A CMMC compliance checklist lists every security practice a Department of Defense (DoD) contractor must meet for Cybersecurity Maturity Model Certification (CMMC). That means 15 practices at Level 1 and 110 at Level 2, each tracked with a status, evidence, an owner, and a sign-off date.
Our free template below follows that structure, domain by domain. It also covers the three documents assessors review alongside it. Those are the System Security Plan (SSP), the Plan of Action and Milestones (POA&M), and your Supplier Performance Risk System (SPRS) score.
Work through it before you book an assessment. Every unmet practice costs SPRS points, and conditional Level 2 status needs at least 88 of 110.
Download your free CMMC compliance checklist
A fill-in checklist for CMMC Level 1 and Level 2, organized by domain. It covers CUI and FCI scope boundaries, required documentation, and assessment readiness.
Download templateKey takeaways
A CMMC compliance checklist tracks the 15 Level 1 practices and 110 Level 2 practices, grouped into 14 NIST SP 800-171 domains.
Level 1 protects Federal Contract Information (FCI), while Level 2 protects Controlled Unclassified Information (CUI).
The checklist must record scope boundaries, the SSP and POA&M, and whether you face a self-assessment or a C3PAO assessment.
Your SPRS score runs from -203 to 110, and conditional Level 2 status needs at least 88 with POA&M items closed within 180 days.
Level 1 allows no POA&M, so all 15 practices must be met before you affirm compliance in SPRS.
What is CMMC compliance, and why does a checklist matter?
CMMC compliance means meeting the Cybersecurity Maturity Model Certification rules for DoD contractors in the Defense Industrial Base (DIB). The Federal Register’s CMMC Program rule (32 CFR Part 170, effective December 16, 2024) sets three levels. Contracts start requiring them in phases.
A checklist turns those requirements into tasks you can assign and close. It keeps evidence organized and shows assessors that each control is deliberate. It also stops a contractor from discovering unmet practices during the assessment itself, when a contract award is on the line.
CMMC 2.0 framework: Three levels and 14 domains
CMMC 2.0 defines three levels. Level 1 and Level 2 already appear in DoD contracts. Level 3 (Expert) enters contracts later in the phased rollout.
What is a CMMC compliance checklist?
A CMMC compliance checklist is a structured table that lists every security practice CMMC 2.0 requires, organized by domain and level. It records that you assessed each control, documented its current state, and planned a fix for each unmet practice.
Your compliance program is the controls themselves. The checklist is the record assessors review to confirm those controls are intentional. It maps to NIST SP 800-171 Rev 2, the standard underpinning Level 2. It also maps to the Defense Federal Acquisition Regulation Supplement (DFARS 252.204-7021), which flows CMMC obligations into prime contracts.
How to fill out the checklist
Step 1: Define the assessment scope. Identify the systems, networks, and data flows that handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Document the boundary clearly so assessors know what is in scope.
Step 2: Assign responsibility. Give each practice a named owner in IT, security, or management. Record that owner on the checklist row, so every open item has someone accountable for closing it.
Step 3: Assess the current state. Mark each practice as met (✓), partially met (~), or not met (✗). Cite evidence such as screenshots, configuration files, policy documents, or audit logs. Assessors score only met or not met, so treat a partial as not met.
Step 4: Record unmet practices in the POA&M. Every practice that is not fully met gets a Plan of Action and Milestones (POA&M) entry. Record what is missing, why, when it will be fixed, and who owns the fix. At Level 1 the POA&M is a working tool only, because every practice must be met before you affirm.
Step 5: Prepare the documentation. Bundle the completed checklist with your System Security Plan (SSP), POA&M, and SPRS score. Post the score in the Supplier Performance Risk System before contract award if the contract carries the DFARS CMMC clause.
CMMC Level 1: 15 foundational practices
Level 1 protects Federal Contract Information (FCI) with 15 practices across six domains. They are the minimum baseline for any DoD contractor that handles FCI.
- Access Control (AC): Limit system access to authorized users and devices, and control what is posted on publicly accessible systems.
- Identification and Authentication (IA): Verify user and device identity before granting access, with unique user IDs and password standards.
- Media Protection (MP): Sanitize or destroy media that holds FCI, such as USB drives and hard drives, before disposal or reuse.
- Physical Protection (PE): Restrict physical access to facilities and equipment, escort visitors, and keep physical access logs.
- System and Communications Protection (SC): Monitor and control communications at system boundaries, and separate publicly accessible systems into their own subnetworks.
- System and Information Integrity (SI): Fix system flaws promptly, protect against malicious code, keep that protection updated, and run periodic and real-time scans.
