Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630

CMMC checklist for defense contractors

A practical checklist to help your team organize the steps from scoping through assessment readiness.

ChecklistReadinessCUI scope

Author: Velocity CMMC Team

Reviewer: Velocity CMMC Review Team

Last reviewed: July 21, 2026

Official sources reviewed

Contract language, current regulations, and official CMMC program guidance control. Last reviewed July 21, 2026 for current CMMC program sources.

  • DoD CMMC Resources & Documentation
  • 32 CFR Part 170
  • DFARS 252.204-7021
  • NIST SP 800-171 Rev. 2
  • CMMC Level 2 Assessment Guide via DoD Resources

Use this checklist in the right order

The most common mistake is treating the checklist like a shopping list of controls. Start with scope, then move into control validation, documentation, remediation, and sustained maintenance.

Readiness checklist

  • Confirm whether the company handles FCI, CUI, or both.
  • Identify where CUI enters, resides, moves, and leaves the environment.
  • Create or refresh the asset inventory and the network / data-flow diagrams.
  • Define the assessment boundary and identify systems providing security protection.
  • Review identity, access, endpoint, logging, encryption, backup, and incident response practices.
  • Collect existing policies, procedures, diagrams, inventories, and implementation records.
  • Build the remediation roadmap.
  • Prepare SSP, POA&M, and supporting evidence structure.
  • Plan for the operating model after the initial readiness sprint.

Want us to walk through this checklist with your team?

Book a CUI scoping and readiness workshop to turn this checklist into a real project plan.