Resource Guides

CMMC Compliance Checklist for Defense Contractors

A practical, step-by-step CMMC 2.0 compliance checklist covering all three levels, Phase 1 and Phase 2 timelines, the 110 NIST SP 800-171 controls, C3PAO selection, SPRS scoring, and cost planning.

CMMC 2.0 Compliance Checklist: A Practical Guide for Defense Contractors

If you handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) as part of your defense work, you need the appropriate CMMC status when it appears in applicable DoD solicitations and contracts. Phase 1 enforcement is already live. Phase 2 begins in November 2026. This guide breaks the entire process into concrete steps so you can move from uncertainty to a clear plan of action.

What CMMC 2.0 Is and Why It Matters Now

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the Department of Defense’s framework for ensuring that every company in the defense industrial base meets baseline cybersecurity standards before receiving contract awards. The final rule took effect on December 16, 2024 (Source: Federal Register Vol. 89, No. 175, Department of Defense, September 2024).

The stakes are straightforward: without the required CMMC status at the appropriate level, your company may not be eligible for applicable new DoD contract awards. This is not a future possibility. It is current policy.

As of October 2025, only 1% of defense contractors reported being fully prepared for CMMC certification, down from 8% in 2023 and 4% in 2024 (Source: State of the DIB Report 2025, CyberSheath/Merrill Research, October 2025). Approximately 80,000 defense contractors will need Level 2 certification through a third-party assessment (Source: CMMC Implementation, DoD CIO, 2025). Only about 270 organizations currently hold final CMMC Level 2 certificates (Source: State of the DIB Report 2025, CyberSheath/Merrill Research, October 2025).

The gap between what is required and what the industrial base has achieved is significant. It is also an opportunity: companies that certify early will be positioned to capture contracts that competitors cannot pursue.

The Three CMMC Levels

Level 1: Foundational

  • Who needs it: Companies handling only Federal Contract Information (FCI)
  • Controls: 15 basic cybersecurity practices from FAR 52.204-21
  • Assessment: Annual self-assessment
  • Estimated cost: $5,000 to $15,000 (Source: CMMC Certification Cost Breakdown, Secureframe, 2026)

Level 2: Advanced

  • Who needs it: Companies handling Controlled Unclassified Information (CUI), which includes the vast majority of defense contractors working on sensitive programs
  • Controls: All 110 security controls from NIST SP 800-171 Rev 2, organized across 14 control families
  • Assessment: Third-party assessment by an authorized C3PAO (some contracts may allow self-assessment during Phase 1)
  • Certification validity: Three years
  • Estimated total cost: $75,000 to $150,000 for small to mid-size businesses, including remediation, documentation, and assessment fees (Source: CMMC Compliance Costs 2026, CISPOINT, January 2026)

Level 3: Expert

  • Who needs it: Companies handling the most sensitive CUI on critical defense programs
  • Controls: 110 NIST SP 800-171 controls plus 24 additional controls from NIST SP 800-172
  • Assessment: Government-led assessment by DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)
  • Estimated cost: Can exceed $500,000 (Source: CMMC Certification Cost Breakdown, Secureframe, 2026)

Most defense contractors will need Level 2. If you are unsure which level applies to you, review the CUI markings on information you receive from DoD programs or consult the contracting officer on your current contracts.

Phase 1 and Phase 2 Timelines

Phase 1 (November 10, 2025 to November 9, 2026)

Phase 1 is currently active. During this phase:

  • CMMC Level 1 and Level 2 self-assessments are required in applicable new DoD solicitations
  • The DoD may require Level 2 C3PAO certification at its discretion on select contracts
  • All new contracts containing DFARS 252.204-7021 will require a CMMC certification at the appropriate level

Phase 2 (Beginning November 10, 2026)

Phase 2 introduces third-party certification where applicable:

  • Level 2 C3PAO assessments become required where specified (self-assessment is no longer sufficient for most CUI-handling contracts)
  • Level 3 DIBCAC assessments may begin appearing in solicitations
  • Contracts awarded before Phase 2 may include CMMC requirements at option exercise

Full Implementation (By November 2028)

CMMC compliance becomes mandatory across applicable DoD contracts involving FCI or CUI (Source: CMMC 2.0 Rollout Update, Pivot Point Security, 2025).

