CMMC compliance checklist: 15 key steps
A practical guide for DoD contractors navigating CMMC 2.0 requirements – what to prepare, what to verify, and how to reduce risk before certification becomes mandatory.
As of November 10th, 2025, the Department of Defense’s (DoD) final CMMC 2.0 rule takes effect, beginning a phased three-year rollout of contractual CMMC compliance requirements. If your organization wishes to compete for new DoD work – or maintain existing contracts – you’ll need to be actively preparing for this shift before it’s too late. This handy 15-step CMMC compliance checklist can help you understand what’s required, prepare effectively, and be sure you’re ready when the time comes.
No matter where you are on the Defense Industrial Base (DIB) – from manufacturing components, providing services, or supporting programs indirectly – CMMC 2.0 applies to you. Prime contractors, subcontractors, vendors, and service providers that handle DoD-related government information must meet these requirements to remain eligible for contracts.
CMMC 2.0 has been streamlined to three levels from the original five introduced in 2020. Here’s a top-level look at the requirements for each level:
While the model is structured, implementation is never exactly simple — especially for organizations balancing legacy environments, active contracts, and phased rollout timelines.
This 15-step checklist is a quick reference for how most organizations approach this process as they start reviewing their CMMC compliance. Print it out or bookmark it to refer to as you go through the compliance process. You’ll also find a more in-depth explanation of each step below the checklist.
The 15-step CMMC 2.0 compliance checklist above provides an overview of the process for achieving DoD certification. While the specific requirements vary by level, the core actions remain largely the same: define scope, assess gaps, remediate controls, document implementation, and maintain compliance over time. Here is how to apply the checklist for each CMMC 2.0 level.
LEVEL 1
CMMC 2.0 Level 1 requirements focus on safeguarding FCI and require compliance with FAR 52.204-21. At Level 1, you need to do an annual self-assessment. To meet Level 1 requirements, prioritize these elements of the checklist:
Use Steps 2–5 to confirm that you handle only FCI, define your in-scope systems, and map where that FCI is stored, processed, and transmitted.
Apply Steps 6 and 7 to compare your current practices to the 15 FAR 52.204-21 controls, documenting shortfalls and remediation tasks in POA&Ms.
In Steps 8–10, implement missing policies and basic technical safeguards, and make sure all staff understand their responsibilities for handling FCI.
Use Steps 11–14 to complete your annual self-assessment, assemble supporting evidence, and submit results to the DoD Supplier Performance Risk System (SPRS).
For Step 15, keep patching, monitoring, and training on a regular cadence so your organization is ready for each yearly reaffirmation.
Level 2
CMMC 2.0 Level 2 requirements focus on protecting CUI and align with the 110 practices in NIST SP 800-171. The same 15 steps still apply, but each one becomes more detailed and cross-functional than for Level 1. Here’s how the 15 steps expand for Level 2 organizations:
Use Steps 1–3 to understand the CMMC framework, confirm that you handle CUI as well as FCI, and determine that your contracts call for Level 2.
In Steps 4–5, assign a compliance owner or team and map your CUI data flows, systems, users, and locations – often including a defined CUI enclave.
Apply Steps 6 and 7 to assess your posture against all 110 controls, documenting each unmet requirement in POA&Ms and updating your System Security Plan (SSP).
With Steps 8–10, implement missing controls, update policies and procedures, and determine whether your existing systems suffice or new platforms are needed to support CMMC 2.0 compliance at scale.
Use Steps 11–13 to conduct internal self-assessments, address outstanding POA&M items, and prepare the documentation and evidence required by C3PAOs or government assessors.
Finally, in Steps 14–15, submit your NIST 800-171 score to SPRS with the appropriate attestation, then keep your SSP, controls, and evidence up to date between assessments.
