The Cybersecurity Maturity Model Certification (CMMC) program presents a challenge for small defense contractors. You need the certification to compete for Department of Defense (DoD) contracts, but achieving compliance can feel overwhelming with limited IT staff and tight budgets. State-sponsored attackers have already stolen 614 gigabytes of defense data from a Defense Industrial Base (DIB) subcontractor, including schematics for the Osprey, F-35, and F-55 fighter jets. Your organization could be next if you're not protecting Controlled Unclassified Information (CUI) correctly.
This checklist guides you through essential compliance steps for CMMC, focusing on cost management and realistic implementation for smaller organizations. Each item includes the requirement reference and what "done" actually looks like.
What This Checklist Covers
This checklist addresses CMMC Level 2 readiness, which requires implementing all 110 security requirements from NIST SP 800-171 Rev 2. If your contracts involve CUI, you're subject to these controls under DFARS 252.204-7012 regardless of CMMC's regulatory timeline. This checklist helps you build defensible evidence that you've implemented each requirement, the foundation for any third-party assessment.
Prerequisites
Before starting this checklist, confirm:
- You've identified all systems that process, store, or transmit CUI.
- You have executive buy-in and a designated CMMC program lead.
- You've allocated budget (small businesses typically budget $20,000 to $50,000 annually for compliance work).
- You understand your CUI scope, what data you handle, and where it resides.
If you haven't scoped CUI yet, stop here. Every control you implement depends on knowing what you're protecting.
Checklist Items
1. Document your System Security Plan (SSP)
Reference: NIST SP 800-171 3.12.4
Create a written SSP that describes your security boundary, lists all 110 controls, and documents your implementation approach for each. Include network diagrams showing CUI flow.
Good looks like: An assessor can read your SSP and understand exactly where CUI lives, how you protect it, and what compensating controls you use for any requirements you can't fully implement. Your SSP matches your actual environment.
2. Implement Multi-Factor Authentication for all CUI access
Reference: NIST SP 800-171 3.5.3
Deploy MFA on every system, application, and remote access point where users can reach CUI. This includes VPNs, cloud services, and local network access.
Good looks like: No user can access CUI with just a password. You have Audit Logging proving MFA is enforced. Your MFA solution meets FIPS 140-2 validation requirements for federal use.
3. Encrypt CUI at rest and in transit
Reference: NIST SP 800-171 3.13.11, 3.13.8
Enable FIPS 140-2 validated encryption on all devices storing CUI. Use TLS 1.2 or higher for data in motion.
Good looks like: Every laptop, server, and mobile device with CUI uses full-disk encryption. Your cloud storage buckets enforce encryption. Email containing CUI uses encrypted transport. You can demonstrate FIPS validation certificates for your cryptographic modules.
4. Establish access control policies tied to job roles
Reference: NIST SP 800-171 3.1.1, 3.1.2
Define user roles and assign CUI access based on job function. Document who needs access to what and why.
Good looks like: You have a written access control policy. Users can only reach CUI necessary for their role. You review permissions quarterly and remove access when employees change roles or leave.
5. Deploy continuous monitoring and log collection
Reference: NIST SP 800-171 3.3.1, 3.3.2
Implement logging on all CUI systems. Collect and review logs for security events, failed login attempts, and configuration changes.
Good looks like: You retain logs for at least one year. You have a SIEM or log aggregation tool that alerts on suspicious activity. You can produce audit trails showing who accessed specific CUI and when.
6. Conduct vulnerability scanning monthly
Reference: NIST SP 800-171 3.11.2
Run authenticated vulnerability scans against all systems in your CUI environment at least monthly. Remediate critical and high findings within 30 days.
Good looks like: You have scan reports for the past six months. You track remediation in a ticketing system. Your assessor can see that you're closing vulnerabilities on schedule.
7. Implement incident response procedures
Reference: NIST SP 800-171 3.6.1, 3.6.2
Write an incident response plan that includes detection, containment, eradication, and recovery steps. Train your team on their roles during an incident.
Good looks like: Your plan specifies who to notify, including DoD within 72 hours per DFARS 252.204-7012. You've tested the plan with a tabletop exercise. Contact information is current.
