remote access and session locks.

Audit and Accountability (AU): Logging of access to CUI, protected log retention, and regular log review for unauthorized access or anomalies.

Identification and Authentication (IA): Unique user identification, MFA, password complexity and reuse limits, and identifier management. Passwords are stored and sent only in cryptographically protected form.

System and Communications Protection (SC): Encryption of CUI in transit and at rest with FIPS-validated cryptography, secure wireless and remote access, and network boundary protections.

Required CMMC documentation: SSP, POA&M, and SPRS score

Beyond the checklist, your compliance package includes three documents.

System Security Plan (SSP). A narrative describing your system architecture, data flows, CUI boundaries, and how each practice is implemented. The SSP explains how each control works, and the checklist scores whether it is in place.

Plan of Action and Milestones (POA&M). Every practice not fully met goes here, with a remediation date, a responsible party, and a resource estimate. Assessors review it to judge whether open items will close on time.

SPRS score. You calculate a score from -203 to 110 and post it in the Supplier Performance Risk System before contract award. Conditional Level 2 status requires at least 88 of 110 (80%). Every open POA&M item must then close within 180 days.

How the SPRS score is calculated

Scoring starts at 110, and each unmet requirement subtracts its weight of 5, 3, or 1 points. The heaviest weights sit on requirements such as MFA and CUI encryption. That is why a contractor with a handful of misses can still fall below 88.

The weights also decide what may wait. Generally only 1-point requirements may sit on a POA&M at assessment, and a few of those are excluded too. The one larger exception is encryption that works but is not yet FIPS-validated. Rank open checklist items by weight, as the scale below shows how narrow the passing band is.

SPRS score scale for CMMC Level 2 running from -203 to 110: below 88 is not eligible for conditional status, 88 to 109 is conditional Level 2 with POA&M items closed within 180 days, and 110 is final Level 2 with all 110 requirements met. Each unmet requirement subtracts 5, 3 or 1 points.
Only 22 points separate a perfect score from losing conditional status, so a few 5-point misses decide the outcome. Figures from 32 CFR Part 170 and the DoD Assessment Methodology.

Which contractors need CMMC compliance?

Any organization in the Defense Industrial Base (DIB) that processes, stores, or transmits FCI or CUI on a DoD contract needs CMMC compliance. This includes:

  • Prime contractors and subcontractors on defense contracts
  • Organizations handling CUI (Controlled Unclassified Information) or FCI (Federal Contract Information)
  • Defense suppliers in sectors such as aerospace, cybersecurity, and advanced manufacturing
  • Managed service providers (MSPs) whose systems touch a contractor’s CUI

Holding only FCI still means Level 1, with an annual self-assessment and affirmation in SPRS. Contracts solely for commercially available off-the-shelf (COTS) items are exempt.

Common assessment findings and how to fix them

First-time assessments often turn up the same five problems.

Finding Why it happens Remediation
Missing MFA on admin accounts MFA deployment takes effort, and some admins resist new login steps. Implement MFA on all privileged accounts, using authenticator apps or hardware keys. Timeline: 4-8 weeks depending on vendor support.
Incomplete audit logging Logging is enabled, but logs are not centralized or reviewed regularly. Deploy a SIEM or centralized log management system. Set up automated alerts for suspicious access. Timeline: 6-12 weeks.
Unencrypted data in transit or at rest Legacy systems may not support modern encryption, and the fix often lacks urgency. Move to FIPS-validated encryption for storage and TLS 1.2 or higher for network traffic. Timeline: 8-16 weeks.
No formal SSP or an outdated SSP SSP writing is manual and sits apart from day-to-day operations. Assign a security lead to draft the SSP from your completed checklist, then review it with IT. Timeline: 4-6 weeks.
Weak access control policies Access is granted on request but not reviewed, so stale accounts pile up. Implement role-based access control (RBAC), run quarterly access reviews, and document approval workflows. Timeline: 6-10 weeks.

Contractors that pass tie checklist completion to a phased remediation roadmap. They assign an owner to each finding and track closure in one shared system.

Building a CMMC readiness timeline

Months 1-2: Scope definition and kickoff. Define CUI and FCI boundaries, identify systems in scope, and assign compliance roles.

Months 2-3: Baseline assessment. Assess each CMMC practice against your checklist and document its current state. Log every unmet practice in the POA&M.

Months 3-8: Remediation and control implementation. Run remediation work in parallel, such as MFA rollout, encryption, and policy updates. Update checklist status monthly.

Months 8-10: Evidence collection and documentation. Gather proof that controls are in place, such as screenshots, policies, audit logs, and configuration files. Then finalize the SSP.

Months 10-11: Pre-assessment review (Level 2 only). If you need a C3PAO assessment, run a mock assessment or bring in a consultant for a readiness review.

Month 12: Final assessment and SPRS submission. Complete the self-assessment or C3PAO assessment, calculate your SPRS score, and post it in the Supplier Performance Risk System.

