> ## Content Index
> Fetch the complete content index at: https://www.cmmcoperator.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CMMC Self-Assessment Checklist
- URL: https://www.cmmcoperator.com/cmmc-self-assessment-checklist/
- Published: 2026-07-17T02:12:53.000Z
- Updated: 2026-07-17T02:13:55.000Z
- Description: Forty checks in four passes, updated for the self-assessment era: with Phase 2 suspended, you are your own assessor now. Prepare like the real one still shows up.
- Author: HydratedSec
- Tags: Documentation & Assessment, NIST 800-171

The Pentagon does not often move a compliance deadline in your favor, but here we are: on July 13 the Department of War [suspended CMMC Phase 2](https://www.cmmcoperator.com/cmmc-phase-2-suspended/), the November 10 transition that would have started writing C3PAO certification requirements into new solicitations. A Reform Task Force now has 60 days to decide what CMMC wants to be when it grows up. If you had a countdown clock on the wall, you may unplug it. Do not unplug the log server.

Because here is the part the headlines keep skipping: the assessor is not coming in November, but your obligations never left. DFARS 252.204-7012 and the full NIST SP 800-171 Rev 2 standard are untouched, and Level 2 *self*\-assessment is now the operative regime in new solicitations. Congratulations: you are your own assessor. The good news is that the assessor already knows where everything is. The bad news is that the assessor already knows where everything is.

*Scope note, updated July 2026: this checklist prepares you for an honest Level 2 self-assessment and keeps you ready for any future third-party or government-led (DIBCAC) assessment. During the suspension, C3PAO certification cannot be required in new solicitations; your SPRS score and your affirming official’s attestation carry the weight instead. That part is not a joke: the Department of Justice keeps bringing False Claims Act cases over misrepresented cybersecurity compliance, so use this list to prepare, not to round up. The clause-level detail lives in [the DFARS clause guide](https://www.cmmcoperator.com/dfars-clauses-behind-cmmc/).*

Forty checks in four passes: 10 on documentation, 12 on technical controls, 10 on organizational process, and 8 on assessment-day logistics. Work them in order; the documentation pass is where self-assessments quietly fail.

## Documentation Readiness

Policies, plans, and procedures an assessor would request on Day 1\. In a self-assessment, "the assessor" is you, so request them from yourself and see what actually turns up.

- System Security Plan (SSP) is complete, current, and covers all 110 controls
- SSP includes accurate system boundary diagram with all CUI data flows
- SSP identifies all interconnections and external system services
- POA&M is current with realistic milestones and responsible parties
- All security policies are signed by an authorizing official and dated within 12 months
- Incident Response Plan exists and includes CUI-specific procedures
- Configuration Management Plan documents baseline configurations
- Access Control Policy defines account types, approval, and review processes
- Media Protection Policy covers CUI marking, handling, storage, and destruction
- Personnel Security Policy includes screening, termination, and transfer procedures

## Technical Controls

System configurations and security mechanisms that must be demonstrated, not described. If the evidence is a screenshot you took just now, note the date honestly.

- Multi-factor authentication enforced for all privileged and remote access
- FIPS 140-2 validated encryption for CUI in transit (TLS 1.2+)
- FIPS 140-2 validated encryption for CUI at rest (AES-256 or equivalent)
- Audit logging enabled for all CUI access, authentication, and privilege use
- Audit logs protected from unauthorized modification and retained per policy
- Session lock activates after defined period of inactivity (≤15 minutes recommended)
- Unsuccessful login attempts limited and accounts locked after threshold
- System components inventoried with authorized software baselines
- Vulnerability scanning performed regularly with documented remediation timelines
- Network segmentation isolates CUI enclaves from general-purpose networks
- Wireless access points secured with enterprise authentication (802.1X)
- Mobile devices governed by MDM with remote wipe capability

## Organizational Processes

The ongoing activities that prove the program runs between assessments. These are the items that separate a real program from a binder.

- Security awareness training conducted for all personnel within 30 days of hire and annually
- Role-based training provided for personnel with significant security responsibilities
- Background checks completed for all personnel with CUI access
- Access reviews conducted at least quarterly for CUI systems
- Account management includes timely disable/removal on termination or transfer
- Physical access to CUI processing/storage areas is controlled and logged
- Visitor access requires escort and logging
- Security assessments performed at least annually
- Risk assessments conducted and documented with remediation plans
- Configuration change control process in place with security impact analysis

## Assessment Day Preparation

Written for the day a third-party assessor arrives. During the suspension, treat it as the dress-rehearsal list: DIBCAC still conducts government-led assessments, and if Phase 2 comes back you will be glad you kept the muscle.

- Assessment team briefed on system boundaries, CUI types, and data flows
- Technical POCs identified for each control family and available during assessment
- Evidence artifacts organized by control family (screenshots, configs, policy excerpts)
- Test/demo accounts prepared for assessor to verify technical controls
- Conference room or virtual meeting environment reserved for assessment interviews
- Key personnel schedules confirmed - no vacations during assessment week
- SSP and POA&M provided to assessors at least 2 weeks in advance
- Known weaknesses documented in POA&M (no surprises for the assessor)

Checklists tell you what to look at; they do not write the documents. The free [Mac-First Readiness Pack](https://www.cmmcoperator.com/cmmc-l2-readiness-pack/) includes the pre-assessment self-assessment workbook with estimated SPRS scoring, and [the CMMC Operator Suite](https://www.cmmcoperator.com/cmmc-operator-suite/) is the SSP, policy, procedure, and POA&M documentation system the checklist keeps pointing at.