CMMC pre-assessment checklist for defense contractors
A practical, current checklist for preparing scope, evidence, people and remediation before a CMMC Level 1 or Level 2 assessment.
Last reviewed October 4, 20268 minute read
ASSESSMENT READINESS
CUI boundary
01 Contract
02 Scope
03 Evidence
TestREADY
BOTTOM LINE
The answer in brief
Start with the contract and assessment scope, not a control spreadsheet. Confirm what information you handle, where it flows, which assets are in scope and what evidence supports each claimed implementation.
Pass 1: contract, information and accountability
Complete these checks before reviewing controls. A technically strong environment can still be assessed against the wrong boundary when the contract and information types are unclear.
01Locate the applicable clausesIdentify the FAR, DFARS and CMMC language in each solicitation, contract, order and option period.Evidence: Clause register with contract number, clause, required level, assessment type and responsible owner.Watch for: Relying on a customer email instead of the executed contract.02Separate FCI from CUIDocument what information is received, created and returned, then classify each workflow using the authoritative source.Evidence: Information inventory with examples, source, markings, owner and handling path.Watch for: Treating every customer document as CUI or assuming unmarked information cannot be CUI.03Name the affirming officialIdentify the senior representative who can affirm continuing compliance and make sure the person understands the basis for that statement.Evidence: Named role, approval record and scheduled affirmation review.Watch for: Waiting until submission day to decide who will affirm.04Record supplier obligationsIdentify subcontractors and external providers that receive FCI, handle CUI or provide security protection for the environment.Evidence: Supplier register, flowdown decision, contract language and responsibility matrix.Watch for: Assuming an MSP owns compliance because it operates the tools.
Scope is not an IP address list. It is a defensible explanation of where protected information enters, where it moves, where it rests and which people, technology and facilities can affect it.
01Draw the CUI lifecycleShow receipt, creation, storage, processing, transmission, backup, archive and disposal.Evidence: A data flow diagram tied to named systems and business processes.Watch for: A generic network diagram with no information flow.02Classify every relevant assetIdentify CUI assets, security protection assets, contractor risk managed assets and specialized assets using the current scoping guidance.Evidence: Asset inventory with category, owner, location, purpose and rationale.Watch for: Leaving cloud tenants, admin workstations, identity systems or backup platforms out of scope without analysis.03Test segmentation claimsConfirm that technical boundaries actually prevent unintended access and data movement.Evidence: Firewall rules, identity restrictions, test results and approved architecture.Watch for: Calling an enclave isolated because it uses a separate folder or tenant group.04Include people and facilitiesMap administrators, users, support personnel, remote locations and physical areas that can access or affect the environment.Evidence: Role matrix, access lists, facility diagram and remote access path.Watch for: Scoping only devices and applications.
For each applicable objective, prepare a consistent story across documentation, interviews and technical testing. One policy document is rarely enough.
01Map every assessment objectiveRecord the implementation statement, owner, system and evidence for every applicable objective.Evidence: Objective level evidence matrix with stable file locations.Watch for: Mapping only the 110 requirement titles.02Collect evidence from normal operationsUse records created by real work, not screenshots produced only for the assessment.Evidence: Tickets, logs, approvals, review records, alerts, training records and configuration exports.Watch for: Undated screenshots with no system, user or context.03Interview the people doing the workAsk operators to explain the process and demonstrate it in the real environment.Evidence: Interview plan with owner, topic, supporting artifacts and followup actions.Watch for: A policy owner answering for a technical process they do not perform.04Test the claimed mechanismConfirm settings and outcomes through observation, sampling or a controlled test.Evidence: Test procedure, sample selected, result, date and reviewer.Watch for: Treating product purchase or configuration intent as implementation.
01Reconcile the SSP with realityConfirm system descriptions, boundaries, connections and implementation statements match the current environment.Evidence: Approved SSP with version history and named system owner.Watch for: Template language that describes tools or processes the company does not use.02Create an evidence indexMake evidence easy to retrieve without exposing unrelated sensitive information.Evidence: Index by objective, owner, artifact date, location and access restriction.Watch for: Collecting thousands of files with no traceability.03Prepare demonstrationsIdentify which requirements are best shown live and rehearse safe, repeatable demonstrations.Evidence: Demo script, responsible operator, expected result and fallback artifact.Watch for: Making unplanned production changes during an assessment.04Resolve open findingsSeparate fixed, verified findings from permitted POA&M items and items that block the desired status.Evidence: Closure test, retained proof and synchronized SSP or procedure update.Watch for: Marking a finding closed when the purchase order is approved.
Pass 6: make the readiness decision
1
Freeze the scope
Get leadership, IT, security and contract stakeholders to agree on the boundary.
2
Walk every objective
Record satisfied, other than satisfied, missing evidence and the owner of each follow-up.
3
Correct high-risk gaps
Prioritize identity, access, logging, incident response, configuration and CUI protection weaknesses.
4
Re-test closures
A completed task is not a closed finding until evidence confirms the requirement is satisfied.
5
Prepare the team
Confirm availability of evidence owners and rehearse how they will demonstrate normal operations.
Ready signal
Three forms of proof agree
The SSP describes the mechanism, the operator explains the same process and a current artifact or test demonstrates it.
Stop signal
The evidence changes the story
Documentation says one thing, the configuration shows another and nobody can identify who owns the process.
Primary sources
Use the official source when a solicitation, contract or assessment decision depends on the answer.