A Level 1 checklist usually has one row per practice, with columns for current state, evidence, and sign-off date. Level 1 needs no third-party audit. A senior official still affirms compliance in SPRS every year, so the documentation has to hold up.
CMMC Level 2: 110 advanced practices
Level 2 protects Controlled Unclassified Information (CUI) with 110 practices across 14 domains, aligned to NIST SP 800-171. Certified Third-Party Assessment Organizations (C3PAOs) assess prioritized contracts. Other contracts allow a self-assessment.
Level 2 adds the remaining NIST SP 800-171 families on top of Level 1. These include audit logging, incident response, risk assessment, security awareness training, configuration management, and maintenance. A Level 2 checklist runs to several rows per domain, with detailed evidence and remediation deadlines tracked in the POA&M.
Critical Level 2 domains for first-time assessments
Access Control (AC): Least privilege and role-based access control (RBAC) for systems handling CUI, plus controlled remote access and session locks.
Audit and Accountability (AU): Logging of access to CUI, protected log retention, and regular log review for unauthorized access or anomalies.
Identification and Authentication (IA): Unique user identification, MFA, password complexity and reuse limits, and identifier management. Passwords are stored and sent only in cryptographically protected form.
System and Communications Protection (SC): Encryption of CUI in transit and at rest with FIPS-validated cryptography, secure wireless and remote access, and network boundary protections.
Required CMMC documentation: SSP, POA&M, and SPRS score
Beyond the checklist, your compliance package includes three documents.
System Security Plan (SSP). A narrative describing your system architecture, data flows, CUI boundaries, and how each practice is implemented. The SSP explains how each control works, and the checklist scores whether it is in place.
Plan of Action and Milestones (POA&M). Every practice not fully met goes here, with a remediation date, a responsible party, and a resource estimate. Assessors review it to judge whether open items will close on time.
SPRS score. You calculate a score from -203 to 110 and post it in the Supplier Performance Risk System before contract award. Conditional Level 2 status requires at least 88 of 110 (80%). Every open POA&M item must then close within 180 days.
How the SPRS score is calculated
Scoring starts at 110, and each unmet requirement subtracts its weight of 5, 3, or 1 points. The heaviest weights sit on requirements such as MFA and CUI encryption. That is why a contractor with a handful of misses can still fall below 88.
The weights also decide what may wait. Generally only 1-point requirements may sit on a POA&M at assessment, and a few of those are excluded too. The one larger exception is encryption that works but is not yet FIPS-validated. Rank open checklist items by weight, as the scale below shows how narrow the passing band is.

Which contractors need CMMC compliance?
Any organization in the Defense Industrial Base (DIB) that processes, stores, or transmits FCI or CUI on a DoD contract needs CMMC compliance. This includes:
- Prime contractors and subcontractors on defense contracts
- Organizations handling CUI (Controlled Unclassified Information) or FCI (Federal Contract Information)
- Defense suppliers in sectors such as aerospace, cybersecurity, and advanced manufacturing
- Managed service providers (MSPs) whose systems touch a contractor’s CUI
Holding only FCI still means Level 1, with an annual self-assessment and affirmation in SPRS. Contracts solely for commercially available off-the-shelf (COTS) items are exempt.
Common assessment findings and how to fix them
First-time assessments often turn up the same five problems.
Contractors that pass tie checklist completion to a phased remediation roadmap. They assign an owner to each finding and track closure in one shared system.
Building a CMMC readiness timeline
Months 1-2: Scope definition and kickoff. Define CUI and FCI boundaries, identify systems in scope, and assign compliance roles.
Months 2-3: Baseline assessment. Assess each CMMC practice against your checklist and document its current state. Log every unmet practice in the POA&M.
Months 3-8: Remediation and control implementation. Run remediation work in parallel, such as MFA rollout, encryption, and policy updates. Update checklist status monthly.
Months 8-10: Evidence collection and documentation. Gather proof that controls are in place, such as screenshots, policies, audit logs, and configuration files. Then finalize the SSP.
Months 10-11: Pre-assessment review (Level 2 only). If you need a C3PAO assessment, run a mock assessment or bring in a consultant for a readiness review.
Month 12: Final assessment and SPRS submission. Complete the self-assessment or C3PAO assessment, calculate your SPRS score, and post it in the Supplier Performance Risk System.
Timelines vary with organization size, current maturity, and remediation complexity. A mature contractor with strong IT practices may finish in 6-9 months. A new entrant or one with legacy systems may need 12-18 months.
