CMMC Readiness Checklist
Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.
Published · v1.0.0 · 2026-08-01
Academy · Resources
Checklists, templates, guides, quick-reference sheets, and practice exercises — written in plain language, versioned, printable, and free unless marked premium.
10
Checklists
16
Templates
13
Guides
6
Quick reference sheets
7
Readiness exercises
52 resources
Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.
Published · v1.0.0 · 2026-08-01
A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.
Published · v1.0.0 · 2026-08-01
A fast, honest look at your current security posture across identity, devices, data, people, and response.
Published · v1.0.0 · 2026-08-01
The thirty-day baseline: the controls that stop the majority of small-business incidents, ordered by impact.
Published · v1.0.0 · 2026-08-01
What to put in place before your first federal award creates security obligations you cannot meet.
Published · v1.0.0 · 2026-08-01
A proportionate review for the vendors that actually hold your data — without sending a two-hundred-question survey.
Published · v1.0.0 · 2026-08-01
Turn what you already do into evidence: what to capture, how to label it, and how long to keep it.
Published · v1.0.0 · 2026-08-01
Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.
Published · v1.0.0 · 2026-08-01
The habits every employee should be able to demonstrate, written as a self-check rather than a lecture.
Published · v1.0.0 · 2026-08-01
Day-one security steps that prevent most access and offboarding problems later.
Published · v1.0.0 · 2026-08-01
The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.
Published · v1.0.0 · 2026-08-01
What employees may and may not do with company systems, data, devices, and AI tools.
Published · v1.0.0 · 2026-08-01
Modern, usable password and authentication rules that people can actually follow.
Published · v1.0.0 · 2026-08-01
Security expectations for home offices, travel, personal devices, and public networks.
Published · v1.0.0 · 2026-08-01
A short, usable plan: who to call, what to do first, what to write down, and who must be notified.
Published · v1.0.0 · 2026-08-01
One list of the devices, accounts, and services you are actually responsible for protecting.
Published · v1.0.0 · 2026-08-01
A single record of who holds your data, what they hold, and when you last looked at them.
Published · v1.0.0 · 2026-08-01
Track the risks you know about, who owns them, and what you decided to do — including accepting them.
Published · v1.0.0 · 2026-08-01
A plan of action and milestones you can actually maintain, with the fields assessors expect.
Published · v1.0.0 · 2026-08-01
A section-by-section outline for a System Security Plan a small business can maintain.
Published · v1.0.0 · 2026-08-01
A single record proving who trained, when, on what version, and with what result.
Published · v1.0.0 · 2026-08-01
The once-a-year pass that keeps a program from quietly going stale.
Published · v1.0.0 · 2026-08-01
A short signature page confirming an employee read and understood a specific policy version.
Published · v1.0.0 · 2026-08-01
Define your data levels and the handling rules that follow from each one.
Published · v1.0.0 · 2026-08-01
A repeatable quarterly review of who has access to what, with a decision recorded for each row.
Published · v1.0.0 · 2026-08-01
Proof that backups exist, run, and have actually been restored at least once.
Published · v1.0.0 · 2026-08-01
A plain-language explanation of the Cybersecurity Maturity Model Certification program, who it applies to, and what preparation actually involves.
Published · v1.0.0 · 2026-08-01
The requirement set that governs protecting Controlled Unclassified Information in non-federal systems, explained without the jargon.
Published · v1.0.0 · 2026-08-01
A System Security Plan describes your system and how each control is implemented. Here is what belongs in it and how to keep it current.
Published · v1.0.0 · 2026-08-01
A Plan of Action and Milestones is how you honestly track gaps. Done well, it builds trust; done badly, it destroys it.
Published · v1.0.0 · 2026-08-01
Your boundary decides how much compliance work you have. Learn how to draw one that is defensible and small.
Published · v1.0.0 · 2026-08-01
How to recognize CUI, why marking matters, and what changes the moment you handle it.
Published · v1.0.0 · 2026-08-01
How security obligations actually reach you: clauses, flow-downs, and the questions to ask before you sign.
Published · v1.0.0 · 2026-08-01
The six weeks before an assessment, sequenced: documentation, evidence, owner rehearsal, and gap honesty.
Published · v1.0.0 · 2026-08-01
A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.
Published · v1.0.0 · 2026-08-01
The recurring, expensive errors we see small businesses make — and the cheap correction for each.
Published · v1.0.0 · 2026-08-01
What counts as evidence, how to capture it without slowing the business, and how to keep it usable.
Published · v1.0.0 · 2026-08-01
Preventive, detective, corrective, administrative, technical, physical — what the categories mean and why it matters when you write narratives.
Published · v1.0.0 · 2026-08-01
How to answer customer security questionnaires quickly, accurately, and without overpromising.
Published · v1.0.0 · 2026-08-01
The acronyms that appear in contracts and assessments, defined in one line each.
Published · v1.0.0 · 2026-08-01
Who does what in a small-business program, sized for teams without a security department.
Published · v1.0.0 · 2026-08-01
What to do in the first hour, first day, and first week of a suspected incident.
Published · v1.0.0 · 2026-08-01
Post it by the desk: the current, sane guidance on passwords and multi-factor authentication.
Published · v1.0.0 · 2026-08-01
A pocket guide to capturing artifacts that will still make sense in six months.
Published · v1.0.0 · 2026-08-01
A realistic phase-by-phase timeline for a small business standing up a program.
Published · v1.0.0 · 2026-08-01
Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.
Published · v1.0.0 · 2026-08-01
Sort realistic records into classification levels and defend the handling rules that follow.
Published · v1.0.0 · 2026-08-01
Practice separating CUI from FCI and from ordinary business information.
Published · v1.0.0 · 2026-08-01
Turn vague intentions into policy statements that are testable and enforceable.
Published · v1.0.0 · 2026-08-01
Play the assessor: decide whether sample artifacts actually prove the control claimed.
Published · v1.0.0 · 2026-08-01
Draft one System Security Plan section end to end, using the narrative pattern assessors expect.
Published · v1.0.0 · 2026-08-01
Score yourself honestly across six areas and turn the two lowest into a short plan.
Published · v1.0.0 · 2026-08-01
Resource library v1.2.0 · 52 resources. All material is original ComplianceAnvil content written from public, authoritative sources. These resources are educational readiness material — ComplianceAnvil is not a certification authority, assessor, or law firm, and nothing here is legal advice or a compliance assessment.