← Custodia

The CMMC Compliance Checklist

Most CMMC checklists hand you a list before telling you whether it is your list. This one starts with the question that decides everything, then gives you the real requirements for whichever answer you get.

Level 1: 15 requirementsLevel 2: 110 requirementsUpdated July 2026

The answer in 50 words

There is no single CMMC checklist. There are two, and your data picks one. FCI only means Level 1: 15 safeguarding requirements from FAR 52.204-21, self assessed, binary MET or NOT MET. CUI means Level 2: 110 requirements from NIST SP 800-171 Revision 2, scored and filed in SPRS.

Step 0: which checklist is actually yours?

Every hour spent on the wrong list is an hour wasted, and the wrong list is usually the expensive one. Contractors talk themselves into Level 2 because it sounds thorough, then spend months and tens of thousands of dollars building for a category of information they never receive. The gate is not your revenue, your headcount, or how important the contract feels. It is one question about data.

If you handle FCI only

You are CMMC Level 1

Federal Contract Information is information the government provides to you, or that you generate for the government under a contract, that is not intended for public release. It is defined at FAR 4.1901. It arrives unmarked. If this describes everything you touch, your list is the 15 below.

CMMC Level 1 overview
If you handle CUI

You are CMMC Level 2

Controlled Unclassified Information is a separate category with its own handling rules, and the tell is simple: CUI arrives marked, FCI does not. If marked CUI lands in your email or on your file share, your list is the 110.

CMMC Level 2 overview

Not sure? That is the normal answer, and it is worth being sure before you spend anything. The free 2 minute check sorts it out from your actual contracts. For the underlying distinction, read what CUI is and CUI vs FCI. One more thing worth saying plainly: a prime telling you that you need Level 2 is not the same as a contract requiring it. Ask which clause, and read it.

The eight steps, whichever level you land on

The shape of the work is identical at both levels. Only the middle gets bigger.

  1. 01

    Determine what information you handle

    Read your contracts and look at what the government actually sends you. FCI only points to Level 1. Anything marked as CUI points to Level 2. This answer changes every line that follows, so settle it first.

  2. 02

    Draw your scope

    List the people, devices, and systems that store, process, or transmit that information. That boundary is what you assess. Everything outside it is out of scope and stays out.

  3. 03

    Pick your level

    FCI only means CMMC Level 1: 15 safeguarding requirements from FAR 52.204-21, self assessed. CUI in scope means CMMC Level 2: 110 requirements from NIST SP 800-171 Revision 2.

  4. 04

    Work the checklist for your level

    At Level 1, walk all 15 requirements across the six domains and mark each MET or NOT MET. At Level 2, walk the 110 requirements across the 14 domains and score each one.

  5. 05

    Capture evidence for every item you mark

    For each requirement, save the screenshot, export, log page, or signed document that shows the control is real. Capture it as you configure, not months later.

  6. 06

    Write the System Security Plan

    The SSP describes your scope and how each requirement is satisfied inside it. At Level 2 the SSP is itself a scored requirement, so it is not optional paperwork.

  7. 07

    Have a senior official affirm

    A senior official inside your company affirms the results. At Level 1 that means every one of the 15 requirements is MET. At Level 2 it means your score and any POA&M are stated honestly.

  8. 08

    File in SPRS and re affirm annually

    Post the affirmation in PIEE under SPRS and Cyber Reports. Then re affirm every 12 months, and refresh it whenever your scope or systems change.

Checklist A · FCI only

The CMMC Level 1 checklist: all 15 requirements

Level 1 is self assessed. There is no assessor, no application, no fee, and no numerical score. Each requirement is simply MET or NOT MET, and there are no POA&M items to defer a gap into. All 15 must be MET before a senior official affirms in SPRS, and you re affirm every 12 months.

Under each requirement below is what the item means in plain English and what “met” actually looks like when someone asks you to show it. That second line is the one that matters. Most contractors can honestly say they do the thing. Fewer can produce the artifact that proves it, and the artifact is what turns a claim into a defensible affirmation.