Expert guidance before your assessment
Understand your regulatory baseline. Read the Federal Register’s CMMC Program rule (32 CFR Part 170) to confirm your obligations and phase-in dates.
Start with a scope workshop. Bring together IT, security, legal, and business teams to define which systems handle CUI or FCI. Scope sets your assessment size, timeline, and resource needs.
Reuse evidence from other audits. If you also complete a Sarbanes-Oxley compliance checklist, its access reviews and logging evidence can support several CMMC rows.
Use the free Cyber AB resource library. The CMMC Accreditation Body publishes guidance documents and practice domains on its website at no cost.
How Pabau keeps checklist records and sign-offs in one place
Many contractors start the checklist in a spreadsheet and chase sign-offs by email. Evidence then ends up split across inboxes and shared drives, and proving which version is current takes work.
Pabau, the practice management platform we build, includes a digital form builder as part of its compliance tools for practices. You can rebuild the checklist as a fillable form, add a signature field for each owner, and keep every completed copy in one searchable place.
That suits medical practices that also hold DoD contracts and want compliance paperwork in the system they already use. Keep CUI itself inside the boundary your SSP defines, and use Pabau for the checklist and its sign-offs.

Book a demo to see how Pabau’s digital forms keep checklist records and signed acknowledgments together.
Keep checklist records and sign-offs together
Pabau’s digital forms let your team complete the checklist, collect signatures from each owner, and keep every completed copy in one searchable place.
Conclusion
Start with scope, because it decides how many practices you must evidence and how large the assessment gets. Then score the checklist the way an assessor will, with every partial counted as not met.
Work the POA&M by point weight. Clearing 5-point items first protects the 88-point threshold and keeps conditional status within reach. The trade-off is time, since a new entrant may need 12-18 months to close the list.
If you run a medical practice alongside defense work, keep that paperwork in one system. Book a demo to see how Pabau’s digital forms hold your checklist sign-offs next to your practice records.
Continue your research
Answering to more than one framework? Sarbanes-Oxley (SOX) compliance checklist lays out the controls, tests, and sign-offs auditors expect under SOX.
Handling patient data as well as CUI? HIPAA risk assessment walks through documenting the risks to electronic health information.
Hardening clinical systems too? EHR security covers access control, encryption, and the safeguards HIPAA requires for health records.
Need a way to log security incidents? Incident report form gives you a standard format for documenting incidents and follow-up.
Frequently asked questions
What is CMMC compliance?
CMMC (Cybersecurity Maturity Model Certification) is a mandatory framework for Department of Defense contractors in the Defense Industrial Base who handle controlled information. It defines three levels of security maturity, with Level 1 protecting Federal Contract Information and Level 2 protecting Controlled Unclassified Information under NIST SP 800-171.
Do all DoD contractors need CMMC certification?
Almost all do. Any organization in the Defense Industrial Base (DIB) that handles CUI or FCI under a DoD contract must comply. DFARS clause 252.204-7021 writes that requirement into contracts. Contracts solely for commercially available off-the-shelf (COTS) items are exempt.
What is the difference between Level 1 and Level 2 CMMC?
Level 1 covers 15 foundational practices protecting Federal Contract Information (FCI) and allows annual self-assessment. Level 2 covers 110 advanced practices protecting Controlled Unclassified Information (CUI). Prioritized contracts need a C3PAO assessment, and other contracts allow a self-assessment.
How long does CMMC certification take?
Expect roughly 6-18 months, depending on maturity. A mature contractor may finish in 6-9 months, while a new entrant or one with legacy systems may need 12-18. These are planning estimates, not regulatory deadlines. They cover scope definition, baseline assessment, control implementation, evidence collection, and final assessment.
What is the relationship between CMMC and NIST SP 800-171?
CMMC 2.0 Level 2 practices map directly to NIST SP 800-171 Rev 2, the NIST standard for protecting Controlled Unclassified Information. Level 2 requires all 110 NIST practices. The CMMC framework adds assessment and certification on top of the NIST standard.
Who conducts CMMC Level 2 assessments?
Certified Third-Party Assessment Organizations (C3PAOs), accredited by the CMMC Accreditation Body (Cyber AB), conduct Level 2 assessments on prioritized DoD contracts. Non-prioritized contracts may use self-assessment. C3PAOs are independent auditors trained to evaluate CMMC practices against NIST controls.
What happens if a contractor fails a CMMC assessment?
A failed assessment means practices are not fully implemented. A score of at least 88 of 110 earns conditional status. The contractor then has up to 180 days to close POA&M items in a closeout assessment. Below that, the contractor must remediate and reassess. Contract opportunities may be delayed or lost if certification is not achieved in time.