CMMC 2.0 Compliance Checklist Template

Third-party certification for Level 2 has been suspended, but the self-assessment, the SPRS score and the affirmation a senior official signs every year are still conditions of award. Eligibility can lapse on a missed date as easily as on a failed control.

The Cybersecurity Maturity Model Certification (CMMC) programme decides whether a defence contractor can be awarded a Department of Defense contract that involves Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). This free CMMC compliance checklist takes primes and subcontractors through one full cycle: reading the level from each contract, scoping assets, the Level 1 or Level 2 self-assessment against NIST SP 800-171 Rev. 2, the SPRS entry, a POA&M closeout inside 180 days, and the annual affirmation. Answers on the first task show only the phases your level needs. The result is a dated record of every score, status and affirmation.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

What the Phase 2 Suspension Changed, and What It Did Not

CMMC rests on two rules. The programme rule, 32 CFR Part 170, took effect on 16 December 2024 and defines levels, scoring, scoping and affirmations. The acquisition rule, which added the clause at DFARS 252.204-7021 and the solicitation notice at 252.204-7025, took effect on 10 November 2025. That date started Phase 1, in which contracts could require Level 1 (Self) or Level 2 (Self) as a condition of award.

Phase 2 was due on 10 November 2026, when third-party Level 2 certification would have become a condition of award. On 13 July 2026 the Department (now also styled the Department of War) suspended it, along with later implementation milestones, and began a 60-day review. Only Level 1 (Self) or Level 2 (Self) may now be specified, and C3PAO and Level 3 requirements are being removed from solicitations and contracts. The underlying obligations stayed: NIST SP 800-171 Rev. 2 through DFARS 252.204-7012, self-assessment results in SPRS and annual affirmations.

CMMC covers contractor information systems. Federal systems run on the Government’s behalf fall outside Part 170 (they follow FISMA), as does FedRAMP authorisation of cloud services.

Level 1 (Self)

Contracts involving FCI only

Requirements: the 15 safeguarding requirements in FAR 52.204-21(b)(1).

Result: every requirement MET. No POA&M is allowed.

Cadence: self-assessment and affirmation every year.

Recorded in: SPRS, with an affirmation by the Affirming Official.

Level 2 (Self)

Contracts involving CUI

Requirements: the 110 requirements of NIST SP 800-171 Rev. 2.

Result: a score out of 110. Conditional status from 88 with a permitted POA&M; Final at 110.

Cadence: assessment every three years, affirmation every year.

Recorded in: SPRS, per system, under a CMMC unique identifier.

Suspended at the time of review

Level 2 (C3PAO) and Level 3 (DIBCAC)

Certification by an authorised C3PAO, and Level 3 assessment by DCMA’s DIBCAC, remain defined in Part 170 but may not be required in procurements during the suspension. Contractors can still choose a C3PAO assessment voluntarily.

What the CMMC Compliance Checklist Covers

Seven phases, of which each contractor sees only the ones its level needs. Requirement numbers are from NIST SP 800-171 Rev. 2 and 32 CFR Part 170.

Phase 1

Phase 1: Contracts, Level & Scope

Answers on the first task decide which of Phases 2, 3, 4 and 7 appear.

  • Record the CMMC level each contract requires — from clause 252.204-7021 or the 252.204-7025 notice, including any amendment removing a C3PAO or Level 3 requirement
  • Classify the information each contract involves — FCI only, or CUI as marked by the Government; any CUI means Level 2 at least
  • Categorise every in-scope asset — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets or Out-of-Scope (32 CFR 170.19)
  • List external service providers — a cloud service holding CUI must meet the FedRAMP requirements in DFARS 252.204-7012; other providers’ services are assessed as part of yours
  • Flow the right level down to subcontractors — Level 1 (Self) for FCI only, at least Level 2 (Self) for CUI (32 CFR 170.23)
  • Name the Affirming Official — the senior representative who will sign every affirmation in SPRS
Phase 2

Phase 2: Level 1 Self-Assessment

Shown only when no CUI is in scope; a Level 2 status already covers Level 1.

  • Assess the 15 Level 1 requirements — using the NIST SP 800-171A objectives, reading FCI wherever an objective says CUI
  • Fix every gap before submitting — Level 1 allows no POA&M, so a single NOT MET means no status
  • Enter the result in SPRS — level, status date, assessment scope, CAGE codes and the compliance result
  • Submit the Level 1 affirmation — then schedule next year’s self-assessment before this one expires
Phase 3

Phase 3: Level 2 Evidence Base

Shown when CUI is in scope.

