Cost, Grants and Exposure
If You Have Not Started: What to Do in the Next 30 Days
Your organization needs to meet CMMC requirements, and the deadline to show compliance is getting closer. The checklist below breaks down exactly what the CMMC framework asks of you. It explains each step honestly so you can make meaningful progress during your first 30 days.
What is actually required for CMMC compliance right now?
CMMC certification by a third party assessor is not required as of July 2026. The Department of War suspended the CMMC Phase II third party certification requirement, pending a strategic review expected to conclude in September 2026. What is still required and actively enforced is compliance with DFARS 252.204-7012, NIST SP 800-171 Rev 2, annual self assessments for Level 1 and Level 2, SPRS score posting, and annual senior official affirmation. The government can still conduct its own assessments, and your senior official’s signature is now the primary assurance of your compliance claims.
This means your self-assessment carries even more legal weight. Inflated or inaccurate scores may increase your False Claims Act exposure, as recent enforcement actions have shown.
What should you do first for CMMC compliance?
The right first steps are not audits or buying tools. The CMMC compliance checklist starts with scoping, inventory, and documentation. Here is what you should do in the next 30 days.
1. Scope your environment: What assets are in play?
CMMC compliance starts with knowing exactly what you are protecting and where it flows. Scoping defines the boundaries of your assessment. According to 32 CFR 170.19(c)(1) Table 3 and the CMMC Scoping Guide, assets fall into five categories:
- CUI Assets: Systems that process, store, or transmit Controlled Unclassified Information (CUI). These are assessed against all 110 controls.
- Security Protection Assets: Devices and systems that provide security services for CUI assets. These are assessed against controls relevant to their function.
- Contractor Risk Managed Assets: Not directly assessed, but reviewed in your System Security Plan (SSP) and subject to spot checks.
- Specialized Assets: Includes government furnished equipment, IoT, operational technology, and test equipment. These require SSP review only.
- Out of Scope Assets: No assessment, but you must be able to justify their separation from CUI.
Action: Prepare and document the four artifacts every assessor will require: a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and an Authorized User List.
2. Inventory your systems and users
Once you have scoped your environment, inventory every system, application, and user that falls within that boundary. This is more than a list for your own use. The inventory is required evidence for your SSP and is the foundation for control implementation.
Action: Document all hardware, software, cloud services, and user accounts that touch CUI or provide security for those systems. Note any specialized or contractor risk managed assets.
3. Build your System Security Plan (SSP)
The System Security Plan is your single most important document. It describes how you meet each of the 110 NIST SP 800-171 Rev 2 controls at Level 2, or the 17 practices at Level 1. The SSP must cover:
- Which controls are implemented and how
- The scope of your environment, including diagrams and inventories
- Any gaps and your Plan of Action and Milestones (POA&M) for remediation
According to available data, fewer than half of Level 2 companies have completed their SSP or POA&M documentation. This is a critical gap, as the SSP is required for both self-assessment and any future government-led or third-party assessment.
Action: Start drafting your SSP. Focus on describing your current state honestly. For each control, document your policy (intent), procedure (how), and evidence (proof in the form of system-generated artifacts).
4. Post your SPRS score and prepare for senior official affirmation
After completing your self-assessment, you must post your score in the Supplier Performance Risk System (SPRS). For full compliance at Level 2, the required score is 110. The average across the defense industrial base is around 60, so most companies have room to improve.
Your senior official must provide an annual affirmation of your self-assessment. With no third party between your self-assessment and the government, the accuracy of your SSP and SPRS score is more important than ever.
5. Plan for a gap assessment
A true baseline requires a gap assessment against all 110 controls. Most companies spend between $10,000 and $50,000 for this service. However, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant, delivered as services, covering all 110 controls for qualifying defense contractors. This can give you a comprehensive understanding of your current state without an immediate outlay.
What controls are included in the CMMC compliance checklist?
At Level 2, you must address 110 controls across 14 families, as established in NIST SP 800-171 Rev 2:
- Access Control (22 controls)
- Awareness and Training (3)
- Audit and Accountability (9)
- Configuration Management (9)
- Identification and Authentication (11)
- Incident Response (3)
- Maintenance (6)
- Media Protection (9)
- Physical Protection (6)
- Personnel Security (2)
- Risk Assessment (3)
- Security Assessment (4)
- System and Communications Protection (16)
- System and Information Integrity (7)
Every control is broken down into assessment objectives in NIST SP 800-171A. All objectives must be met for a control to be considered fully implemented.
What are the risks of getting this wrong?
Self-assessment is not a free pass. Recent False Claims Act cases show the government will pursue contractors who falsely claim compliance. Examples include companies that:
- Falsely certified compliance but failed to scan and remediate vulnerabilities
- Used non-FedRAMP email for CUI
- Had no SSP on file
- Shared defense data with unauthorized foreign entities
Liability can extend to primes, subcontractors, affiliates, and even private equity owners. Whistleblowers can file actions on the government’s behalf. Accuracy and documentation are your best protection.
Common questions
What happens if I do not have my SSP ready?
Without an SSP, you cannot complete a valid self-assessment, and you are out of compliance with DFARS 252.204-7012 and NIST SP 800-171 requirements.
Do I need to work with a C3PAO right now?
No. The requirement for third party certification is currently suspended. Self-assessments and government-led reviews are the current enforcement mechanism.
How do I know which assets are in scope for CMMC?
Follow the five asset categories in the CMMC Scoping Guide and prepare the required diagrams and lists. If you process, store, or transmit CUI, those systems are always in scope.
Assess Your Cybersecurity Gaps Immediately
If you have not started your CMMC compliance checklist, focus on scoping, inventory, and building your SSP in the next 30 days. When you are ready for a comprehensive gap assessment, consider the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 NIST SP 800-171 controls for qualifying defense contractors. It is a practical way to establish your baseline and plan your next steps without immediate new spending.