CMMC Level 2 requires compliance with all 110 security practices drawn from NIST SP 800-171. This checklist organizes those practices into the 14 control domains so you can quickly assess where your organization stands and prioritize remediation efforts before your assessment.
How to Use This Checklist
For each practice, mark your current status: Implemented (fully in place and documented), Partially Implemented (in progress or inconsistently applied), or Not Implemented (gap exists). Practices marked Partially or Not Implemented become your POA&M (Plan of Action & Milestones) — the roadmap you'll need to present during your CMMC assessment.
Access Control (AC)
22 practices- Limit system access to authorized users and processes
- Limit system access to types of transactions and functions authorized users are permitted to execute
- Control the flow of CUI in accordance with approved authorizations
- Separate duties of individuals to reduce risk of malevolent activity
- Employ the principle of least privilege
- Use non-privileged accounts when accessing non-security functions
Identification & Authentication (IA)
11 practices- Identify system users, processes, and devices
- Authenticate identities before allowing access
- Use multifactor authentication for local and network access to privileged accounts
- Employ replay-resistant authentication mechanisms
- Enforce minimum password complexity and change requirements
Configuration Management (CM)
9 practices- Establish and maintain baseline configurations for systems
- Establish and enforce security configuration settings
- Track, review, approve, and log changes to systems
- Analyze security impact of changes prior to implementation
- Define, document, and enforce user-installed software restrictions
Incident Response (IR)
3 practices- Establish an operational incident-handling capability
- Track, document, and report incidents to appropriate officials
- Test the organizational incident response capability
Risk Assessment (RA)
3 practices- Periodically assess risk to operations, assets, and individuals
- Scan for vulnerabilities in systems periodically and when new vulnerabilities are identified
- Remediate vulnerabilities in accordance with risk assessments
System & Communications Protection (SC)
16 practices- Monitor, control, and protect communications at external boundaries
- Implement subnetworks for publicly accessible system components
- Deny network communications traffic by default
- Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission
- Terminate network connections after a defined period of inactivity
Need Help Closing Your Gaps?
DesignNMind specializes in CMMC Level 2 readiness — from gap assessment and SSP development to POA&M management and assessment preparation. Let's talk through your current posture.
Schedule a CMMC ConsultationView CMMC Services