CMMC Assessment Preparation Checklist
Filled in by the compliance lead in the weeks before a Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment, with the IT manager and the executive who will sign, this checklist produces a go or no-go view across the five things an assessment actually tests: that scope is settled and defensible, that the documents exist and agree with each other, that the evidence is collected and validated, that the people who will be interviewed know what they will be asked, and that the systems behave the way the documents say. Every unticked box is a reason to delay, not a note for the day.
- 01
Start this no later than the point at which you are choosing a Certified Third-Party Assessment Organization (C3PAO). Some boxes take weeks to tick.
- 02
Work the five checklists in order. Scope first, because a scope problem invalidates everything after it.
- 03
Tick a box only when the named person confirms it and can point to the artefact. The compliance lead should not tick boxes on other people’s behalf.
- 04
Record every untick in the findings block with the checklist it belongs to and a date by which it will be resolved. Decide the go or no-go with the executive who will sign the affirmation, not alone.
- 05
Keep the completed checklist. It is useful evidence of a managed program, and it is the starting point for the annual affirmation and the next assessment.
5 checklists, 2 sets of fields, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- Assessment particulars
- 1. Scope
- Scope
- 2. Documentation
- Documentation
- 3. Evidence
- Evidence
- 4. Personnel and interview preparation
- Personnel and interview preparation
- 5. Technical readiness
- Technical readiness
- Go or no-go
- Resolve every untick, or make an explicit decision with the signing executive to proceed with it recorded.
- After the assessment, keep the SSP, POA&M, evidence tracker and this checklist under the same review cadence you used to prepare; the annual affirmation asks whether the program is still true.
- Return to the CUI Identification Worksheet (CMMCg-R001) whenever a new contract, prime or information type arrives; scope changes start there.
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.