Level 3
CMMC 2.0 Level 3 requirements apply to organizations supporting the DoD’s most sensitive, mission-critical programs and handling high-value CUI. This level builds on Level 2 by introducing enhanced practices aligned with NIST SP 800-172 and requires government-led assessments. At Level 3, CMMC becomes a formal security program with executive oversight, not an extension of checklist-based compliance. Applying the checklist to Level 3 shifts the focus toward governance, resilience, and sustained operational readiness:
Use Steps 1–5 to confirm you support high-value CUI, identify in-scope systems and data, and establish a governed boundary. This typically includes defined ownership, executive accountability, and alignment with enterprise risk management.
In Steps 6–8, expand your assessment beyond NIST SP 800-171 to include the additional Level 3 practices. Update POA&Ms and SSPs to reflect enhanced security objectives, control maturity, and remediation planning.
Apply Steps 9–10 with emphasis on advanced monitoring, threat detection, incident response, and recovery. Controls at this level are designed to withstand advanced persistent threats and maintain continuity for mission-critical operations.
Use Steps 11–13 to rehearse for DIBCAC or other government-led assessments. Ensure documentation, evidence, and operational practices are consistently review-ready and supported by trained, cross-functional teams.
With Steps 14–15, integrate Level 3 into your broader security and governance framework. Maintain SPRS records, keep documentation and evidence current, and treat reassessments as continuous risk management—not a one-time event.
Any time you’re dealing with multiple stakeholders, conflicting interpretations, legacy systems, and a multi-year rollout of compliance guidelines, there are bound to be issues that can affect contract eligibility, increase costs, and delay certification. One of the most common issues is assuming that CMMC Level 1 requirements can be addressed informally, when they actually require a defined scope, documented controls, and an annual self-assessment submitted to SPRS. Another common issue is assuming that CMMC applies only when organizations permanently store CUI. In practice, receiving, viewing, transmitting, or processing CUI during contract performance – along with handling certain types of FCI – triggers specific CMMC 2.0 requirements and determines whether Level 1 or Level 2 applies.
Organizations can sometimes view CMMC as a one-time certification milestone rather than an ongoing program that requires continuous evidence, up-to-date documentation, active POA&Ms, and ongoing alignment with NIST SP 800-171. As a result, remediation is rushed, evidence is incomplete, and certification timelines are delayed. Many teams also expect assessors to provide guidance during the audit. They don’t. They also underestimate the effort required to map CUI boundaries correctly or assume that purchasing new security tools alone is sufficient for CMMC compliance. These gaps can result in expanded scope, higher costs, or rework late in the process. Finally, some organizations overlook how cross-functional CMMC really is. Compliance requires coordinated effort across IT, operations, HR, engineering, and leadership – not just cybersecurity teams. Being aware of these issues and addressing them early helps build a smoother, more predictable path to CMMC readiness.
As you’ve probably gathered, achieving CMMC 2.0 compliance is only the starting point. To remain eligible for DoD contracts, organizations must show continuous alignment with their certification level, keep documentation current, and maintain the security controls defined in NIST SP 800-171. This includes regularly updating the SSP, maintaining accurate POA&Ms, and keeping evidence such as logs, access reviews, training records, and asset inventories ready for audit. Ongoing monitoring – patching, threat detection, vulnerability scanning, and incident response – is essential to demonstrate that controls remain effective over time.
Assessment obligations also continue after certification. Level 1 requires an annual self-assessment and SPRS submission. Level 2 organizations must submit yearly affirmations and undergo a C3PAO assessment every three years. Level 3 requires government-led reassessments on the same cycle. Treating CMMC as an ongoing program – not a one-time project – helps organizations stay prepared and compliant throughout the contract lifecycle.
CMMC 2.0 introduces a higher, more consistent standard for protecting FCI and CUI across the defense supply chain, and preparing for it requires thoughtful planning, cross-functional coordination, and ongoing attention. By using this CMMC compliance checklist as a guide – defining your scope, assessing gaps, implementing controls, documenting evidence, and maintaining continuous readiness – your organization can move through the process with greater clarity and confidence.
Discover how Infor’s GovCloud solutions support CMMC 2.0 compliance requirements out of the box.