  • Update the system security plan (3.12.4) — boundary, environment and how each of the 110 requirements is met; without a current SSP an assessment cannot be completed
  • Map evidence to every 800-171A objective — policies, configurations and records in final form, because drafts and working papers do not count
  • Confirm FIPS-validated encryption protects CUI (3.13.11) — non-validated encryption still costs 3 points
  • Confirm multi-factor authentication for all users (3.5.3) — MFA for remote and privileged users only costs 3 points, none costs 5
  • Close the gaps a POA&M cannot hold — any requirement worth more than 1 point (bar non-validated encryption), plus 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 and 3.12.4
  • Describe enduring exceptions and operational plans of action in the SSP — properly documented, both are assessed as MET
Phase 4

Phase 4: Level 2 Assessment & SPRS

The C3PAO task appears only for Level 2 (C3PAO) or Level 3. The POA&M answer on the scoring task controls Phase 5.

  • Score the assessment under 32 CFR 170.24 — start at 110 and subtract 5, 3 or 1 point for each requirement NOT MET; the score can go negative
  • Test against the conditional threshold — 88 or more with only permitted items on the POA&M gives Conditional status; anything less gives none
  • Engage an authorised C3PAO — chosen from the Cyber AB Marketplace; results go into CMMC eMASS and flow to SPRS
  • Enter the self-assessment in SPRS — score, status date, scope, CAGE codes and POA&M usage, under a CMMC unique identifier per system
  • Submit the affirmation — required at the completion of every assessment, whether the status is Conditional or Final
Phase 5

Phase 5: POA&M Closeout

Shown only when the assessment left requirements NOT MET on a POA&M.

  • Set the deadline at 180 days from the Conditional CMMC Status Date — if the POA&M is not closed by then, the status expires
  • Give each open requirement an owner and a date — review progress weekly rather than in the last month
  • Run the POA&M closeout assessment — covering only the POA&M items, done by you for Level 2 (Self) and by a C3PAO for Level 2 (C3PAO)
  • Update SPRS and submit a new affirmation — an affirmation is required after every closeout
  • Record the Final status date — it sets the date of the next affirmation
Phase 6

Phase 6: Annual Affirmation

Runs every year from the Final CMMC Status Date.

  • Review what changed since the last assessment — new systems, sites, service providers or CUI flows that alter the scope
  • Re-check the requirements that drift — account reviews, patching, audit log review, training records and visitor logs
  • Confirm subcontractors have current affirmations — primes must ensure each one completes and maintains its own
  • Confirm cyber incident reporting works — DFARS 252.204-7012 requires a report to DoD within 72 hours of discovery
  • Submit the annual affirmation in SPRS — for each CMMC unique identifier covered by the contract
  • Diarise the next assessment — Level 1 every year; Level 2 and Level 3 within three years of the status date
Phase 7 — Level 3 Only

Phase 7: Level 3 (DIBCAC) Preparation

Shown only when a contract requires Level 3, which DoD expects to reserve for its most critical programmes.

  • Confirm Final Level 2 (C3PAO) status for the Level 3 scope — DIBCAC will not start a Level 3 assessment without it
  • Implement the 24 selected NIST SP 800-172 requirements — with the DoD-assigned parameters in table 1 to 32 CFR 170.14(c)(4)
  • Stand up a 24/7 security operations centre and a 24-hour response team — 3.6.1e and 3.6.2e, neither of which can go on a POA&M
  • Document the threat-informed risk assessment and supply chain risk plan — also excluded from a Level 3 POA&M
  • Affirm both statuses every year — Level 2 (C3PAO) and Level 3 (DIBCAC), because each assessment checks different requirements

The CMMC Rollout and Where It Paused

Part 170 sets four phases, each starting one calendar year after the one before.

16 December 2024

Programme rule in force

32 CFR Part 170 took effect, incorporating NIST SP 800-171 Rev. 2 and the February 2021 edition of SP 800-172 by reference.

10 November 2025

Phase 1 begins

The DFARS rule took effect. Solicitations can require Level 1 (Self) or Level 2 (Self) as a condition of award. This phase remains in force.

13 July 2026

Phase 2 suspended

The Department suspended Phase 2 and later milestones and set up a CMMC Reform Task Force. Class deviation 2026-O0025 carried the suspension into acquisition rules on 16 July, and Revision 3 restated it on 3 September.

10 November 2026 (suspended)

Phase 2 as written

Level 2 (C3PAO) would have become a condition of award for applicable contracts.

10 November 2027 and 10 November 2028 (on hold)

Phases 3 and 4 as written

Phase 3 would add Level 3 and C3PAO requirements at option exercise; Phase 4 would apply CMMC to all applicable contracts.

