← All Blogs

CMMC Compliance Checklist

CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires contractors handling federal contract information or controlled unclassified information to certify their cybersecurity. The checklist runs: determine your required level, scope where CUI lives, run a gap assessment against NIST 800-171, implement the controls, document an SSP and POA&M, train staff, then complete a self-assessment or a C3PAO assessment depending on level.

The CMMC compliance checklist steps
The CMMC compliance checklist steps
Key takeaways
  • CMMC is required for DoD contractors that handle federal contract information or controlled unclassified information (CUI).
  • Determine which level you need (1, 2, or 3); most CUI handlers need Level 2.
  • The core work is closing gaps against the 110 controls of NIST SP 800-171.
  • You must document a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M).
  • Level 1 is self-assessed; most Level 2 requires a third-party (C3PAO) assessment.

What is CMMC?

CMMC, the Cybersecurity Maturity Model Certification, is the U.S. Department of Defense program that requires companies in the defense supply chain to prove they protect sensitive government information. If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on a DoD contract, you will need to meet a CMMC level to win and keep that work. It exists because the defense supply chain has been a persistent target for nation-state attackers, and the DoD needs assurance that its contractors, especially the many small and midsize ones, are actually securing the data they handle.

For affected contractors, CMMC is not optional, it is a condition of doing business with the DoD, and the cost of a breach in this space is severe, with the average data breach reaching $4.88 million and reported cybercrime losses topping $12.5 billion in a single year. This guide is a practical checklist for getting to compliance. It pairs with our CMMC compliance services and IT compliance services overviews.

Step 1: Determine the CMMC level you need

CMMC has three levels, and your required level depends on the type of information you handle, which is specified in your contract:

The three CMMC levels
The three CMMC levels

Most contractors that touch CUI need Level 2, so identifying your level correctly, from your contract requirements, is the essential first step that scopes everything else.

Step 2: Scope where CUI lives

Before assessing controls, map exactly where the protected information (FCI or CUI) is stored, processed, and transmitted across your systems, people, and facilities. This scoping defines your assessment boundary, everything that touches CUI is in scope and must meet the requirements. Done well, scoping can dramatically reduce your compliance burden, because you can isolate CUI into a defined environment (an enclave) rather than having to secure your entire business to CMMC standards. Getting scope right is one of the highest-leverage decisions in the whole process, both for cost and for passing the assessment.

Step 3: Run a gap assessment against NIST 800-171

For Level 2, the substance of CMMC is the 110 security controls of NIST SP 800-171, covering access control, awareness and training, audit and accountability, configuration management, incident response, and more. Conduct a gap assessment: measure your current security against each of these controls and document where you fall short. This produces your roadmap, the specific gaps you must close, and feeds the scoring the DoD uses. An honest, thorough gap assessment is the foundation; underestimating gaps here is how organizations fail their formal assessment later.

Step 4: Implement the controls

Close the gaps by implementing the required controls. This is the bulk of the work and spans technology and process: multi-factor authentication, access controls and least privilege, encryption of CUI at rest and in transit, audit logging, configuration hardening, vulnerability management, incident response capability, and more. People matter as much as technology here, since the human element features in 68 percent of breaches, so security training is a required control, not an optional extra. Implementation is where most of the time and budget goes, and where a defense-experienced IT partner adds the most value.

The average data breach cost 4.88 million dollars in 2024
The average data breach cost 4.88 million dollars in 2024

Step 5: Document an SSP and POA&M

CMMC requires specific documentation, and it is not optional paperwork, it is assessed. The System Security Plan (SSP) describes your environment and how you meet each control; it is a central document an assessor will scrutinize. The Plan of Action and Milestones (POA&M) documents any controls not yet fully met and your concrete plan and timeline to remediate them. Note that for full Level 2 certification, critical controls generally cannot be left on a POA&M, so plan to close the most important gaps before assessment. Maintaining accurate, current documentation is itself part of demonstrating a mature security program.

