Skip to content

CMMC

CMMC Level 2 & NIST SP 800-171 Rev 3 Readiness Checklist

A practice-oriented checklist to protect CUI, implement NIST 800-171 requirements, and prepare for a CMMC Level 2 assessment.

Estimated time
6–18 Months
Audience
US Defense Contractors and CUI Processors
Last updated

Operational reference for CMMC Level 2 / 800-171 preparation. Formal status is determined by a C3PAO assessment and SPRS affirmation where required.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: CUI Scoping

Phase 2: 800-171 Control Implementation

Phase 3: SSP & Evidence

Phase 4: Assessment Readiness

FAQ

What is a C3PAO?+

A Certified Third-Party Assessor Organization authorized to perform CMMC Level 2 assessments.

Is CMMC the same as 800-171?+

Level 2 is aligned to 800-171 practices. CMMC adds assessment methodology, affirmation, and (for some contracts) third-party certification.

Does FedRAMP replace CMMC?+

FedRAMP can provide inheritance for cloud controls; the contractor still owns the customer-responsible practices.

Can POA&Ms be open at assessment?+

Only as allowed by current DoD/CMMC assessment policy. Do not assume every gap can be deferred.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer