Back to Resources
CMMCChecklist5 min read

CMMC Level 2 Readiness Checklist

CMMC Level 2 requires compliance with all 110 security practices drawn from NIST SP 800-171. This checklist organizes those practices into the 14 control domains so you can quickly assess where your organization stands and prioritize remediation efforts before your assessment.

How to Use This Checklist

For each practice, mark your current status: Implemented (fully in place and documented), Partially Implemented (in progress or inconsistently applied), or Not Implemented (gap exists). Practices marked Partially or Not Implemented become your POA&M (Plan of Action & Milestones) — the roadmap you'll need to present during your CMMC assessment.

Access Control (AC)

22 practices
  • Limit system access to authorized users and processes
  • Limit system access to types of transactions and functions authorized users are permitted to execute
  • Control the flow of CUI in accordance with approved authorizations
  • Separate duties of individuals to reduce risk of malevolent activity
  • Employ the principle of least privilege
  • Use non-privileged accounts when accessing non-security functions

Identification & Authentication (IA)

11 practices
  • Identify system users, processes, and devices
  • Authenticate identities before allowing access
  • Use multifactor authentication for local and network access to privileged accounts
  • Employ replay-resistant authentication mechanisms
  • Enforce minimum password complexity and change requirements

Configuration Management (CM)

9 practices
  • Establish and maintain baseline configurations for systems
  • Establish and enforce security configuration settings
  • Track, review, approve, and log changes to systems
  • Analyze security impact of changes prior to implementation
  • Define, document, and enforce user-installed software restrictions

Incident Response (IR)

3 practices
  • Establish an operational incident-handling capability
  • Track, document, and report incidents to appropriate officials
  • Test the organizational incident response capability

Risk Assessment (RA)

3 practices
  • Periodically assess risk to operations, assets, and individuals
  • Scan for vulnerabilities in systems periodically and when new vulnerabilities are identified
  • Remediate vulnerabilities in accordance with risk assessments

System & Communications Protection (SC)

16 practices
  • Monitor, control, and protect communications at external boundaries
  • Implement subnetworks for publicly accessible system components
  • Deny network communications traffic by default
  • Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission
  • Terminate network connections after a defined period of inactivity

Need Help Closing Your Gaps?

DesignNMind specializes in CMMC Level 2 readiness — from gap assessment and SSP development to POA&M management and assessment preparation. Let's talk through your current posture.

Schedule a CMMC ConsultationView CMMC Services