CMMC 2.0 Compliance Checklist: Every Control Domain, Item by Item
This is a working checklist, not a narrative. If you want the sequential story of how a CMMC 2.0 certification project unfolds from first assessment to ongoing maintenance, see our CMMC 2.0 Roadmap. This page is the reference document to work from once you’re in it — organized by control domain, with specific items to verify, track, and check off as you go.
Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Self-assessment requirements and your underlying NIST SP 800-171 obligations are unaffected. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for current program status.
Executive Summary
Main Idea: CMMC 2.0 Level 2 requires demonstrable implementation of all 110 NIST SP 800-171 controls across 14 domains. This checklist breaks each domain into specific, verifiable items so you can track exactly what’s implemented, what’s documented, and what’s still open.
Why You Should Care: A C3PAO assessor — or your own self-assessment — doesn’t evaluate “CMMC compliance” as a single yes/no. They evaluate each control individually, and gaps in any single domain can hold up certification. Working through this checklist domain by domain surfaces exactly where your gaps are before an assessor finds them.
Key Takeaways
- CMMC compliance is evaluated control by control, not as a single pass/fail. An assessor reviews each of the 110 controls individually against your System Security Plan. A strong posture in nine domains doesn’t offset a genuine gap in a tenth — every domain needs to hold up on its own.
- Data flow visibility is the prerequisite this checklist assumes you already have. You can’t check off Access Control or Audit and Accountability items accurately if you don’t know every system where CUI or FCI actually lives — including email, file sharing, and web forms that often get overlooked in favor of primary databases and applications.
- Documentation is as much a checklist item as the technical control itself. A control that’s implemented but undocumented in your SSP is, from an assessor’s perspective, indistinguishable from a control that doesn’t exist. Every item below has both a “do it” component and a “document it” component.
- Gaps aren’t failures if they’re tracked properly. A documented POA&M with a realistic remediation timeline is an acceptable state for a control that isn’t yet fully implemented. An undocumented gap, discovered by the assessor rather than disclosed by you, is a much bigger problem.
- This checklist is a living document, not a one-time exercise. Controls that pass today can drift out of compliance as systems, staff, and vendors change. Revisit this checklist on a regular cadence, not just before a scheduled assessment.
Before You Start
Confirm two things before working through the domain checklists below, since they determine which items actually apply to you.
☐ Confirm your required CMMC level. Level 1 applies if you handle only Federal Contract Information (FCI). Level 2 applies if you handle Controlled Unclassified Information (CUI) — this checklist is built around Level 2’s full 110-control requirement. Level 3 adds enhanced controls on top of Level 2. Check your contract language or your prime’s flow-down requirements directly.
☐ Inventory every system that touches CUI or FCI. This includes obvious systems (file servers, databases) and commonly overlooked ones (email, file sharing platforms, managed file transfer, web forms collecting data from partners, and any AI tools with access to these systems). You cannot accurately complete the checklist below without this inventory.
Access Control (AC)
☐ Limit system access to authorized users, processes, and devices only.
☐ Limit access to the types of transactions and functions authorized users are permitted to perform (least privilege).
☐ Control the flow of CUI in accordance with approved authorizations.
☐ Separate duties of individuals to reduce the risk of malicious activity without collusion.
☐ Employ the principle of least privilege for all accounts and processes, including privileged accounts.
☐ Limit unsuccessful logon attempts and enforce automatic session lockout after a defined period of inactivity.
☐ Control connections to external systems and monitor remote access sessions.
☐ Document all access control policies in your SSP, including who reviews and approves access requests.
Learn more about the Access Control domain for CMMC compliance.
Audit and Accountability (AU)
☐ Create and retain system audit logs sufficient to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity.
☐ Ensure the actions of individual system users can be uniquely traced, so users can be held accountable for their actions.
☐ Review and update logged events periodically as your systems and threat landscape change.
☐ Protect audit logs and audit logging tools from unauthorized access, modification, and deletion.
☐ Correlate audit records across multiple systems for a unified timeline during an investigation.