AC

Access Control

Who gets in, what they can do once inside, and what leaves.

4 of 15
  1. 01

    Limit system access to authorized users

    AC.L1-b.1.i

    Only people you have approved can sign in to the systems that hold federal contract information. That includes processes and devices, not just humans.

    What met looks like: You can produce a current list of every active account, each one tied to a named person, a documented service function, or an approved device. No leftover logins from people who left.
    FAR 52.204-21(b)(1)(i)
  2. 02

    Limit access to permitted transactions and functions

    AC.L1-b.1.ii

    Being approved is not the same as being approved for everything. People get only the access their job requires. The bookkeeper does not change IT settings.

    What met looks like: Every account holding an admin or elevated role is visible by name with the role it holds, and you can show at least one standard user carrying no elevated role at all.
    FAR 52.204-21(b)(1)(ii)
  3. 03

    Verify and control connections to external systems

    AC.L1-b.1.iii

    You know which outside systems touch your contract work. Personal laptops, vendor portals, a prime file share, a cloud drive, and you approved each one on purpose.

    What met looks like: A written inventory of every external connection with its purpose, the data it can reach, and who authorized it, plus a short rule that no new connection gets added without owner approval.
    FAR 52.204-21(b)(1)(iii)
  4. 04

    Control information posted on publicly accessible systems

    AC.L1-b.1.iv

    Nothing from a federal contract lands on your website, your LinkedIn, or a press release without somebody reviewing it first.

    What met looks like: A written posting rule that your people have acknowledged, plus a recorded periodic sweep of your own public surfaces showing the date, what was reviewed, and what was found.
    FAR 52.204-21(b)(1)(iv)
IA

Identification and Authentication

One login per person, and prove it is really them.

2 of 15
  1. 05

    Identify users, processes, and devices

    IA.L1-b.1.v

    Every login belongs to one identifiable person. The shared front desk account that everybody uses is the classic failure here.

    What met looks like: Your user list shows individual named accounts. Shared mailboxes are configured as shared mailboxes rather than user accounts, and every service account has a documented human owner.
    FAR 52.204-21(b)(1)(v)
  2. 06

    Authenticate users, processes, and devices

    IA.L1-b.1.vi

    Before anyone gets in, verify they are who they claim to be. In practice that means a real password plus a second factor.

    What met looks like: A policy showing multifactor authentication is enabled or enforced, an enrollment report with nobody left sitting at disabled, and any exception (break glass, service accounts) documented with a reason.
    FAR 52.204-21(b)(1)(vi)
MP

Media Protection

Nothing readable leaves the building.

1 of 15
  1. 07

    Sanitize or destroy media before disposal or reuse

    MP.L1-b.1.vii

    Wipe or destroy the laptop, phone, drive, or paper file that held contract information before it goes to the curb, the recycler, or the next employee.

    What met looks like: A written sanitization procedure that names a method for each media type, plus a disposal log with real entries: date, item, serial, method, who performed it, who witnessed it.
    FAR 52.204-21(b)(1)(vii)
PE

Physical Protection

Lock the door, watch the visitor, count the keys.

2 of 15
  1. 08

    Limit physical access to systems and equipment

    PE.L1-b.1.viii

    Only approved people can walk up to the computer, the server, or the cabinet that holds contract information. A locked office counts. Do not overbuild this one.

    What met looks like: A photo of the locked space with the lock actually visible, plus a signed roster of who is authorized to enter. Home offices and vehicles used for the work belong on that roster too.
    FAR 52.204-21(b)(1)(viii)
  2. 09

    Escort visitors, log physical access, and control access devices

    PE.L1-b.1.ix

    One requirement, three habits. Escort non employees while they are near contract information, keep a record of who came in and when, and know where every key, fob, and door code is.

    What met looks like: A signed escort rule, a visitor log with genuine recurring entries (date, name, company, escort, time in, time out), and an access device register showing what was issued and what came back.
    FAR 52.204-21(b)(1)(ix)
SC

System and Communications Protection

A wall between you and the open internet.

