CMMC readiness checklist: understand the levels and plan your next step

A useful CMMC readiness plan starts with a clear boundary, real responsibilities and evidence of how your business works. Use this guide to organize the next conversation with your team or a consultant.

Last reviewed October 9, 2026. Educational guidance, not a determination of your contract obligations or an assessment result.

What does CMMC mean?

CMMC stands for Cybersecurity Maturity Model Certification. It is the U.S. defense department’s program for assessing how contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

FCI and CUI are information categories, not labels for an entire company. Different projects, systems and subcontract relationships can create different responsibilities. Start with the information your business receives, creates, stores, processes or transmits while performing the work. Then confirm the requirements in your solicitation, contract and applicable subcontract.

Readiness consulting can help you understand that starting point and organize improvements. It does not replace a formal assessment, confer CMMC status or guarantee a contract award.

CMMC levels: what changes from Level 1 to Level 3?

Level 1: basic safeguarding of FCI

The regulatory model includes 15 basic safeguarding requirements from FAR 52.204-21. Level 1 uses an annual self-assessment and annual affirmation. It does not allow a conditional assessment result based on an assessment Plan of Action and Milestones (POA&M).

Level 2: protection of CUI

Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The regulatory model provides for a self-assessment or a CMMC Third-Party Assessment Organization (C3PAO) assessment, depending on applicable requirements. Do not automatically substitute Revision 3 because it is a newer publication.

Current implementation guidance continues Level 2 self-assessments. Under the model, Level 2 assessments occur every three years with affirmation after the assessment and annually thereafter. Assessment POA&Ms are allowed only within defined limits; eligible open items must be closed within 180 days. A remediation to-do list is not automatically an acceptable assessment POA&M.

Level 3: selected enhanced requirements

Level 3 adds 24 selected requirements from NIST SP 800-172 to the Level 2 baseline. The regulatory model uses government-led assessments by DCMA DIBCAC. This is a defined model route, not a statement that every CUI contractor currently needs Level 3.

A model level and an implementation phase are different things. The Phase II suspension does not itself repeal the three-level model. Review the current implementation note below before making scheduling or purchasing decisions.

Use our browser-only level planning checker to organize questions. Your contract determines the applicable requirements; a short questionnaire cannot make that determination.

Which requirements apply to your contract and systems?

Collect the relevant solicitation language, contract clauses, amendments and prime-contractor flow-downs. Have your contracts lead and technical lead review them together. Ask what information is involved, which systems support the work, what assessment designation is required and when an assessment or affirmation must be current.

If the wording is unclear, identify the question for your contracting officer or prime through the appropriate channel. Avoid selecting a level solely because your organization is small, works in manufacturing or uses a particular software platform. Likewise, do not assume that a cloud product or managed service makes the whole environment compliant.

Your CMMC readiness checklist

  1. Confirm the requirement and assessment route

    Do: Record the applicable contract or subcontract requirement, assessment designation, responsible business owner and the source of any deadline. Separate confirmed obligations from assumptions or marketing claims.

    Useful output: A short requirements register your contracts and security leads can agree on. Flag questions that need clarification before committing to an expensive technical change.

  2. Map information and define the boundary

    Do: Trace where FCI or CUI enters the business, who uses it, where it is stored, how it moves and who supports the relevant systems. Include people, endpoints, networks, cloud services, facilities and outside providers that may affect the assessment scope.

    Useful output: A scope narrative, a high-level information-flow map and an inventory with accountable owners. Record why a system is inside or outside the proposed boundary. Validate those decisions against the applicable official scoping guidance.

    Watch for: CUI reaching email, shared drives, personal devices, support tools or backups outside the intended environment. A boundary on a diagram is only useful if it matches actual practice.

  3. Identify gaps and prioritize remediation

    Do: Evaluate the applicable requirements using the official assessment guidance. Distinguish a missing control, a partly implemented process and an evidence gap. Identify dependencies, responsible owners and the work needed to validate each fix.

    Useful output: A prioritized gap register with specific actions, ownership, estimated effort and acceptance criteria. Address systemic problems rather than treating every missing document as an isolated writing task.

