Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intended audience
Owners and IT leads at defense-supply-chain contractors
Difficulty
Intermediate
Estimated time
45 minutes
Access
Free
CMMC
NIST SP 800-171
DFARS
Government contracting
Manufacturing
Professional services

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Determine whether your contracts involve FCI, CUI, or neither, and what that means for scope.
  • Define a written system boundary that names the systems, people, and cloud services in scope.
  • Distinguish between a control that is documented and one that has current, dated evidence behind it.
  • Build a POA&M that tracks every control gap toward a target date.

How to use this checklist

Complete the items in order. Anything you cannot answer with a document or a screenshot is a gap, not a maybe. Track unresolved items in your POA&M so nothing gets lost between now and your assessment.

What good looks like

  • A written system boundary that names the systems and people in scope.
  • A System Security Plan that describes how each control is actually implemented.
  • Evidence dated within the last twelve months for every claim you make.

Key takeaways

  • Scope determination comes before any control work, because it decides which systems and clauses apply.
  • A System Security Plan is only credible when it describes how a control is actually implemented, not just that a policy exists.
  • Evidence must be dated within roughly the last twelve months to support a current claim.
  • Gaps belong in a POA&M with an owner and a target date rather than left undocumented.

Checklist

Progress0 of 16 (0%)

Progress is saved in this browser only. It is not a compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 2
Knowledge check

80% required to pass. Answers are graded on our servers.

1. According to the checklist, what should you do first before working through controls?

2. What does the checklist say counts as evidence for a control claim?

3. What is a POA&M used for in this checklist?

4. What must a written system boundary include, per the checklist?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Guide

What is CMMC?

A plain-language explanation of the Cybersecurity Maturity Model Certification program, who it applies to, and what preparation actually involves.

Beginner
12 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Guide

What is NIST SP 800-171?

The requirement set that governs protecting Controlled Unclassified Information in non-federal systems, explained without the jargon.

Intermediate
14 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.