CMMC Level 2 Requirements Checklist for Defense Contractors

CMMC Level 2 is where the defense industrial base does its heavy lifting: all 110 security requirements of NIST SP 800-171 Rev 2, applied to every system in scope for CUI, and verified for most contractors by a triennial C3PAO assessment. What defeats people is rarely a single control — it is the volume, and not knowing what order to tackle it in. This checklist breaks the journey into seven ordered steps, so you always know what comes next and what "done" looks like at each stage.

Before the Checklist: Confirm Level 2 Applies

If you handle CUI, or DFARS 252.204-7012 appears in your contracts, plan for Level 2. Most contracts will require a triennial C3PAO certification assessment; a small subset are designated for self-assessment instead — also conducted every three years, with annual affirmations in SPRS either way. Timing matters too: under the CMMC rollout, Phase 2 begins November 10, 2026, when applicable new solicitations start requiring C3PAO certification as a condition of award. If CUI work is in your pipeline, the clock is already running.

Step 1 — Scope Your CUI Environment

Map where CUI enters, moves, and rests, and categorize assets per the CMMC scoping guidance. This is the decision point with the biggest cost impact of the entire program: bring your whole enterprise into scope, or consolidate CUI into a CMMC secure enclave so far fewer systems carry the 110 requirements.

Step 2 — Write (or Repair) Your System Security Plan

The SSP documents your boundary, network and data-flow diagrams, asset inventory, and an implementation statement for each of the 110 requirements. It is not optional paperwork: under the DoD assessment methodology, an assessment cannot be completed without an SSP at all. We cover the full anatomy in our SSP guide.

Step 3 — Implement the 110 Requirements

The requirements span 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, and ten more. Sequence the work by DoD point weight: the 5-point items, multifactor authentication and FIPS-validated encryption among them, carry the largest score deductions and the longest deployment timelines. Start them first.

Step 4 — Build the Evidence Library

Policies alone are not proof. Collect configurations, logs, records, and screenshots mapped to each requirement and assessment objective — there are 320 objectives behind the 110 requirements. Assessors sample three ways: artifacts, interviews, and demonstrations. If your evidence exists only in someone's head, it does not exist.

Step 5 — Score Yourself and Submit to SPRS

Apply the DoD assessment methodology — scores run from -203 to +110 — and submit through PIEE, recording the score, date, scope, SSP name, and your projected full-implementation date. Our SPRS guide walks the scoring and submission mechanics in detail.

Step 6 — Decide Your POA&M Strategy

Level 2 permits a limited POA&M: broadly, only 1-point items qualify (with narrow exceptions, and six requirements that can never be on one), your score must reach at least 88 of 110, and everything on the list must close within 180 days. The rules are unforgiving enough that the best strategy is simple — arrive on assessment day with few open items, or none. The details are in our POA&M explainer.

Step 7 — Prepare for the C3PAO Assessment

Run a mock assessment or a formal CMMC readiness assessment, rehearse evidence walkthroughs and staff interviews, and handle logistics early: C3PAO calendars are booked months out, so schedule before you are perfect, not after. Assemble your assessment team and agree on how artifacts will be delivered.

How Essendis Helps

Essendis takes contractors through every step on this list — readiness, remediation, enclave build, and assessment preparation — with advisory and engineering under one roof. It is the approach behind our client RPS Defense's perfect 110/110 Level 2 assessment with A-LIGN (C3PAO), achieved with no POA&M. Explore our CMMC Level 2 compliance services, or Connect with an expert to find out which step you are actually on.

Talk to a Cloud Cybersecurity Expert

Thank you for contacting Essendis. Our team is reviewing your submission and will be in touch shortly. 
We look forward to assisting with your cybersecurity and cloud computing needs. 

Continue Exploring Essendis’ Offerings

Return to Essendis
Oops! Something went wrong while submitting the form.