    Watch for: A spreadsheet showing “implemented” because a policy exists. The policy, actual operation and supporting evidence need to agree.

  4. Align documentation with actual operations

    Do: Tailor policies, procedures and, where required, the System Security Plan (SSP) to your environment. Describe who performs each activity, what they do, when they do it and how exceptions are handled.

    Useful output: Controlled documents with owners and review dates, plus a clear change process. Templates can provide structure, but generic language should never describe controls your team does not perform.

    Watch for: Documents that reference discontinued systems, generic job titles or tasks that no one owns. Ask staff to walk through the process rather than merely approving the wording.

  5. Build an evidence trail your team can explain

    Do: Identify evidence that demonstrates both implementation and ongoing operation. Map it to the relevant requirements, assign an owner and note how it is produced and kept current. Prepare responsible staff for appropriate interviews, demonstrations and testing.

    Useful output: An evidence inventory with secure locations, retention expectations and access arrangements. A consultant should explain how your team can reproduce evidence after the engagement ends.

    Watch for: Uncontrolled copies of sensitive diagrams, access exports or technical records. Keep assessment materials in approved systems. Do not upload CUI, passwords or an SSP to an ordinary lead form.

  6. Prepare for assessment and ongoing maintenance

    Do: Confirm the applicable assessment route, submission and affirmation responsibilities. Use official assessment criteria, resolve eligible outstanding issues within the applicable rules and arrange a handover from the project team to ongoing operations.

    Useful output: A responsibility matrix, assessment preparation plan and recurring review schedule. Identify who can make required affirmations and who keeps relevant Supplier Performance Risk System (SPRS) information current.

    Watch for: Treating the assessment date as the end of the work. Staff changes, new tools, contracts and information flows may affect the environment and its supporting evidence.

What should a CMMC readiness consultant deliver?

Agree on outputs before work starts. Depending on your needs, a practical engagement may include a confirmed scope summary, a requirements and gap register, a remediation plan, tailored documentation, an evidence inventory and a handover your team can use.

Clarify who implements technical changes, who approves policies, who owns documents and who maintains controls afterward. A consultant’s recommendations may depend on your IT provider or internal staff completing work. Those dependencies should appear in the plan and price.

Ask for deliverables that are specific enough to inspect. “Help with compliance” is less useful than a named scope, review process, acceptance criteria and list of exclusions.

Questions to ask before hiring a consultant

  • Experience: Which engagements have involved a similar information boundary, operating model and internal team? How can relevant experience and any claimed credentials be verified?
  • Scope: How will you validate information flows and out-of-scope assumptions before estimating the work?
  • Delivery: Who will perform the work, what will we receive and how will we know each deliverable is complete?
  • Responsibility: What must our staff or existing IT provider do? Who is accountable when a dependency delays the plan?
  • Evidence: How will you verify actual operation and help us keep evidence current after handover?
  • Cost: What is included, excluded or recurring? What changes would trigger additional fees or licensing costs?
  • Independence: How do you distinguish readiness consulting from formal assessment, and what conflicts or referral relationships should we understand?
  • Information handling: How will sensitive material be accessed, protected, retained and returned or deleted?

A promise of guaranteed certification, a universal deadline or an immediate platform purchase without a scope review should prompt more questions.

Current implementation status and official sources

Reviewed October 9, 2026: On July 13, 2026, the Department suspended the planned Phase II transition. Current official guidance says implementation is paused in Phase I, with Level 1 and Level 2 self-assessment requirements continuing. Existing safeguarding obligations remain. No replacement Phase II start date was identified in the official guidance reviewed.

The assessment routes described in the regulatory model should be read separately from current procurement implementation. Do not treat November 10, 2026 as a confirmed universal third-party certification deadline. Review your actual contract, any amendments and current official guidance before acting.

Turn the checklist into a useful conversation.

Start with your business, your readiness stage and the areas where you need help. Keep sensitive contract and technical material out of the initial request.

Reach out to a CMMC Specialist