CMMC Level 2 Readiness Checklist
Filled in by the compliance lead with the IT manager and, where they exist, the managed service provider, this checklist produces a first honest view of where your organization stands against Cybersecurity Maturity Model Certification (CMMC) Level 2, family by family. It walks all 14 requirement families of NIST SP 800-171 Rev 2, the standard CMMC Level 2 assesses against, and asks 3 to 5 review questions per family. Unticked boxes become the first entries in your Gap & POA&M Tracker.
- 01
Do this after scope is settled (CMMCg-R003) and the inventory exists (CMMCg-R004). Answering these questions for an undefined environment produces an undefined answer.
- 02
For each family, tick a box only if you could show an assessor something today: a setting, a log, a document, a record. "We do that" without an artefact is an untick.
- 03
This is a review of posture, not the assessment. NIST SP 800-171 Rev 2 has 110 requirements across these 14 families and CMMC Level 2 assesses each of them; the questions here are prompts to find where to look harder, not a substitute for the requirements.
- 04
Write every untick into the findings block with the family code and one line on why. Those lines become rows in the CMMC Gap & POA&M Tracker (CMMCg-R007).
- 05
Repeat the review after each round of remediation. Keep the dated copies; the trend is itself useful evidence of a managed program.
14 checklists, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- The 14 requirement families
- AC — Access Control
- AT — Awareness and Training
- AU — Audit and Accountability
- CM — Configuration Management
- IA — Identification and Authentication
- IR — Incident Response
- MA — Maintenance
- MP — Media Protection
- PS — Personnel Security
- PE — Physical Protection
- RA — Risk Assessment
- CA — Security Assessment
- SC — System and Communications Protection
- SI — System and Information Integrity
- Write each unticked box into the CMMC Gap & POA&M Tracker (CMMCg-R007) as a deficiency with an owner and a target date.
- For each family, name the policy and procedure that should support it and check whether they exist using the CMMC Policy & Procedure Matrix (CMMCg-R006).
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.