CMMC Compliance Checklist
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires contractors handling federal contract information or controlled unclassified information to certify their cybersecurity. The checklist runs: determine your required level, scope where CUI lives, run a gap assessment against NIST 800-171, implement the controls, document an SSP and POA&M, train staff, then complete a self-assessment or a C3PAO assessment depending on level.

- CMMC is required for DoD contractors that handle federal contract information or controlled unclassified information (CUI).
- Determine which level you need (1, 2, or 3); most CUI handlers need Level 2.
- The core work is closing gaps against the 110 controls of NIST SP 800-171.
- You must document a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M).
- Level 1 is self-assessed; most Level 2 requires a third-party (C3PAO) assessment.
What is CMMC?
CMMC, the Cybersecurity Maturity Model Certification, is the U.S. Department of Defense program that requires companies in the defense supply chain to prove they protect sensitive government information. If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on a DoD contract, you will need to meet a CMMC level to win and keep that work. It exists because the defense supply chain has been a persistent target for nation-state attackers, and the DoD needs assurance that its contractors, especially the many small and midsize ones, are actually securing the data they handle.
For affected contractors, CMMC is not optional, it is a condition of doing business with the DoD, and the cost of a breach in this space is severe, with the average data breach reaching $4.88 million and reported cybercrime losses topping $12.5 billion in a single year. This guide is a practical checklist for getting to compliance. It pairs with our CMMC compliance services and IT compliance services overviews.
Step 1: Determine the CMMC level you need
CMMC has three levels, and your required level depends on the type of information you handle, which is specified in your contract:

- Level 1 (Foundational). For contractors handling only Federal Contract Information (FCI). Covers basic safeguarding and is self-assessed annually.
- Level 2 (Advanced). For contractors handling Controlled Unclassified Information (CUI). Aligns with the 110 controls of NIST SP 800-171, and most Level 2 work requires a third-party assessment.
- Level 3 (Expert). For the highest-priority programs and the most sensitive information, building on Level 2 with additional requirements and a government-led assessment.
Most contractors that touch CUI need Level 2, so identifying your level correctly, from your contract requirements, is the essential first step that scopes everything else.
Step 2: Scope where CUI lives
Before assessing controls, map exactly where the protected information (FCI or CUI) is stored, processed, and transmitted across your systems, people, and facilities. This scoping defines your assessment boundary, everything that touches CUI is in scope and must meet the requirements. Done well, scoping can dramatically reduce your compliance burden, because you can isolate CUI into a defined environment (an enclave) rather than having to secure your entire business to CMMC standards. Getting scope right is one of the highest-leverage decisions in the whole process, both for cost and for passing the assessment.
Step 3: Run a gap assessment against NIST 800-171
For Level 2, the substance of CMMC is the 110 security controls of NIST SP 800-171, covering access control, awareness and training, audit and accountability, configuration management, incident response, and more. Conduct a gap assessment: measure your current security against each of these controls and document where you fall short. This produces your roadmap, the specific gaps you must close, and feeds the scoring the DoD uses. An honest, thorough gap assessment is the foundation; underestimating gaps here is how organizations fail their formal assessment later.
Step 4: Implement the controls
Close the gaps by implementing the required controls. This is the bulk of the work and spans technology and process: multi-factor authentication, access controls and least privilege, encryption of CUI at rest and in transit, audit logging, configuration hardening, vulnerability management, incident response capability, and more. People matter as much as technology here, since the human element features in 68 percent of breaches, so security training is a required control, not an optional extra. Implementation is where most of the time and budget goes, and where a defense-experienced IT partner adds the most value.