☐ Confirm your audit logs are consolidated and reviewable in one place, not scattered across systems with no unified format an assessor can review efficiently.
Learn more about the Audit and Accountability domain for CMMC compliance.
Configuration Management (CM)
☐ Establish and maintain baseline configurations for all systems handling CUI.
☐ Establish and enforce security configuration settings for information technology products.
☐ Track, review, approve, and log all changes to organizational systems.
☐ Analyze the security impact of changes prior to implementation.
☐ Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
☐ Apply the principle of least functionality by configuring systems to provide only essential capabilities.
Learn more about the Configuration Management domain for CMMC compliance.
Identification and Authentication (IA)
☐ Identify system users, processes acting on behalf of users, and devices uniquely.
☐ Authenticate the identities of users, processes, and devices before allowing access.
☐ Enforce multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
☐ Enforce a minimum password complexity and change frequency, or use passwordless authentication methods that meet an equivalent standard.
☐ Prevent reuse of identifiers and passwords for a defined period.
☐ Obscure feedback of authentication information (no visible passwords during entry).
Learn more about the Identification & Authentication domain for CMMC compliance.
Media Protection (MP)
☐ Protect (physically control and securely store) system media containing CUI, both paper and digital.
☐ Limit access to CUI on system media to authorized users.
☐ Sanitize or destroy system media containing CUI before disposal or reuse.
☐ Mark media with necessary CUI markings and distribution limitations.
☐ Control access to media containing CUI and maintain accountability for media during transport outside controlled areas.
Learn more about the Media Protection domain for CMMC compliance.
Personnel Security (PS)
☐ Screen individuals prior to authorizing access to systems containing CUI.
☐ Ensure CUI and systems containing CUI are protected during and after personnel actions such as termination or transfer.
☐ Document offboarding procedures, including immediate revocation of access upon termination.
Learn more about the Personnel Security domain for CMMC compliance.
Physical Protection (PE)
☐ Limit physical access to systems, equipment, and operating environments to authorized individuals.
☐ Escort visitors and monitor visitor activity, maintaining audit logs of physical access.
☐ Control and manage physical access devices (keys, badges, access codes).
☐ Enforce safeguarding measures for CUI at alternate work sites, including remote work locations.
Learn more about the Physical Protection domain for CMMC compliance.
Risk Assessment (RA)
☐ Periodically assess the risk to organizational operations, assets, and individuals from the operation of your systems.
☐ Scan for vulnerabilities in systems and applications periodically and when new vulnerabilities are identified.
☐ Remediate identified vulnerabilities in accordance with a documented risk-based timeline.
☐ Document your risk assessment process and findings — this is one of the most frequently requested artifacts in C3PAO assessments.
Learn more about the Risk Assessment domain for CMMC compliance.
Security Assessment (CA)
☐ Periodically assess security controls to determine if they’re effective in their application.
☐ Develop and implement plans of action (POA&Ms) to correct deficiencies and reduce or eliminate vulnerabilities.
☐ Monitor security controls on an ongoing basis to ensure continued effectiveness.
☐ Maintain a current System Security Plan (SSP) describing system boundaries, environments of operation, and how each control is implemented.
Learn more about the Security Assessment domain for CMMC compliance.
System and Communications Protection (SC)
☐ Monitor, control, and protect communications at external boundaries and key internal boundaries.
☐ Implement subnetworks for publicly accessible system components, separated from internal networks.
☐ Use FIPS-validated cryptography (FIPS 140-3) to protect the confidentiality of CUI at rest and in transit.
☐ Establish and manage cryptographic keys in accordance with applicable requirements — verify whether your key management includes hardware-backed protection (HSM or equivalent).
☐ Prevent unauthorized and unintended information transfer via shared system resources.
Learn more about the System & Communications Protection domain for CMMC compliance.
System and Information Integrity (SI)
☐ Identify, report, and correct system flaws in a timely manner.
☐ Provide protection from malicious code at appropriate locations within organizational systems.
☐ Monitor systems, including inbound and outbound communications, for unauthorized use.
