A printable self-assessment for defense contractors. Covers Federal Contract Information (FCI · Level 1, 15 controls) and Controlled Unclassified Information (CUI · Level 2, 110 controls across the 14 NIST SP 800-171 domains) — plus six program-level readiness gates most assessments stumble on.
Walk through this checklist with the people who actually run the systems — not just policy owners. Checkboxes survive printing. Score honestly. If less than 80% of any domain is checked, that domain will dominate your remediation timeline.
CMMC has two practitioner paths below Level 3. Use the scoping card that matches your contract obligations. Most primes handle both FCI and CUI; subcontractors typically start on FCI until a task order pulls them into CUI scope.
Use this path if your DoD contracts only involve FCI — information provided by or generated for the Government under contract not intended for public release. Annual self-assessment against 15 safeguarding requirements from FAR 52.204-21, grouped under four core domains. No third-party assessment required at Level 1.
Use this path if your contracts carry DFARS 252.204-7012 and you process, store, or transmit CUI on DoD programs. Third-party C3PAO assessment every three years against the full 110 NIST SP 800-171 Rev 2 controls, grouped under 14 domains. Expect 12–18 months from gap assessment to certified.
The 15 FAR 52.204-21 basic safeguarding requirements, grouped under the four domains exercised at Level 1: Access Control, Identification & Authentication, Media Protection, and System & Communications Protection. Check all 15 before claiming Level 1 readiness.
The 110 NIST SP 800-171 Rev 2 controls collapsed into the 14 domains an OSC recognizes. Each item is a one-line self-assessment question. C3PAO scoring is binary — a control is either met or it isn't. Tick every box across all 14 domains before scheduling a C3PAO assessment.
These six program-level items are where most failed assessments land — not the controls themselves, but the surrounding documentation infrastructure and program maturity. If any of these is unchecked, the assessment will find it.