CMMC READINESS

CMMC pre-assessment checklist for defense contractors

A practical, current checklist for preparing scope, evidence, people and remediation before a CMMC Level 1 or Level 2 assessment.

Last reviewed October 4, 20268 minute read

BOTTOM LINE

The answer in brief

Start with the contract and assessment scope, not a control spreadsheet. Confirm what information you handle, where it flows, which assets are in scope and what evidence supports each claimed implementation.

Pass 1: contract, information and accountability

Complete these checks before reviewing controls. A technically strong environment can still be assessed against the wrong boundary when the contract and information types are unclear.

Locate the applicable clausesIdentify the FAR, DFARS and CMMC language in each solicitation, contract, order and option period.Evidence: Clause register with contract number, clause, required level, assessment type and responsible owner.Watch for: Relying on a customer email instead of the executed contract.
Separate FCI from CUIDocument what information is received, created and returned, then classify each workflow using the authoritative source.Evidence: Information inventory with examples, source, markings, owner and handling path.Watch for: Treating every customer document as CUI or assuming unmarked information cannot be CUI.
Name the affirming officialIdentify the senior representative who can affirm continuing compliance and make sure the person understands the basis for that statement.Evidence: Named role, approval record and scheduled affirmation review.Watch for: Waiting until submission day to decide who will affirm.
Record supplier obligationsIdentify subcontractors and external providers that receive FCI, handle CUI or provide security protection for the environment.Evidence: Supplier register, flowdown decision, contract language and responsibility matrix.Watch for: Assuming an MSP owns compliance because it operates the tools.

Official basis:DoD CMMC policy and Phase II suspension, DFARS 252.204-7012

Pass 2: build a boundary an assessor can follow

Scope is not an IP address list. It is a defensible explanation of where protected information enters, where it moves, where it rests and which people, technology and facilities can affect it.

Draw the CUI lifecycleShow receipt, creation, storage, processing, transmission, backup, archive and disposal.Evidence: A data flow diagram tied to named systems and business processes.Watch for: A generic network diagram with no information flow.
Classify every relevant assetIdentify CUI assets, security protection assets, contractor risk managed assets and specialized assets using the current scoping guidance.Evidence: Asset inventory with category, owner, location, purpose and rationale.Watch for: Leaving cloud tenants, admin workstations, identity systems or backup platforms out of scope without analysis.
Test segmentation claimsConfirm that technical boundaries actually prevent unintended access and data movement.Evidence: Firewall rules, identity restrictions, test results and approved architecture.Watch for: Calling an enclave isolated because it uses a separate folder or tenant group.
Include people and facilitiesMap administrators, users, support personnel, remote locations and physical areas that can access or affect the environment.Evidence: Role matrix, access lists, facility diagram and remote access path.Watch for: Scoping only devices and applications.

Official basis:CMMC Level 2 Scoping Guide

Pass 3: identify what the required level expects

AreaCMMC Level 1CMMC Level 2
InformationFCICUI
Requirements15 safeguards from FAR 52.204-21110 requirements from NIST SP 800-171 Rev. 2
AssessmentAnnual self-assessmentSelf-assessment or C3PAO assessment, as specified
POA&MNot permittedLimited use; eligible items must be closed within 180 days
AffirmationAfter each assessmentAfter assessment and annually thereafter

Official basis:DoD CMMC FAQ version 5, 32 CFR Part 170

Pass 4: prove operation, not intention

For each applicable objective, prepare a consistent story across documentation, interviews and technical testing. One policy document is rarely enough.

Map every assessment objectiveRecord the implementation statement, owner, system and evidence for every applicable objective.Evidence: Objective level evidence matrix with stable file locations.Watch for: Mapping only the 110 requirement titles.
Collect evidence from normal operationsUse records created by real work, not screenshots produced only for the assessment.Evidence: Tickets, logs, approvals, review records, alerts, training records and configuration exports.Watch for: Undated screenshots with no system, user or context.
Interview the people doing the workAsk operators to explain the process and demonstrate it in the real environment.Evidence: Interview plan with owner, topic, supporting artifacts and followup actions.Watch for: A policy owner answering for a technical process they do not perform.
Test the claimed mechanismConfirm settings and outcomes through observation, sampling or a controlled test.Evidence: Test procedure, sample selected, result, date and reviewer.Watch for: Treating product purchase or configuration intent as implementation.

Official basis:CMMC Level 2 Assessment Guide

Pass 5: assemble the assessment room

Reconcile the SSP with realityConfirm system descriptions, boundaries, connections and implementation statements match the current environment.Evidence: Approved SSP with version history and named system owner.Watch for: Template language that describes tools or processes the company does not use.
Create an evidence indexMake evidence easy to retrieve without exposing unrelated sensitive information.Evidence: Index by objective, owner, artifact date, location and access restriction.Watch for: Collecting thousands of files with no traceability.
Prepare demonstrationsIdentify which requirements are best shown live and rehearse safe, repeatable demonstrations.Evidence: Demo script, responsible operator, expected result and fallback artifact.Watch for: Making unplanned production changes during an assessment.
Resolve open findingsSeparate fixed, verified findings from permitted POA&M items and items that block the desired status.Evidence: Closure test, retained proof and synchronized SSP or procedure update.Watch for: Marking a finding closed when the purchase order is approved.

Pass 6: make the readiness decision

  1. 1

    Freeze the scope

    Get leadership, IT, security and contract stakeholders to agree on the boundary.

  2. 2

    Walk every objective

    Record satisfied, other than satisfied, missing evidence and the owner of each follow-up.

  3. 3

    Correct high-risk gaps

    Prioritize identity, access, logging, incident response, configuration and CUI protection weaknesses.

  4. 4

    Re-test closures

    A completed task is not a closed finding until evidence confirms the requirement is satisfied.

  5. 5

    Prepare the team

    Confirm availability of evidence owners and rehearse how they will demonstrate normal operations.

Ready signal

Three forms of proof agree

The SSP describes the mechanism, the operator explains the same process and a current artifact or test demonstrates it.

Stop signal

The evidence changes the story

Documentation says one thing, the configuration shows another and nobody can identify who owns the process.

Primary sources

Use the official source when a solicitation, contract or assessment decision depends on the answer.

PRACTITIONER CONTEXT

InfoSecTel LLC · Cyber AB Registered Practitioner RP-3056

Verify on the Cyber AB website ↗