CMMC Level 2 self-assessment checklist

CMMC Level 2 assesses the 110 security requirements of NIST SP 800-171 Rev 2. For contracts that allow self-assessment, your company runs the assessment, posts the score in SPRS, and a senior official affirms it annually. Here is the whole process as a checklist, followed by what each of the 14 control families actually asks of a small shop.

The process, step by step

  1. 01

    Confirm Level 2 self-assessment actually applies to you

    Check your contracts and ask your prime. Level 2 applies when you handle CUI; whether you need a self-assessment or a third-party (C3PAO) certification depends on what the solicitation specifies. If you only handle Federal Contract Information, Level 1's 15 basic practices apply instead.

  2. 02

    Scope your assessment

    Per the DoD Level 2 scoping guide, identify the assets that process, store, or transmit CUI; the assets that protect them; specialized assets (machine controllers, test equipment); and what's out of scope. A smaller, well-separated scope is the single biggest cost lever a small business has.

  3. 03

    Assess all 110 requirements against the 320 assessment objectives

    Each requirement in NIST SP 800-171 Rev 2 breaks into assessment objectives in NIST SP 800-171A, and a requirement is met only when every objective is met. Record a status for each: implemented, partially implemented, not implemented, or not applicable.

  4. 04

    Calculate your SPRS score

    Start at 110 and subtract each unmet requirement's fixed weight (5, 3, or 1) from the DoD Assessment Methodology. No partial credit, with two narrow exceptions for MFA and FIPS-validated encryption. The floor is −203.

  5. 05

    Write the System Security Plan

    The SSP describes your environment and how each of the 110 requirements is implemented. Without one, a DoD assessment cannot be conducted at all — it is the document everything else hangs on.

  6. 06

    Put every gap in a POA&M with dates and owners

    Each unmet requirement gets a Plan of Action & Milestones entry: the deficiency, the planned fix, a milestone date, and a responsible person. Under CMMC, POA&Ms are time-boxed (180 days) and only allowed for a limited set of lower-weight requirements — the highest-weight controls must be met, not planned.

  7. 07

    Submit your score in SPRS and affirm it

    Post the score, scope, assessment date, and your projected 110 date through the PIEE portal. A senior company official (the Affirming Official) must affirm continuing compliance annually — and the affirmation carries False Claims Act weight, so submit the honest number.

  8. 08

    Re-assess when things change, and keep score current

    New servers, a new cloud service, an office move, or staff turnover can change answers. The self-assessment is valid three years, but the annual affirmation means your posture has to stay true year-round.

The 14 control families in plain English

All 110 requirements fall into 14 families. The counts below are from the official Rev 2 structure — together they break into 320 assessment objectives.

Access Control AC · 22 requirements

Who and what is allowed to reach CUI, and the limits placed on that access — accounts, privileges, remote access, wireless, mobile devices, and external/public systems.

Awareness and Training AT · 3 requirements

Making sure owners, administrators, and users understand the security risks in their work and are trained to handle CUI and recognize threats.

Audit and Accountability AU · 9 requirements

Recording system activity so actions can be traced to individuals, and reviewing those logs to detect and investigate problems.

Configuration Management CM · 9 requirements

Establishing and maintaining secure, documented settings and inventories for your systems, and controlling how changes are made.

Identification and Authentication IA · 11 requirements

Proving that users and devices are who they claim to be before granting access — unique accounts, passwords, and multi-factor authentication.

Incident Response IR · 3 requirements

Being ready to detect, report, contain, and recover from security incidents, and practicing the plan.

Maintenance MA · 6 requirements

Performing system maintenance safely — controlling tools, media, remote maintenance, and the people who do it.

Media Protection MP · 9 requirements

Protecting, controlling, marking, transporting, and safely disposing of media (drives, paper, backups) that hold CUI.

Personnel Security PS · 2 requirements

Screening people before granting access to CUI and protecting CUI when staff are terminated or change roles.

Physical Protection PE · 6 requirements

Limiting and monitoring physical access to the facilities, equipment, and systems that handle CUI, including at alternate work sites.

Risk Assessment RA · 3 requirements

Identifying and evaluating risks to your systems and CUI, including scanning for and remediating vulnerabilities.

Security Assessment CA · 4 requirements

Periodically checking that controls work, tracking gaps in a plan of action, monitoring controls over time, and maintaining the system security plan.

System and Communications Protection SC · 16 requirements

Protecting information as it moves across and between systems — network boundaries, segmentation, encryption, and secure communications.

System and Information Integrity SI · 7 requirements

Finding and fixing flaws, protecting against malicious code, and monitoring systems and traffic for attacks.

Where small shops lose the most points

The DoD methodology weights each requirement 5, 3, or 1 — and the 5-point requirements cluster in things small businesses rarely formalize: multifactor authentication, incident response, security awareness training, audit logging, and access control policy. The good news is that several are cheap to fix (often configuration changes in Microsoft 365 you already pay for). Get your estimated score with the free SPRS score calculator, or check the Level 1 basics first with the free Level 1 checker.

Frequently asked questions

Self-assessment or C3PAO certification — which do I need?
The solicitation tells you. CMMC Level 2 contracts specify either a self-assessment or a third-party certification assessment by a C3PAO. Many CUI-handling contracts will require certification as the CMMC rollout phases in — but the requirements assessed are identical (the 110 of NIST SP 800-171 Rev 2), so the preparation work is the same.
How long does a Level 2 self-assessment take a small business?
With records in order, the assessment itself takes days, not months — the long pole is remediation of gaps it finds. A first pass through all 110 requirements with a structured questionnaire takes an owner roughly one to two hours; writing the SSP and POA&M from scratch is what consumes weeks, which is the part worth automating.
Can I have POA&Ms and still be CMMC Level 2 compliant?
Only within limits: a conditional self-assessment requires a minimum SPRS score of 88 (80% of 110), POA&M items must be limited to 1-point requirements (with narrow exceptions), and everything must be closed out within 180 days. The highest-weight requirements cannot sit on a POA&M.
Is this checklist based on NIST SP 800-171 Rev 2 or Rev 3?
Rev 2 — 110 requirements and 320 assessment objectives — because that is what CMMC 2.0 assesses against. Rev 3 exists but is not yet the CMMC baseline; verify the current state on the DoD CIO's CMMC page before you assess.

Run the whole checklist in one sitting.

ClearPath's plain-English questionnaire walks you through all 110 requirements, computes your exact SPRS score with the official methodology, and drafts the SSP and POA&M — ready for your review in Word.

Start my self-assessment →

Informational only — not a compliance determination, an assessment, or legal advice. Requirements are defined by NIST SP 800-171 Rev 2, NIST SP 800-171A, the DoD Assessment Methodology, and 32 CFR Part 170; always verify against the official publications.