This CMMC compliance checklist is built for the requirement in front of you right now: the Level 2 self-assessment. In July 2026 the Department of War paused third-party CMMC assessment, which means most contractors handling Controlled Unclassified Information are currently accountable for a self-assessment they score and attest to themselves. The checklist below walks that from the 110 controls through the CUI-handling workflows and the documentation an assessor reads, so you can work it top to bottom and know where you stand.
The standard did not change when the assessment path did. Level 2 still means all 110 requirements of NIST SP 800-171 Revision 2, and a self-attestation you cannot support is still a false statement to the government. Treat this as the same bar it always was, now with your signature on the result.
Before the Checklist: What Level 2 Now Requires
Level 2 applies to organizations that process, store, or transmit CUI, and it requires implementing all 110 NIST SP 800-171 Rev 2 requirements across 320 assessment objectives. The suspension changed who confirms your implementation, not what you have to implement. For the detail of what is paused and what stays in force, see the breakdown of the CMMC Level 2 suspension; for the end-to-end assessment mechanics, see the CMMC Level 2 assessment guide.
Three obligations survive the suspension and are the reason the checklist still matters: DFARS 252.204-7012 still requires the 110 controls, the requirements themselves are unchanged, and a false self-attestation carries False Claims Act exposure. Work the checklist as if an assessor will read it, because the version of you that attests is standing in for the assessor who is currently paused.
The CMMC Compliance Checklist for Level 2
Each item below is a checkpoint, not a one-time task. Work them in order, because each depends on the one before it.
- Confirm your level and your contract clauses. Verify whether your contracts carry DFARS 252.204-7012, which points to Level 2 for CUI, versus FAR 52.204-21 for FCI-only work at Level 1. The clauses in your contracts, not your assumptions, set the level.
- Settle and document your scope. Identify every asset that processes, stores, or transmits CUI and everything that protects those systems. Scope drives the size of the assessment, so this checkpoint carries the most cost leverage.
- Inventory and categorize assets. Place every in-scope asset into its category and give every out-of-scope asset a documented reason it cannot reach CUI.
- Assess against all 110 requirements. Run a gap assessment using the NIST SP 800-171A objectives, the same criteria an assessor uses, and rank what is missing.
- Score with the DoD Assessment Methodology. Build your Supplier Performance Risk System score from the official weighted methodology, not an estimate.
- Write the System Security Plan and POA&M. Document how each control is implemented and track every open gap with an owner and a close-out date.
- Submit and maintain. Submit the score to SPRS, close POA&M items within their window, and keep the documentation current as the environment changes.
The rest of this guide expands the checkpoints that carry the most risk: the 110 controls, the CUI-handling workflows, and the documentation.
The 110 Controls: What the CMMC Controls List Covers
The CMMC Level 2 controls list is the 110 requirements of NIST SP 800-171 Revision 2, organized into 14 families. Knowing the families is how you turn an abstract number into a work plan, because each family is a distinct body of work with its own owner.
| Control family group | Examples of what it covers |
|---|---|
| Access and identity | Access control, identification and authentication, limiting who reaches CUI and proving who they are |
| Operations and monitoring | Audit and accountability, configuration management, maintenance, system and information integrity |
| People and response | Awareness and training, personnel security, incident response |
| Protection | Media protection, physical protection, system and communications protection, risk and security assessment |
The table groups the 14 families so the list is workable, but the assessment scores all 110 requirements individually against 320 assessment objectives, which is the deeper number that matters. Each requirement can have several objectives, and every objective has to be met and evidenced. A control that is half-implemented is a partial or failed objective, not a rounding error, so the controls list is best treated as 320 things to prove rather than 110 things to install.
CUI Workflows That Keep Scope Under Control
The fastest way to lose control of a CMMC assessment is to let CUI move in ways your workflows do not account for, because every path CUI takes pulls the systems on that path into scope. Building the handling workflows deliberately is what keeps the boundary you scoped from quietly expanding.
Start by following the data. Trace where CUI enters, where it is processed and stored, and where it leaves, and turn that into a data flow diagram that becomes assessment evidence. The workflows that matter most are the everyday ones: how CUI is received from the government or a prime, how it is stored and who can reach it, how it is transmitted to subcontractors, and how it is disposed of. Each of those is a workflow you define and enforce, not an accident you discover during assessment.
The workflows also decide how tightly you can separate CUI from everything else. Logical separation, using segmentation and access controls, keeps CUI-handling systems apart while they stay connected, and it is the common approach. Physical separation removes the connections entirely for the most sensitive cases. The point of both is the same: the smaller and better-defined the set of systems and people that touch CUI, the smaller the assessment. The mechanics of drawing that line are covered in the CMMC environment scoping guide, and the specific question of where CUI stops is covered in defining the CUI boundary.
Documentation the Checklist Produces
The checklist is not finished until it has produced the documents an assessment runs on, because implemented controls that are not documented cannot be verified. Three artifacts carry the weight.
The System Security Plan is the anchor. It describes how each of the 110 requirements is implemented, defines the boundary, assigns responsibility for each control, and ties to your asset inventory, network diagram, and data flow documentation. It is the first thing an assessor reads, so it has to match what you actually do rather than what you intended.