Step 6: Get assessed and certified

The final step depends on your level. Level 1 and a subset of Level 2 are self-assessed and affirmed annually by your company, with results submitted to the DoD's system. Most Level 2 requires a formal assessment by a Certified Third-Party Assessment Organization (C3PAO), an independent body that verifies your compliance, with certification typically valid for three years. Level 3 involves a government-led assessment. Whichever applies, you submit and affirm your status so contracting officers can confirm your eligibility. Build in time, because assessor availability and remediation of any findings can extend the timeline.

What CMMC costs and how long it takes

Costs vary widely by level and the size and maturity of your environment. As a rough guide, achieving Level 1 often runs around a few thousand dollars, a self-assessed Level 2 can run on the order of tens of thousands, and a third-party-assessed Level 2 for a larger contractor can exceed $100,000 when implementation, tooling, and the C3PAO assessment are combined. Specialist consulting commonly runs $200 to $400 an hour. Timelines range from months to over a year, depending on how far your current security is from the target. The cost is significant, but so is the prize: continued eligibility for DoD contracts.

CMMC costs vary by level
CMMC costs vary by level

Getting to CMMC with help

CMMC is genuinely demanding, especially for small and midsize defense contractors that lack a dedicated security team, and the specialized expertise it requires is scarce amid a global shortfall of about 4.8 million cybersecurity professionals. Many contractors work with a managed IT or security provider experienced in CMMC and NIST 800-171 to scope the environment, run the gap assessment, implement controls, prepare the SSP and POA&M, and get them assessment-ready, often hosting CUI in a compliant enclave the provider manages. It is part of why the managed services market is projected to grow to about $879 billion over the next decade. A partner who knows the framework can be the difference between winning the contract and missing it.

If CMMC is required for your contracts, an experienced partner can guide you from gap assessment to certification. To find one, browse vetted, merit-ranked firms by city in the Best IT MSP directory, where ranking is earned on rating and verified data. (This guide is general information; confirm current CMMC requirements with official DoD sources and your assessor.)

Frequently asked questions

What is CMMC?

CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program requiring defense-supply-chain contractors to prove they protect sensitive government information. If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on a DoD contract, you must meet a CMMC level to win and keep that work.

What are the CMMC levels?

There are three. Level 1 (Foundational) is for contractors handling only FCI and is self-assessed. Level 2 (Advanced) is for CUI and aligns with the 110 controls of NIST SP 800-171, with most Level 2 requiring a third-party assessment. Level 3 (Expert) is for the highest-priority programs and the most sensitive information, with a government-led assessment.

What are the steps to CMMC compliance?

Determine the level you need from your contract, scope where CUI is stored and processed, run a gap assessment against NIST SP 800-171, implement the required controls, document a System Security Plan (SSP) and Plan of Action and Milestones (POA&M), then complete a self-assessment or a C3PAO third-party assessment depending on your level.

What is NIST 800-171 and how does it relate to CMMC?

NIST SP 800-171 is a set of 110 security controls for protecting Controlled Unclassified Information. CMMC Level 2 is built directly on these controls, so the substance of achieving Level 2 is closing gaps against NIST 800-171. A gap assessment against these controls produces the roadmap and feeds the score the DoD uses.

How much does CMMC compliance cost?

It varies by level and the size and maturity of your environment. Level 1 often runs around a few thousand dollars, a self-assessed Level 2 on the order of tens of thousands, and a third-party-assessed Level 2 for a larger contractor can exceed $100,000 once implementation, tooling, and the C3PAO assessment are combined. Specialist consulting commonly runs $200 to $400 an hour.

Do I need a third-party assessment for CMMC?

It depends on your level. Level 1 and a subset of Level 2 are self-assessed and affirmed annually. Most Level 2 requires a formal assessment by a Certified Third-Party Assessment Organization (C3PAO), with certification typically valid for three years, and Level 3 involves a government-led assessment. Your contract and the information you handle determine which applies.

Get CMMC-ready with defense-experienced experts

Best IT MSP is the independent directory of vetted managed IT and security providers across North America. Compare merit-ranked firms in your city experienced in CMMC and NIST 800-171. No pay-to-play.

▶ Browse Vetted Providers

← Back to all Blogs