☐ Update malicious code protection mechanisms when new releases are available.
Learn more about the System and Information Integrity domain for CMMC compliance.
Incident Response (IR)
☐ Establish an operational incident-handling capability, including preparation, detection, analysis, containment, recovery, and user response activities.
☐ Track, document, and report incidents to designated officials and authorities, both internal and external, as required.
☐ Confirm your incident reporting process satisfies the 72-hour reporting requirement under DFARS 252.204-7012 for cyber incidents involving covered defense information.
Learn more about the Incident Response domain for CMMC compliance.
Awareness and Training (AT)
☐ Ensure personnel are made aware of security risks associated with their activities and applicable policies.
☐ Provide security awareness training upon hiring and refresh at least annually.
☐ Provide role-based training for personnel with assigned security responsibilities.
Learn more about the Awareness and Training domain for CMMC compliance.
Maintenance (MA)
☐ Perform maintenance on organizational systems using controlled, documented procedures.
☐ Require multi-factor authentication for nonlocal maintenance sessions.
☐ Supervise maintenance activities performed by personnel without required access authorization.
Learn more about the Maintenance domain for CMMC compliance.
How Kiteworks Supports This Checklist
Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, directly addressing several of the domains above without requiring a separate tool for each one.
Access Control and Identification and Authentication: a unified Data Policy Engine enforces role-based and attribute-based access control, least privilege, and multi-factor authentication consistently across secure email, secure file sharing, managed file transfer, and SFTP.
Audit and Accountability, Security Assessment: a single, consolidated, immutable audit trail spans every channel, giving you one place to demonstrate compliance rather than reconciling logs across disconnected systems.
System and Communications Protection: AES-256 encryption at the file and disk level, FIPS 140-3 validated cryptographic modules, and customer-owned encryption keys, with optional HSM integration for hardware-backed key management.
System and Information Integrity: continuous monitoring and anomaly detection across all sensitive data exchange channels, with SIEM integration for broader organizational visibility.
To see how Kiteworks maps to your specific open checklist items, schedule a custom demo.
Frequently Asked Questions
CMMC 2.0 Level 2 requires implementation of all 110 security controls specified in NIST SP 800-171, organized across 14 domains: Access Control, Audit and Accountability, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each control is assessed individually — either through self-assessment or third-party C3PAO certification, depending on program requirements.
The primary artifact is your System Security Plan (SSP), which describes how your organization implements each of the 110 required controls. For any control not yet fully implemented, a Plan of Action and Milestones (POA&M) documents the specific remediation steps and timeline. Assessors also commonly request audit logs demonstrating that access controls and monitoring are operating as described, evidence of security awareness training completion, incident response documentation, and configuration baselines. A checklist item that’s “done” but undocumented in the SSP is functionally invisible to an assessor.
A roadmap describes the sequence of a CMMC certification project — determining your level, assessing gaps, remediating, verifying, and maintaining compliance over time, in that order. A checklist is a reference tool for working through the specific, granular items within that process — the individual controls across all 14 domains that need to be implemented and documented. Use the roadmap to understand the overall journey and use this checklist as the working document once you’re actively assessing and remediating gaps.
Controls that pass today can drift out of compliance as systems, staff, and vendors change — a new employee onboarded without proper access review, a system reconfigured without updating the SSP, a vendor relationship added without documenting the new CUI flow. Organizations with mature compliance programs revisit this CMMC checklist on a regular internal cadence, not just before a scheduled recertification assessment. Level 2 and Level 3 certifications require triennial recertification, but the underlying controls need to remain effective continuously in between.
Additional Resources
- Blog Post CMMC Compliance for Small Businesses: Challenges and Solutions
- Blog Post CMMC Compliance Guide for DIB Suppliers
- Blog Post CMMC Audit Requirements: What Assessors Need to See When Gauging Your CMMC Readiness
- Guide CMMC 2.0 Compliance Mapping for Sensitive Content Communications
- Blog Post The True Cost of CMMC Compliance: What Defense Contractors Need to Budget For