Step 5: Document an SSP and POA&M
CMMC requires specific documentation, and it is not optional paperwork, it is assessed. The System Security Plan (SSP) describes your environment and how you meet each control; it is a central document an assessor will scrutinize. The Plan of Action and Milestones (POA&M) documents any controls not yet fully met and your concrete plan and timeline to remediate them. Note that for full Level 2 certification, critical controls generally cannot be left on a POA&M, so plan to close the most important gaps before assessment. Maintaining accurate, current documentation is itself part of demonstrating a mature security program.
Step 6: Get assessed and certified
The final step depends on your level. Level 1 and a subset of Level 2 are self-assessed and affirmed annually by your company, with results submitted to the DoD's system. Most Level 2 requires a formal assessment by a Certified Third-Party Assessment Organization (C3PAO), an independent body that verifies your compliance, with certification typically valid for three years. Level 3 involves a government-led assessment. Whichever applies, you submit and affirm your status so contracting officers can confirm your eligibility. Build in time, because assessor availability and remediation of any findings can extend the timeline.
What CMMC costs and how long it takes
Costs vary widely by level and the size and maturity of your environment. As a rough guide, achieving Level 1 often runs around a few thousand dollars, a self-assessed Level 2 can run on the order of tens of thousands, and a third-party-assessed Level 2 for a larger contractor can exceed $100,000 when implementation, tooling, and the C3PAO assessment are combined. Specialist consulting commonly runs $200 to $400 an hour. Timelines range from months to over a year, depending on how far your current security is from the target. The cost is significant, but so is the prize: continued eligibility for DoD contracts.

Getting to CMMC with help
CMMC is genuinely demanding, especially for small and midsize defense contractors that lack a dedicated security team, and the specialized expertise it requires is scarce amid a global shortfall of about 4.8 million cybersecurity professionals. Many contractors work with a managed IT or security provider experienced in CMMC and NIST 800-171 to scope the environment, run the gap assessment, implement controls, prepare the SSP and POA&M, and get them assessment-ready, often hosting CUI in a compliant enclave the provider manages. It is part of why the managed services market is projected to grow to about $879 billion over the next decade. A partner who knows the framework can be the difference between winning the contract and missing it.
If CMMC is required for your contracts, an experienced partner can guide you from gap assessment to certification. To find one, browse vetted, merit-ranked firms by city in the Best IT MSP directory, where ranking is earned on rating and verified data. (This guide is general information; confirm current CMMC requirements with official DoD sources and your assessor.)
Frequently asked questions
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program requiring defense-supply-chain contractors to prove they protect sensitive government information. If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on a DoD contract, you must meet a CMMC level to win and keep that work.
What are the CMMC levels?
There are three. Level 1 (Foundational) is for contractors handling only FCI and is self-assessed. Level 2 (Advanced) is for CUI and aligns with the 110 controls of NIST SP 800-171, with most Level 2 requiring a third-party assessment. Level 3 (Expert) is for the highest-priority programs and the most sensitive information, with a government-led assessment.
What are the steps to CMMC compliance?
Determine the level you need from your contract, scope where CUI is stored and processed, run a gap assessment against NIST SP 800-171, implement the required controls, document a System Security Plan (SSP) and Plan of Action and Milestones (POA&M), then complete a self-assessment or a C3PAO third-party assessment depending on your level.
What is NIST 800-171 and how does it relate to CMMC?
NIST SP 800-171 is a set of 110 security controls for protecting Controlled Unclassified Information. CMMC Level 2 is built directly on these controls, so the substance of achieving Level 2 is closing gaps against NIST 800-171. A gap assessment against these controls produces the roadmap and feeds the score the DoD uses.
How much does CMMC compliance cost?
It varies by level and the size and maturity of your environment. Level 1 often runs around a few thousand dollars, a self-assessed Level 2 on the order of tens of thousands, and a third-party-assessed Level 2 for a larger contractor can exceed $100,000 once implementation, tooling, and the C3PAO assessment are combined. Specialist consulting commonly runs $200 to $400 an hour.
Do I need a third-party assessment for CMMC?
It depends on your level. Level 1 and a subset of Level 2 are self-assessed and affirmed annually. Most Level 2 requires a formal assessment by a Certified Third-Party Assessment Organization (C3PAO), with certification typically valid for three years, and Level 3 involves a government-led assessment. Your contract and the information you handle determine which applies.
Related reading
Get CMMC-ready with defense-experienced experts
Best IT MSP is the independent directory of vetted managed IT and security providers across North America. Compare merit-ranked firms in your city experienced in CMMC and NIST 800-171. No pay-to-play.
Best IT MSP is an independent directory that connects you with vetted managed IT providers. Browse the directory city by city:
- Managed IT Services in New York
- Managed IT Services in Los Angeles
- Managed IT Services in Chicago
- Managed IT Services in Houston
- Managed IT Services in Bakersfield
- Managed IT Services in Baltimore
- Managed IT Services in Baton Rouge
- Managed IT Services in Boise
- Managed IT Services in Boston
- Managed IT Services in Bowie