2 of 15
  1. 10

    Monitor and control communications at system boundaries

    SC.L1-b.1.x

    A firewall stands between your network and the public internet, and you know what crosses it in both directions.

    What met looks like: A simple network diagram, a firewall or router admin screenshot showing the firewall is on and the factory admin password was changed, and the inbound rules or a default deny posture visible.
    FAR 52.204-21(b)(1)(x)
  2. 11

    Separate publicly accessible system components

    SC.L1-b.1.xi

    Public facing things, your marketing site and your guest Wi-Fi, do not sit on the same network segment as the machine where contract work happens.

    What met looks like: An inventory of every public facing system your company runs and where it is hosted. If your site lives on vendor hosted SaaS and you run nothing public yourself, write that down explicitly instead of leaving it implied.
    FAR 52.204-21(b)(1)(xi)
SI

System and Information Integrity

Patch the holes, run the scanner, keep it current.

4 of 15
  1. 12

    Identify, report, and correct flaws in a timely manner

    SI.L1-b.1.xii

    Install the security updates, and keep something that proves you did. Saying you installed updates is not the control. Showing it is.

    What met looks like: A written cadence (critical inside 30 days, everything else at least monthly) and update history covering every device in scope, with no end of life software anywhere on the list.
    FAR 52.204-21(b)(1)(xii)
  2. 13

    Provide protection from malicious code

    SI.L1-b.1.xiii

    Antivirus runs on every computer and on email. Windows Defender counts, as long as it is actually on.

    What met looks like: Every device in scope appears in the antivirus inventory or dashboard with real time protection showing on, servers included, plus the email scanning setting captured.
    FAR 52.204-21(b)(1)(xiii)
  3. 14

    Update malicious code protection when new releases are available

    SI.L1-b.1.xiv

    Keep the antivirus current by letting it update its own definitions automatically. Old definitions are the same as no antivirus.

    What met looks like: A per device definition version with a recent timestamp and the auto update setting visible. Definitions two weeks stale on an always on machine means the control is quietly broken.
    FAR 52.204-21(b)(1)(xiv)
  4. 15

    Perform periodic scans and real time scans of external files

    SI.L1-b.1.xv

    A full scan runs on a schedule, and the antivirus inspects files the moment they are downloaded, opened, or executed.

    What met looks like: Real time protection on, a recurring scan scheduled at least weekly at a time the devices are actually awake, and one recent successful scan visible in the history.
    FAR 52.204-21(b)(1)(xv)
Why some lists look longer than 15

You will find CMMC checklists online with a higher count. They are not inventing requirements. The CMMC Assessment Guide breaks the physical protection requirement at FAR 52.204-21(b)(1)(ix) into separate sub practices for escorting visitors, logging access, and managing access devices, and some writers count each sub practice as its own line. The regulation counts it once. The number of safeguarding requirements is 15, and the work is the same either way.

Checklist B · CUI in scope

The CMMC Level 2 checklist: the shape of 110 requirements

Level 2 is 110 requirements from NIST SP 800-171 Revision 2, across 14 domains. Listing all 110 here would not help you, so here is the shape and the rules that govern it. Every requirement has its own page with the official statement, its objectives, and the evidence it expects.

The Level 2 list is not the Level 1 list with more items bolted on. It is a different instrument: scored rather than binary, with a documented plan for what is not yet done, and with the System Security Plan itself counted as one of the scored requirements. Work it in this order.

01

Scope first, always

At Level 2 scope is the whole ball game. Decide what is inside the CUI boundary and what stays out, because every one of the requirements applies to what is inside. Contractors who scope the entire company assess the entire company. Contractors who isolate CUI into a defined enclave assess the enclave. The second group finishes.

02

Write the System Security Plan

The SSP describes your boundary and how each requirement is satisfied within it. It is not a formality: NIST SP 800-171 Revision 2 makes the SSP itself a scored requirement, so an environment with no SSP loses points for the absence of the document that was supposed to describe it.

