CMMC 2.0 · Self-Assessment

CMMC 2.0 Readiness Checklist

A printable self-assessment for defense contractors. Covers Federal Contract Information (FCI · Level 1, 15 controls) and Controlled Unclassified Information (CUI · Level 2, 110 controls across the 14 NIST SP 800-171 domains) — plus six program-level readiness gates most assessments stumble on.

Walk through this checklist with the people who actually run the systems — not just policy owners. Checkboxes survive printing. Score honestly. If less than 80% of any domain is checked, that domain will dominate your remediation timeline.

Step 0 — Pick Your Path

Which path applies to you?

CMMC has two practitioner paths below Level 3. Use the scoping card that matches your contract obligations. Most primes handle both FCI and CUI; subcontractors typically start on FCI until a task order pulls them into CUI scope.

CMMC Level 1
Federal Contract Information (FCI)
15 safeguarding requirements · annual self-assessment

Use this path if your DoD contracts only involve FCI — information provided by or generated for the Government under contract not intended for public release. Annual self-assessment against 15 safeguarding requirements from FAR 52.204-21, grouped under four core domains. No third-party assessment required at Level 1.

CMMC Level 2
Controlled Unclassified Information (CUI)
110 NIST 800-171 Rev 2 controls · C3PAO assessment

Use this path if your contracts carry DFARS 252.204-7012 and you process, store, or transmit CUI on DoD programs. Third-party C3PAO assessment every three years against the full 110 NIST SP 800-171 Rev 2 controls, grouped under 14 domains. Expect 12–18 months from gap assessment to certified.

Level 1 · 15 Controls

FCI Checklist (Level 1)

The 15 FAR 52.204-21 basic safeguarding requirements, grouped under the four domains exercised at Level 1: Access Control, Identification & Authentication, Media Protection, and System & Communications Protection. Check all 15 before claiming Level 1 readiness.

AC Access Control
IA Identification & Authentication
MP Media Protection
SC System & Communications Protection
Level 2 · 110 Controls

CUI Checklist (Level 2)

The 110 NIST SP 800-171 Rev 2 controls collapsed into the 14 domains an OSC recognizes. Each item is a one-line self-assessment question. C3PAO scoring is binary — a control is either met or it isn't. Tick every box across all 14 domains before scheduling a C3PAO assessment.

AC Access Control
AT Awareness & Training
AU Audit & Accountability
CM Configuration Management
IA Identification & Authentication
IR Incident Response
MA Maintenance
MP Media Protection
PS Personnel Security
PE Physical Protection
RA Risk Assessment
CA Security Assessment
SC System & Communications Protection
SI System & Information Integrity
After the Controls

Program-Level Readiness Gates

These six program-level items are where most failed assessments land — not the controls themselves, but the surrounding documentation infrastructure and program maturity. If any of these is unchecked, the assessment will find it.

Want a vCISO to walk you through it?

Most contractors find their real gaps during the first vCISO session.

If your scoring revealed weaknesses, that's the most useful outcome. Book a strategy call to walk through the results with a CMMC-experienced vCISO — no sales pitch, just a clear remediation picture.

Book a CMMC Strategy Call →