8. Separate CUI systems from general business networks
Reference: NIST SP 800-171 3.13.1
Create a security boundary around CUI systems using firewalls, VLANs, or separate networks. Limit connections between CUI and non-CUI environments.
Good looks like: Your network diagram shows a clear CUI enclave. Firewall rules restrict traffic in and out. You can demonstrate that general office systems can't directly access CUI without going through controlled access points.
9. Establish configuration management baselines
Reference: NIST SP 800-171 3.4.1, 3.4.2
Document approved configurations for servers, workstations, and network devices. Track and approve all changes.
Good looks like: You have hardening standards based on DISA STIGs or CIS Benchmarks. Configuration changes require approval. You can restore systems to known-good states.
10. Vet and monitor third-party service providers
Reference: NIST SP 800-171 3.12.1, 3.12.2
Require flow-down DFARS 252.204-7012 language in contracts with any vendor who handles CUI on your behalf. Verify their compliance annually.
Good looks like: Your cloud providers have FedRAMP Moderate authorization or equivalent. Your contracts include cyber incident reporting obligations. You review vendor compliance documentation before sharing CUI.
11. Implement physical access controls for CUI storage
Reference: NIST SP 800-171 3.10.1, 3.10.2
Restrict physical access to areas where CUI is processed or stored. Use badge readers, locks, or other physical barriers.
Good looks like: Server rooms require badge access. Visitor logs track who enters controlled areas. Backup media is stored in locked cabinets. You audit physical access quarterly.
12. Conduct security awareness training annually
Reference: NIST SP 800-171 3.2.1, 3.2.2
Train all employees with CUI access on security policies, phishing recognition, and incident reporting. Document completion.
Good looks like: Every employee completes training within 30 days of hire and annually thereafter. You track completion rates. Training covers CUI handling, password requirements, and how to report suspicious activity.
13. Sanitize media before disposal or reuse
Reference: NIST SP 800-171 3.8.3
Use NIST SP 800-88 compliant methods to wipe or destroy storage devices that held CUI. Document sanitization.
Good looks like: You have a media sanitization policy. Hard drives are degaussed or shredded. You keep certificates of destruction. Devices never leave your facility with CUI intact.
14. Prepare evidence packages for assessment
Reference: CMMC Assessment Guide
Organize documentation, screenshots, policies, logs, and scan reports that demonstrate control implementation. Map evidence to each of the 110 requirements.
Good looks like: Your evidence is organized by control family. Assessors can find what they need without hunting. You have date-stamped artifacts proving continuous compliance, not point-in-time setup before assessment.
Common Mistakes
Treating CMMC as a one-time project. Compliance is continuous. If you implement controls just before assessment and then let them lapse, you're not actually protecting CUI, and you'll fail your next audit.
Scoping CUI too broadly. Some contractors assume all DoD data is CUI. It's not. Over-scoping drives up costs unnecessarily. Review contract clauses and data markings carefully.
Ignoring compensating controls. If you can't implement a requirement exactly as written, document a compensating control that achieves equivalent protection. Leaving gaps undocumented guarantees assessment findings.
Skipping the SSP. Your System Security Plan is not optional paperwork. It's the roadmap an assessor uses to validate your entire program. If your SSP doesn't match reality, you'll fail.
Underestimating cloud configuration work. Moving to FedRAMP Moderate cloud doesn't make you compliant automatically. You still own identity management, access control, logging, and incident response. Review your Customer Responsibility Matrix carefully.
Next Steps
After completing this checklist:
- Schedule a readiness assessment with a Registered Practitioner Organization to identify gaps before your formal CMMC assessment.
- Build a Plan of Action and Milestones (POA&M) for any controls you can't implement immediately. Document target completion dates and risk acceptance.
- Engage with support programs like NIST Manufacturing Extension Partnership centers or prime contractor assistance programs to offset costs.
- Monitor regulatory updates. CMMC implementation continues to evolve under 32 CFR Part 170, and you need to track changes that affect your compliance timeline.
The average data breach costs almost $5 million, and nearly one in five small and medium-sized businesses that suffer cyberattacks subsequently file for bankruptcy or close. CMMC compliance protects your business viability as much as it protects national security. The work is real, and so are the consequences of skipping it.