The Plan of Action and Milestones records every open gap with a fix, an owner, and a deadline. Under a conditional status, those items carry a 180-day close-out window, and some requirements cannot be deferred to a POA&M at all. Alongside these, keep the evidence that each control operates: policies and procedures, configuration records, training completion, and logs that show monitoring is real and ongoing. This evidence is what turns your self-attestation from a claim into something you can defend.
External Providers on the Checklist
If a third party touches your CUI, it belongs on the checklist. An External Service Provider that processes, stores, or transmits CUI, or that handles the data protecting it, falls inside your assessment scope and has to be documented. A Cloud Service Provider that handles CUI carries a specific requirement: it must meet FedRAMP Moderate equivalency, measured against the FedRAMP Moderate baseline and established through a 3PAO report and body of evidence, and the assessment checks that the equivalency exists. That cloud equivalency is separate from your own 800-171 Rev 2 obligation on your own systems, so the two stack rather than one covering the other. Record who owns which control in a Customer Responsibility Matrix inside your SSP, because assuming a provider covers a requirement it does not is a gap that surfaces at assessment. For the FedRAMP side of this requirement, see Elevate’s FedRAMP advisory services.
Elevate helps defense contractors work this checklist from scope through a defensible SPRS score, so the self-assessment you attest to is one you can stand behind. To pressure-test your checklist before you submit, book a readiness call with an Elevate advisor.
Conclusion
A CMMC compliance checklist is only useful if it ends in something you can defend, and during the suspension that something is a Level 2 self-assessment with your name on it. The checklist runs the same way regardless of who eventually verifies it: confirm your level, settle and document your scope, prove all 110 controls across their 320 objectives, build the CUI-handling workflows that keep your boundary from spreading, and produce the System Security Plan and POA&M an assessor reads.
The organizations that treat the current self-assessment as the full obligation, rather than a lighter stand-in, are the ones that will be ready whenever third-party assessment resumes. Work the checklist as if it will be verified, because the standard behind it has not moved. To confirm your Level 2 readiness before you attest, book a readiness call with an Elevate advisor.
Key Takeaways
A CMMC compliance checklist for Level 2 is now, for most contractors, a checklist for the self-assessment you attest to yourself.
- The self-assessment is the live requirement: third-party assessment is paused, so the checklist ends in a score you submit and attest to, with False Claims Act exposure if it overstates reality.
- The controls list is 320 objectives, not 110 boxes: the 110 requirements across 14 families are scored against 320 assessment objectives, each of which must be met and evidenced.
- CUI workflows control your scope: every path CUI takes pulls systems into scope, so deliberate handling and separation workflows are what keep the assessment small.
- Documentation is the deliverable: a System Security Plan that matches reality, a POA&M with real deadlines, and evidence each control operates are what an assessment verifies.
- Providers belong on the checklist: a cloud provider handling CUI must meet FedRAMP Moderate equivalency, which stacks with your own obligation and is documented in a Customer Responsibility Matrix.
FAQs
Q1. What is a CMMC compliance checklist for Level 2? A CMMC compliance checklist for Level 2 is the ordered set of steps a contractor handling Controlled Unclassified Information works through to meet the standard: confirm the level, define and document scope, assess against all 110 NIST SP 800-171 requirements, score the assessment, and produce the System Security Plan and Plan of Action and Milestones. Since third-party assessment was paused in July 2026, the checklist currently ends in a Level 2 self-assessment that you score and attest to in the Supplier Performance Risk System.
Q2. How many controls are on the CMMC Level 2 controls list? CMMC Level 2 uses the 110 security requirements of NIST SP 800-171 Revision 2, organized into 14 families covering access control, identification and authentication, audit and accountability, configuration management, incident response, and more. Those 110 requirements are scored against 320 assessment objectives, so the practical controls list is 320 objectives to meet and evidence rather than 110 items to check off.
Q3. Does the CMMC suspension remove the compliance checklist requirement? No. The July 2026 suspension paused third-party assessment, but the obligation to implement the 110 controls under DFARS 252.204-7012 remains, and contractors must still complete and attest to a Level 2 self-assessment. A false self-attestation carries False Claims Act exposure, so the checklist still has to be worked in full; only the party that verifies it has changed for now.
Q4. How do CUI-handling workflows affect a CMMC assessment? Every path CUI takes pulls the systems on that path into the assessment scope, so how you receive, store, transmit, and dispose of CUI directly determines how large your assessment is. Deliberate workflows, combined with logical or physical separation, keep CUI confined to a defined set of systems and people, which keeps the assessment focused and the cost proportional. Undocumented CUI movement is the fastest way for scope, and cost, to expand.
Q5. What documentation does the checklist have to produce? The checklist has to end in a System Security Plan describing how each of the 110 requirements is implemented, a Plan of Action and Milestones tracking open gaps with owners and deadlines, and the evidence that each control operates, such as policies, configuration records, training records, and logs. This documentation is what turns a self-attestation into something defensible, since an assessment verifies not just that controls exist but that you can prove they do.