Checklist: Preparing for CMMC Level 2 Certification

Phase 1: Assess Your Current State (Weeks 1 to 4)

  • Identify your CUI scope. Determine exactly which systems, networks, and personnel handle CUI. This defines the boundary of your assessment. Everything within this boundary must comply with all 110 controls.
  • Conduct a gap assessment against NIST SP 800-171. Map your current security practices against each of the 110 controls. Be honest about gaps; undiscovered gaps during the actual assessment will be worse than gaps you identify and plan to remediate now.
  • Calculate your SPRS score. The Supplier Performance Risk System (SPRS) score ranges from 110 (full compliance) to -203 (no compliance). Each control carries a weighted value of 5, 3, or 1 points. Your target is a minimum score of 88 for Conditional certification status (Source: SPRS Scoring & POA&M Guide, Elevate Consulting, 2026).
  • Submit your SPRS score. Only 42% of defense contractors have submitted SPRS scores (Source: State of the DIB Report 2025, CyberSheath/Merrill Research, October 2025). This is a baseline requirement. If you have not submitted, you are already non-compliant with DFARS 252.204-7020.
  • Develop or update your System Security Plan (SSP). The SSP documents how each of the 110 controls is implemented in your environment. Fewer than 50% of defense contractors have completed the required documentation (Source: State of the DIB Report 2025, CyberSheath/Merrill Research, October 2025).

Phase 2: Remediate Gaps (Weeks 5 to 20)

  • Build a Plan of Action and Milestones (POA&M). For any control where you have a gap, document the specific deficiency, the remediation plan, the responsible party, and the completion date. POA&Ms are permitted for a limited number of low-impact deficiencies, but each must be closed within 180 days of receiving Conditional certification (Source: CMMC Assessment Guide Level 2 v2.13, DoD CIO, 2025).
  • Implement missing technical controls. Common gaps include:
    • Multi-factor authentication (only 27% of contractors have deployed MFA)
    • Endpoint detection and response (only 25% have EDR in place)
    • Patch management systems (only 22% have them)
    • Vulnerability management programs (21% have them)
    • Secure backup technologies (only 29% deployed) (Source: State of the DIB Report 2025, CyberSheath/Merrill Research, October 2025)
  • Establish continuous monitoring. CMMC is not a point-in-time exercise. You need ongoing log collection, alerting, and incident response procedures.
  • Train your workforce. Security awareness training is required under NIST SP 800-171 Control Family 3.2 (Awareness and Training). Document the training, including dates, attendees, and content covered.
  • Establish an incident response plan. You need a documented and tested plan for responding to cybersecurity incidents, including notification procedures to DoD.

Phase 3: Prepare for Assessment (Weeks 16 to 24)

  • Select a C3PAO. The Cyber AB maintains the marketplace of authorized C3PAOs at cyberab.org. Currently, only about 103 authorized C3PAOs exist to serve approximately 80,000 contractors (Source: CMMC CON 2026 Briefing, CyberSheath, 2026). Wait times for assessments are projected to exceed 18 months by Q3 2026. Start this process immediately.
  • Conduct a readiness assessment. Before engaging a C3PAO for your formal assessment, consider a pre-assessment or readiness review (conducted by a Registered Practitioner Organization, not the same C3PAO that will do your certification assessment) to identify any remaining issues.
  • Gather evidence for each control. For every one of the 110 controls, you need documented evidence that the control is implemented and operating effectively. This includes policies, configuration screenshots, log samples, training records, and interview preparation.
  • Prepare key personnel for interviews. Assessors will interview your IT staff, system administrators, and leadership. They need to be able to articulate how each control is implemented, not just that it exists on paper.
  • Verify your SSP and POA&M are current. These are the first documents an assessor will review. Inconsistencies between your documentation and your actual environment will generate findings.

Phase 4: Certification and Maintenance (Ongoing)

  • Complete the C3PAO assessment. The assessment typically takes 3 to 5 days on-site, depending on the size and complexity of your environment.
  • Close any POA&M items within 180 days. If you receive Conditional certification, you must remediate all identified deficiencies and pass a closeout assessment within 180 days. Failure to close results in loss of certification.
  • Maintain compliance continuously. Your certification is valid for three years, but compliance is ongoing. Document changes to your environment, update your SSP, and conduct annual self-assessments between certification cycles.
  • Plan for recertification. Begin preparing for your next C3PAO assessment at least 12 months before your current certification expires.