03

Score honestly against the point values

Level 2 scores out of 110. You begin at 110 and subtract 1, 3, or 5 points for every requirement you cannot demonstrate. The scale runs as low as negative 203. The score is a fact about your environment, not a target to write toward.

04

The 88 rule and the 180 day closeout

You can file with Conditional status at a score of 88 or better, provided every remaining gap is POA&M eligible. Those POA&M items must close within 180 days. Some requirements can never be deferred to a POA&M at all, and any requirement worth 5 points cannot be either, so 88 is a floor with conditions attached, not a passing grade.

05

File in SPRS and affirm annually

The self assessment is filed in SPRS and affirmed by a senior official, posted in PIEE under SPRS and Cyber Reports. The affirmation repeats every 12 months. It is a statement to the government, which is why the honest number beats the flattering one every time.

The 110 requirements, by domain

Where the weight sits. Access Control and System and Communications Protection carry the most items, which is where most Level 2 effort actually goes.

The pre work nobody puts on the checklist

These four apply at every level, they come before the first requirement on either list, and they are where the time and money are actually won or lost. No checklist includes them, because they are not requirements. They are the conditions that make the requirements cheap.

Know what data you actually handle

This single answer sets your level, your cost, and your timeline. FCI is information the government gives you or that you generate for the government under a contract, and it is not public. FCI is defined at FAR 4.1901. CUI is a separate, marked category. If nothing you receive is marked as CUI, you are almost certainly an FCI only shop, and most small subcontractors are.

Draw your scope before you touch a control

Scope is the set of people, devices, and systems that store, process, or transmit the information. Every checklist item applies to what is inside the boundary and nothing outside it. Contractors who skip this end up assessing their whole company, which is slower, more expensive, and harder to defend than assessing the part that actually touches the data.

Name your affirming official early

A senior official inside your company signs the affirmation. Not your MSP, not your consultant, not a vendor. Naming that person on day one changes how the work gets done, because the person whose name goes on the filing tends to ask better questions than the person doing the clicking.

Keep evidence as you go, not at the end

Screenshot the setting the moment you change it. Contractors who capture as they configure finish their assessment in hours. Contractors reconstructing evidence six months later spend days, and they are the ones who end up guessing. The habit costs nothing. The reconstruction is where the money goes.

What the Phase 2 suspension changes about this checklist

On July 13, 2026 DoD suspended the CMMC Phase 2 rollout and opened a 60 day review. Paused, not cancelled: the suspension removed the deadline pressure, not the requirement. On the Level 1 list it changes nothing. All 15 FAR 52.204-21 requirements stand, and Phase 1 self assessment obligations on applicable contracts have been in force since November 2025. On the Level 2 list, the C3PAO certification line is paused while the self assessment line is current, which is why this page treats the Level 2 self assessment as the path. DFARS 252.204-7012, the NIST SP 800-171 Revision 2 baseline, government led assessments, and False Claims Act exposure for a false affirmation all remain exactly where they were. The full explainer is here.

CMMC compliance checklist: FAQ

What is on a CMMC compliance checklist?

It depends entirely on your level, which is why a single universal CMMC checklist does not exist. If you handle only Federal Contract Information, your checklist is CMMC Level 1: 15 safeguarding requirements from FAR 52.204-21(b)(1)(i) through (xv), across six domains, self assessed as MET or NOT MET. If you handle Controlled Unclassified Information, your checklist is CMMC Level 2: 110 requirements from NIST SP 800-171 Revision 2 across 14 domains, scored and filed in SPRS. Both lists start with the same first step, which is defining your scope.

How do I know which CMMC level applies to me?

By the data, not by your company size or revenue. FCI only means Level 1. CUI in scope means Level 2. FCI is defined at FAR 4.1901 as information not intended for public release, provided by or generated for the government under a contract. CUI is a separate marked category: CUI arrives marked, FCI does not. If nothing you receive carries a CUI marking, you are very likely an FCI only shop and belong at Level 1.

