CMMC Self-Assessment Checklist
The Pentagon does not often move a compliance deadline in your favor, but here we are: on July 13 the Department of War suspended CMMC Phase 2, the November 10 transition that would have started writing C3PAO certification requirements into new solicitations. A Reform Task Force now has 60 days to decide what CMMC wants to be when it grows up. If you had a countdown clock on the wall, you may unplug it. Do not unplug the log server.
Because here is the part the headlines keep skipping: the assessor is not coming in November, but your obligations never left. DFARS 252.204-7012 and the full NIST SP 800-171 Rev 2 standard are untouched, and Level 2 self-assessment is now the operative regime in new solicitations. Congratulations: you are your own assessor. The good news is that the assessor already knows where everything is. The bad news is that the assessor already knows where everything is.
Scope note, updated July 2026: this checklist prepares you for an honest Level 2 self-assessment and keeps you ready for any future third-party or government-led (DIBCAC) assessment. During the suspension, C3PAO certification cannot be required in new solicitations; your SPRS score and your affirming official’s attestation carry the weight instead. That part is not a joke: the Department of Justice keeps bringing False Claims Act cases over misrepresented cybersecurity compliance, so use this list to prepare, not to round up. The clause-level detail lives in the DFARS clause guide.
Forty checks in four passes: 10 on documentation, 12 on technical controls, 10 on organizational process, and 8 on assessment-day logistics. Work them in order; the documentation pass is where self-assessments quietly fail.
Documentation Readiness
Policies, plans, and procedures an assessor would request on Day 1. In a self-assessment, "the assessor" is you, so request them from yourself and see what actually turns up.
- System Security Plan (SSP) is complete, current, and covers all 110 controls
- SSP includes accurate system boundary diagram with all CUI data flows
- SSP identifies all interconnections and external system services
- POA&M is current with realistic milestones and responsible parties
- All security policies are signed by an authorizing official and dated within 12 months
- Incident Response Plan exists and includes CUI-specific procedures
- Configuration Management Plan documents baseline configurations
- Access Control Policy defines account types, approval, and review processes
- Media Protection Policy covers CUI marking, handling, storage, and destruction
- Personnel Security Policy includes screening, termination, and transfer procedures
Technical Controls
System configurations and security mechanisms that must be demonstrated, not described. If the evidence is a screenshot you took just now, note the date honestly.
- Multi-factor authentication enforced for all privileged and remote access
- FIPS 140-2 validated encryption for CUI in transit (TLS 1.2+)
- FIPS 140-2 validated encryption for CUI at rest (AES-256 or equivalent)
- Audit logging enabled for all CUI access, authentication, and privilege use
- Audit logs protected from unauthorized modification and retained per policy
- Session lock activates after defined period of inactivity (≤15 minutes recommended)
- Unsuccessful login attempts limited and accounts locked after threshold
- System components inventoried with authorized software baselines
- Vulnerability scanning performed regularly with documented remediation timelines
- Network segmentation isolates CUI enclaves from general-purpose networks
- Wireless access points secured with enterprise authentication (802.1X)
- Mobile devices governed by MDM with remote wipe capability
Organizational Processes
The ongoing activities that prove the program runs between assessments. These are the items that separate a real program from a binder.
- Security awareness training conducted for all personnel within 30 days of hire and annually
- Role-based training provided for personnel with significant security responsibilities
- Background checks completed for all personnel with CUI access
- Access reviews conducted at least quarterly for CUI systems
- Account management includes timely disable/removal on termination or transfer
- Physical access to CUI processing/storage areas is controlled and logged
- Visitor access requires escort and logging
- Security assessments performed at least annually
- Risk assessments conducted and documented with remediation plans
- Configuration change control process in place with security impact analysis
Assessment Day Preparation
Written for the day a third-party assessor arrives. During the suspension, treat it as the dress-rehearsal list: DIBCAC still conducts government-led assessments, and if Phase 2 comes back you will be glad you kept the muscle.
- Assessment team briefed on system boundaries, CUI types, and data flows
- Technical POCs identified for each control family and available during assessment
- Evidence artifacts organized by control family (screenshots, configs, policy excerpts)
- Test/demo accounts prepared for assessor to verify technical controls
- Conference room or virtual meeting environment reserved for assessment interviews
- Key personnel schedules confirmed - no vacations during assessment week
- SSP and POA&M provided to assessors at least 2 weeks in advance
- Known weaknesses documented in POA&M (no surprises for the assessor)
Member discussion