The 14 NIST SP 800-171 Control Families

Level 2 requires compliance across all 14 families. Use this as a high-level checklist to track your progress:

Control Family Controls Focus Area
Access Control (AC) 22 Who can access what systems and data
Awareness & Training (AT) 3 Security training and role-based awareness
Audit & Accountability (AU) 9 Logging, monitoring, and audit trail integrity
Configuration Management (CM) 9 Baseline configurations and change control
Identification & Authentication (IA) 11 Identity verification and credential management
Incident Response (IR) 3 Detection, reporting, and response procedures
Maintenance (MA) 6 System maintenance controls and remote access
Media Protection (MP) 9 Protection of digital and physical media
Personnel Security (PS) 2 Screening and personnel management
Physical Protection (PE) 6 Facility and equipment physical security
Risk Assessment (RA) 3 Vulnerability scanning and risk identification
Security Assessment (CA) 4 Internal assessments and system connections
System & Communications Protection (SC) 16 Network boundaries and data transmission
System & Information Integrity (SI) 7 Flaw remediation and malicious code protection

Cost Planning

Be realistic about the investment. Here is what small to mid-size defense contractors should budget for CMMC Level 2:

Category Estimated Range
Gap assessment and consulting $15,000 to $50,000
Technical remediation (tools, infrastructure, configuration) $20,000 to $150,000
Documentation (SSP, POA&M, policies, procedures) $12,000 to $60,000
C3PAO assessment fees $30,000 to $75,000
Total estimated investment $75,000 to $150,000+

(Source: CMMC Compliance Costs 2026, CISPOINT, January 2026; CMMC Certification Cost Breakdown, Secureframe, 2026)

The DoD’s own estimates place average Level 2 C3PAO assessment costs at $105,000 to $118,000 when including all preparation and assessment activities (Source: CMMC 2.0 Rule Analysis, Department of Defense, 2024). For context, the average small business CMMC compliance investment is approximately $138,000 (Source: CMMC Cost Analysis, CISPOINT, January 2026).

This is a significant investment. But consider the alternative: between 33,000 and 44,000 companies are projected to exit the defense market between 2025 and 2027 due to compliance costs (Source: CMMC Cost Analysis, CISPOINT, January 2026). Every company that leaves creates contract opportunities for those that stay.

What Happens If You Do Not Certify

The consequences are direct and immediate:

  1. You cannot win new DoD contracts. Solicitations requiring CMMC certification will exclude non-certified contractors. No exceptions, no waivers.
  2. Existing contracts are at risk. As contracts come up for recompete or option exercise, CMMC requirements will be incorporated. Your incumbency provides no protection without certification.
  3. Prime contractors will replace you. Primes are increasingly requiring CMMC certification from their subcontractors as a condition of teaming. If you cannot certify, you will be replaced by someone who can.
  4. Your SPRS score is visible. DoD contracting officers can see your SPRS submission (or the absence of one) when evaluating your company for awards.

How US Defense Group Can Help

Navigating CMMC compliance while running your business and delivering on existing contracts is a capacity problem as much as a knowledge problem. US Defense Group works with defense and dual-use technology companies to build the operational capabilities required for certification, connecting you with the right advisors, tools, and assessment organizations at each stage of the process.

Through Launcher Station, our accelerator for defense technology companies, we provide hands-on operational support that includes cybersecurity compliance readiness as a core element of preparing companies for sustained growth in the defense market. We understand that CMMC is not just a technical exercise; it is a business decision that determines whether your company will compete for the next generation of defense contracts.

Next Steps

If you are a defense contractor or dual-use technology company working toward CMMC certification, the time to build your compliance roadmap is now, not when the first solicitation requires it.

Sources

Questions about CMMC compliance

What is CMMC compliance?

Cybersecurity Maturity Model Certification compliance is the Department of Defense process for verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. The required status and assessment type depend on the information involved and the CMMC requirement stated in the solicitation or contract.

Source: Department of Defense Chief Information Officer, About CMMC

Which CMMC level applies to a defense contractor?

The Department of Defense assigns the required CMMC level in the procurement. Level 1 addresses foundational safeguards for Federal Contract Information, Level 2 addresses protection of Controlled Unclassified Information, and Level 3 adds selected enhanced requirements for the most sensitive programs.

Source: Department of Defense Chief Information Officer, CMMC resources

Last reviewed , by US Defense Group Editorial Team.

Need help navigating this?