Timelines vary with organization size, current maturity, and remediation complexity. A mature contractor with strong IT practices may finish in 6-9 months. A new entrant or one with legacy systems may need 12-18 months.

Expert guidance before your assessment

Understand your regulatory baseline. Read the Federal Register’s CMMC Program rule (32 CFR Part 170) to confirm your obligations and phase-in dates.

Start with a scope workshop. Bring together IT, security, legal, and business teams to define which systems handle CUI or FCI. Scope sets your assessment size, timeline, and resource needs.

Reuse evidence from other audits. If you also complete a Sarbanes-Oxley compliance checklist, its access reviews and logging evidence can support several CMMC rows.

Use the free Cyber AB resource library. The CMMC Accreditation Body publishes guidance documents and practice domains on its website at no cost.

How Pabau keeps checklist records and sign-offs in one place

Many contractors start the checklist in a spreadsheet and chase sign-offs by email. Evidence then ends up split across inboxes and shared drives, and proving which version is current takes work.

Pabau, the practice management platform we build, includes a digital form builder as part of its compliance tools for practices. You can rebuild the checklist as a fillable form, add a signature field for each owner, and keep every completed copy in one searchable place.

That suits medical practices that also hold DoD contracts and want compliance paperwork in the system they already use. Keep CUI itself inside the boundary your SSP defines, and use Pabau for the checklist and its sign-offs.

Pabau form builder showing a template library and a blank form option
Pabau’s form builder starts from a blank template or 500-plus formats, so you can rebuild this checklist as a signed digital form.

Book a demo to see how Pabau’s digital forms keep checklist records and signed acknowledgments together.

Keep checklist records and sign-offs together

Pabau’s digital forms let your team complete the checklist, collect signatures from each owner, and keep every completed copy in one searchable place.

Pabau practice management dashboard

Conclusion

Start with scope, because it decides how many practices you must evidence and how large the assessment gets. Then score the checklist the way an assessor will, with every partial counted as not met.

Work the POA&M by point weight. Clearing 5-point items first protects the 88-point threshold and keeps conditional status within reach. The trade-off is time, since a new entrant may need 12-18 months to close the list.

If you run a medical practice alongside defense work, keep that paperwork in one system. Book a demo to see how Pabau’s digital forms hold your checklist sign-offs next to your practice records.

Continue your research

Continue your research

Answering to more than one framework? Sarbanes-Oxley (SOX) compliance checklist lays out the controls, tests, and sign-offs auditors expect under SOX.

Handling patient data as well as CUI? HIPAA risk assessment walks through documenting the risks to electronic health information.

Hardening clinical systems too? EHR security covers access control, encryption, and the safeguards HIPAA requires for health records.

Need a way to log security incidents? Incident report form gives you a standard format for documenting incidents and follow-up.

Frequently asked questions

What is CMMC compliance?

CMMC (Cybersecurity Maturity Model Certification) is a mandatory framework for Department of Defense contractors in the Defense Industrial Base who handle controlled information. It defines three levels of security maturity, with Level 1 protecting Federal Contract Information and Level 2 protecting Controlled Unclassified Information under NIST SP 800-171.

Do all DoD contractors need CMMC certification?

Almost all do. Any organization in the Defense Industrial Base (DIB) that handles CUI or FCI under a DoD contract must comply. DFARS clause 252.204-7021 writes that requirement into contracts. Contracts solely for commercially available off-the-shelf (COTS) items are exempt.

What is the difference between Level 1 and Level 2 CMMC?

Level 1 covers 15 foundational practices protecting Federal Contract Information (FCI) and allows annual self-assessment. Level 2 covers 110 advanced practices protecting Controlled Unclassified Information (CUI). Prioritized contracts need a C3PAO assessment, and other contracts allow a self-assessment.

How long does CMMC certification take?

Expect roughly 6-18 months, depending on maturity. A mature contractor may finish in 6-9 months, while a new entrant or one with legacy systems may need 12-18. These are planning estimates, not regulatory deadlines. They cover scope definition, baseline assessment, control implementation, evidence collection, and final assessment.

What is the relationship between CMMC and NIST SP 800-171?

CMMC 2.0 Level 2 practices map directly to NIST SP 800-171 Rev 2, the NIST standard for protecting Controlled Unclassified Information. Level 2 requires all 110 NIST practices. The CMMC framework adds assessment and certification on top of the NIST standard.

Who conducts CMMC Level 2 assessments?

Certified Third-Party Assessment Organizations (C3PAOs), accredited by the CMMC Accreditation Body (Cyber AB), conduct Level 2 assessments on prioritized DoD contracts. Non-prioritized contracts may use self-assessment. C3PAOs are independent auditors trained to evaluate CMMC practices against NIST controls.

What happens if a contractor fails a CMMC assessment?

A failed assessment means practices are not fully implemented. A score of at least 88 of 110 earns conditional status. The contractor then has up to 180 days to close POA&M items in a closeout assessment. Below that, the contractor must remediate and reassess. Contract opportunities may be delayed or lost if certification is not achieved in time.

Found our content helpful?
×