CMMC 2.0 Compliance Checklist for Small Contractors
CMMC 2.0 affects every DoD contractor handling CUI. This practical checklist helps small businesses achieve and maintain compliance without breaking the bank.
March 7, 2026 · Winrove Team
What CMMC 2.0 Means for Small Contractors
The Cybersecurity Maturity Model Certification (CMMC) 2.0 isn't just a box-checking exercise: it's a fundamental shift in how the Department of Defense verifies that its contractors are protecting Controlled Unclassified Information (CUI). For small contractors, the implications are significant: starting in 2025, most DoD contracts touching CUI require CMMC Level 2 compliance, and that compliance must be formally assessed every three years.
The good news for small businesses is that CMMC 2.0 simplified the original CMMC 1.0 framework. Level 2 aligns directly with NIST SP 800-171, which has 110 security controls organized across 14 families. Level 1 (for contracts without CUI) requires only 17 practices and can be self-assessed annually. Most small contractors handling sensitive federal data will fall into Level 2.
This checklist walks you through the essential steps to assess your current posture, address gaps, and prepare for your CMMC assessment.
Phase 1: Determine Your CMMC Level Requirements
Before spending a dollar on compliance activities, confirm what level you actually need:
- Review your contracts and solicitations for DFARS clause 252.204-7012, which signals CUI handling requirements
- Identify whether you handle, process, or store CUI: if yes, you need Level 2
- Assess your supply chain obligations: if your prime contractor requires CMMC, your subcontract will too
- Check solicitation language for specific CMMC level requirements in Sections L and M
If you're unsure, check with your contracting officer or the DoD CMMC information portal. Getting this wrong in either direction is costly: under-complying risks contract loss; over-complying wastes resources.
Phase 2: Complete Your System Security Plan (SSP)
The System Security Plan is the foundation of CMMC compliance. It documents how your organization implements each of the 110 NIST 800-171 controls. An assessor will evaluate your actual implementation against your SSP, so accuracy matters more than polish.
- Define your CUI boundary: Which systems, networks, and devices touch CUI? This is your assessment scope.
- Document each of the 110 controls with one of three statuses: Implemented, Partially Implemented, or Not Implemented
- For each gap, create a Plan of Action & Milestones (POA&M) with target remediation dates
- Identify your responsible personnel for each control domain: access control, incident response, system and communications protection, etc.
Many small contractors underestimate the SSP effort. Budget 40-80 hours for a thorough initial SSP, less if you use a CMMC consultant or template.
Phase 3: Essential Technical Controls Checklist
Access Control (AC)
- ☐ Multi-factor authentication (MFA) enabled for all CUI system access
- ☐ Principle of least privilege implemented: users only access what they need
- ☐ External connections controlled via VPN or similar secure mechanism
- ☐ Privileged accounts separated from standard user accounts
- ☐ Session lock after 15 minutes of inactivity
Identification & Authentication (IA)
- ☐ Password complexity requirements enforced (minimum 12 characters, no common words)
- ☐ MFA enforced for privileged and remote access
- ☐ Authenticator management process documented
- ☐ Default passwords changed on all systems and devices
Configuration Management (CM)
- ☐ Baseline configurations established and documented for all CUI-scope systems
- ☐ Change management process in place before modifying production systems
- ☐ Unauthorized software installation blocked (application whitelisting or similar)
- ☐ Security configuration checklists applied (CIS Benchmarks, STIGs)
Incident Response (IR)
- ☐ Incident response plan documented, tested, and updated annually
- ☐ Reporting procedures for CUI breaches established (72-hour DoD notification requirement)
- ☐ Staff trained on how to recognize and report incidents
- ☐ Lessons learned process after each incident
Audit & Accountability (AU)
- ☐ Audit logging enabled on all CUI-scope systems
- ☐ Logs retained for minimum 90 days, with 1 year recommended
- ☐ Log review process established: who reviews, how often, what triggers investigation
- ☐ Log tampering protections in place
Phase 4: Policy and Training Requirements
Technical controls alone won't pass a CMMC assessment. Assessors look for documented policies, evidence of training, and proof that your people understand their responsibilities.
- Acceptable Use Policy: Document permitted and prohibited uses of company systems
- CUI Handling Policy: Define how CUI is identified, marked, stored, transmitted, and destroyed
- Annual security awareness training: All staff with CUI access must complete it; document completion
- Role-based training: System administrators and privileged users need additional technical training
- Insider threat awareness: Required for Level 2; train staff to recognize and report suspicious behavior
Phase 5: Assessment Preparation
Level 2 CMMC requires a third-party assessment by a C3PAO (Certified Third-Party Assessor Organization) every three years. Here's how to prepare:
- Conduct a gap assessment 6-12 months before your scheduled assessment to identify and remediate issues
- Gather evidence for every control: Screenshots, configuration exports, policy documents, training completion records
- Run a mock assessment: have an internal or trusted external party challenge your implementation before the official assessment
- Ensure your POA&M is current and all items have realistic remediation timelines
- Brief your staff: assessors interview employees, not just review documents
Common Pitfalls for Small Contractors
After working with dozens of small govcon firms through CMMC preparation, these are the most common mistakes:
- Scoping too broadly: Trying to apply CMMC controls to systems that don't touch CUI wastes money
- Treating it as a one-time project: CMMC is continuous: controls must be maintained and evidence must be current
- Neglecting vendor/cloud requirements: Your cloud providers and key vendors may also need to meet CMMC-equivalent requirements
- Underestimating documentation burden: The assessor needs evidence, not just your assurance that controls are in place
CMMC compliance is achievable for small contractors with focused effort and the right tools. Start with your SSP, close your highest-risk gaps first, and build sustainable processes for ongoing compliance maintenance.
Preserved Field Notes article. Original path /blog/cmmc-2-compliance-checklist-small-contractors/. No unrelated help guide has been substituted.
Related Field notes
CMMC Employee Training Requirements: Complete Compliance Guide ↗