How many requirements are on the CMMC Level 1 checklist?

15. They come from FAR 52.204-21(b)(1)(i) through (xv) and spread across six domains: Access Control, Identification and Authentication, Media Protection, Physical Protection, System and Communications Protection, and System and Information Integrity. Some checklists circulating online count more than 15 because the CMMC Assessment Guide splits one physical protection requirement into separate sub practices. The count in the regulation is 15.

What does MET actually mean on a CMMC Level 1 checklist?

Level 1 is binary. Each of the 15 requirements is either MET or NOT MET, with no partial credit, no numerical score, and no POA&M to defer a gap into. All 15 must be MET before a senior official affirms. That is stricter than it sounds in one respect and far simpler in another: there is no math to argue about, but there is also nowhere to hide an open item.

What is the 88 rule on the Level 2 checklist?

Level 2 is scored out of 110. You start at 110 and subtract 1, 3, or 5 points for each requirement not met, and the scale bottoms out at negative 203. You can file with Conditional status at a score of 88 or better, provided every remaining gap is POA&M eligible, and those POA&M items must close within 180 days. Some requirements can never be deferred to a POA&M at all.

Do I need a C3PAO to work through a CMMC checklist?

Not at Level 1, ever. Level 1 is self assessed and self affirmed with no third party assessor in the process. At Level 2, no certification is required by a deadline right now: DoD suspended the CMMC Phase 2 rollout on July 13, 2026 and opened a review, and the Level 2 self assessment is the current path. Individual contracts can still specify what they specify, so read your solicitation.

Does the CMMC Phase 2 suspension change this checklist?

Not on the Level 1 side. All 15 FAR 52.204-21 requirements are unchanged, and Phase 1 self assessment obligations on applicable contracts have been in force since November 2025. On the Level 2 side, the C3PAO certification line is paused while the self assessment line is current. DFARS 252.204-7012 and the NIST SP 800-171 Revision 2 baseline never moved.

Is there a CMMC requirements checklist I can print and fill out?

Yes, and free without an email. The Level 1 checklist covers all 15 requirements in plain English and is built to print. The Level 2 checklist covers all 110 requirements with point values and POA&M eligibility flagged per item. Use this page to confirm which one is yours first, because filling out the wrong list is the most expensive mistake on this page.

Now take the list you were handed and go finish it

Custodia walks the requirements for your level, reviews your evidence, generates the SSP and the affirmation, and tracks the annual cycle so it does not fall off your calendar. 7 day free trial, no credit card.

FCI only

All 15 requirements, guided, with the SSP and SPRS affirmation generated for you. $249/month, or $397/month with a credentialed compliance officer.

The L1 Accelerator
CUI in scope

All 110 requirements, scoped, scored, and filed. $1,499/month, or $2,499/month with a year round officer. Filed in 180 days or we work free until it is.

The Level 2 Accelerator
Still not sure

Answer 8 questions about your contracts and get your level, in writing, in about 2 minutes. Free, and the cheapest possible way to avoid building for the wrong list.

Take the free check

Sources:FAR 52.204-21(b)(1)(i) through (xv) · FAR 4.1901 · 32 CFR Part 170 · NIST SP 800-171 Revision 2 · NIST SP 800-171A · CMMC Assessment Guide Level 1 (v2.13) · CMMC Assessment Guide Level 2 (v2.13) · DFARS 252.204-7012. This page is a plain English summary and a study aid, not legal advice. The authoritative requirements are the regulations themselves, and a self assessment must be affirmed by a senior official only after the requirements are genuinely met.

Free · Every Monday

Get the federal bids a small business can win, in your inbox.

The Monday Bid Digest: brand-new SAM.gov solicitations matched to your NAICS, pre-filtered to Level 1 fit, with the CMMC gate called out on every one. Two minutes, no spam.

Get the Monday Bid Digest
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual, two months free)