Status Requirements Assessed by POA&M Evidenced in
Level 1 (Self)15, FAR 52.204-21Contractor, annuallyNot permittedPhases 1, 2 and 6
Level 2 (Self)110, NIST SP 800-171 Rev. 2Contractor, every three yearsScore of 88 or more, closed within 180 daysPhases 1 and 3–6
Level 2 (C3PAO)110, NIST SP 800-171 Rev. 2Authorised C3PAO, every three yearsAs Level 2 (Self), closed out by the C3PAOPhases 1 and 3–6
Level 3 (DIBCAC)24 selected from NIST SP 800-172 (Feb 2021)DCMA DIBCAC, every three years80% or more, with seven requirements excludedPhase 7

At the time of review the task force’s report, due to the DoD CIO on 11 September 2026, had not been published, so the shape of any revived Phase 2 is unknown. NIST published SP 800-171 Rev. 3 in May 2024, with 97 requirements in 17 families, and SP 800-172 Rev. 3 in May 2026. Neither applies to CMMC yet: Part 170 incorporates Rev. 2 and the February 2021 SP 800-172 by reference, and the September 2026 class deviation still points to Rev. 2. Your obligations follow your own contract clauses, so treat this page as a starting point, not legal advice.

Why Run Your CMMC Cycle in CheckFlow?

1

The 180-day clock sets itself

Enter the Conditional CMMC Status Date and dynamic due dates schedule every POA&M task back from day 180. The closeout phase appears only when requirements were left open.

2

The affirmation has a named owner

A recurring annual schedule starts the affirmation checklist from the Final status date and assigns the sign-off to the Affirming Official through an approval. The activity trail shows who confirmed each check behind the signature, and when.

3

Evidence sits with the requirement

Load the 110 requirements as a data set and each assessment fills from it, with a table for status, points and evidence reference. SPRS records and the SSP version assessed attach to the task they support.

CheckFlow is not a C3PAO, a GRC platform or a scanner, and it does not submit anything to SPRS or eMASS. Keep CUI itself out of your checklists: record where evidence lives, not the controlled information. CheckFlow’s compliance checklist software shows how recurring reviews, approvals and evidence work across a whole compliance calendar.

If you also sell cloud services to agencies, the FedRAMP Compliance Checklist covers authorisation, and systems run on the Government’s behalf follow the FISMA Compliance Checklist. For a security programme wider than CUI, see the NIST CSF 2.0 Checklist.

Frequently Asked Questions

Has CMMC Phase 2 been delayed?

+

Yes. Phase 2 was due to start on 10 November 2026, and on 13 July 2026 the Department suspended it, together with later implementation milestones, pending a review by a CMMC Reform Task Force. No new date had been announced at the time of review. Phase 1 still applies, as does NIST SP 800-171 Rev. 2 through DFARS 252.204-7012.

What is the difference between CMMC Level 1 and Level 2?

+

The information involved. Level 1 applies where a contract involves only Federal Contract Information: 15 requirements from FAR 52.204-21, self-assessed every year, no POA&M allowed. Level 2 applies where CUI is involved: the 110 requirements of NIST SP 800-171 Rev. 2, assessed every three years by the contractor or a C3PAO, as the contract specifies.

What SPRS score do I need for CMMC Level 2?

+

110 for Final status. A score of at least 88, which is 80% of 110, gives Conditional status, provided every open item is a 1-point requirement (or non-FIPS-validated encryption) and none of the six excluded requirements is on the POA&M. Conditional status lasts 180 days. Below 88 there is no Level 2 status, so no award where Level 2 is required.

Does CMMC use NIST SP 800-171 Rev. 2 or Rev. 3?

+

Rev. 2. The CMMC rule incorporates the February 2020 edition of Rev. 2 (with its January 2021 updates) by reference, and the Department’s suspension memo and September 2026 class deviation both restate Rev. 2 as the baseline. Rev. 3, published in May 2024, has not been adopted for CMMC. Assess and score against Rev. 2.

How long do you have to close a CMMC POA&M?

+

180 days from the Conditional CMMC Status Date. Closure has to be confirmed by a POA&M closeout assessment covering only the open requirements, carried out by the contractor for Level 2 (Self), by a C3PAO for Level 2 (C3PAO) and by DIBCAC for Level 3. Miss the deadline and the conditional status expires.

Who signs the CMMC annual affirmation?

+

The Affirming Official: a senior representative of the contractor who is responsible for CMMC compliance and has authority to affirm it. Affirmations are entered in SPRS after every assessment and POA&M closeout, and annually after the Final status date.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Every Affirmation On Time, Every POA&M Closed Inside 180 Days

Free trial — no credit card required.