CMMC Compliance Checklist: 7 Steps to Get Started

Key Takeaways:

  • CMMC compliance is a crucial step for defense contractors. It unlocks access to higher-value DoD contracts that handle CUI.

  • The latest CMMC 2.0 standard requires you to implement 110 NIST SP 800-171 security practices for Level 2, with either a self-assessment or a C3PAO assessment, depending on your contracts and where you fall in the rollout timeline.

  • CMMC 2.0 requirements around continuous monitoring and audit log management are among the most challenging to implement. Huntress centralizes log collection, retention, and monitoring to help your broader security platform meet those requirements.

Cybersecurity Maturity Model Certification (CMMC) levels determine which Department of Defense (DoD) contracts companies can bid on. They also dictate how closely the government watches your actions.

While it's fairly simple for defense contractors to reach Level 1 certification, most struggle with the complex requirements of CMMC Level 2 and above.

This guide helps you break through that barrier. We'll lay out what CMMC certification is, teach you all the terminology you need to know (the DoD loves its acronyms), and provide you with a handy step-by-step CMMC compliance checklist.

CMMC Compliance Checklist: 7 Steps to Get Started

Key Takeaways:

  • CMMC compliance is a crucial step for defense contractors. It unlocks access to higher-value DoD contracts that handle CUI.

  • The latest CMMC 2.0 standard requires you to implement 110 NIST SP 800-171 security practices for Level 2, with either a self-assessment or a C3PAO assessment, depending on your contracts and where you fall in the rollout timeline.

  • CMMC 2.0 requirements around continuous monitoring and audit log management are among the most challenging to implement. Huntress centralizes log collection, retention, and monitoring to help your broader security platform meet those requirements.

Cybersecurity Maturity Model Certification (CMMC) levels determine which Department of Defense (DoD) contracts companies can bid on. They also dictate how closely the government watches your actions.

While it's fairly simple for defense contractors to reach Level 1 certification, most struggle with the complex requirements of CMMC Level 2 and above.

This guide helps you break through that barrier. We'll lay out what CMMC certification is, teach you all the terminology you need to know (the DoD loves its acronyms), and provide you with a handy step-by-step CMMC compliance checklist.

What's CMMC compliance, and what does Level 2 require?

CMMC is a set of compliance regulations the DoD uses to assess how well defense contractors detect, prevent, and address cybersecurity threats. The DoD's Supplier Performance Risk System (SPRS) stores your self-assessment scores and CMMC assessment results for the three CMMC levels. Most contractors strive for Level 2.

Note: Level 3 requires highly advanced cybersecurity techniques, so it's out of reach for most organizations.

CMMC Level 1 requirements

CMMC Level 1 is the most basic compliance level. It means you can handle low-risk Federal Contract Information (FCI), such as administrative records or non-sensitive financial information.

To qualify, you complete a self-assessment against 15 basic safeguarding requirements from FAR 52.204-21 and submit your results in SPRS each year.

CMMC Level 2 requirements and where organizations typically fall short

CMMC Level 2 means you can bid for projects involving controlled unclassified information (CUI). This includes technical military data and security vulnerabilities.

Level 2 CMMC is far more thorough than Level 1. It requires you and your subcontractors to implement 110 different security controls. The National Institute of Standards and Technology (NIST) sets these regulations in its NIST SP 800-171 guidelines.

You can still gain limited access to some DoD contracts even if you don't score a perfect 110, but the majority of jobs require full compliance.

The most common reason companies fall short is their lack of a dedicated security operations center (SOC) that provides continuous monitoring, log management, and formal strategy documents. Examples of these documents are a System Security Plan (SSP) or a Plan of Action and Milestones (PoA&M).

A managed solution, like Huntress, fills those gaps without adding to your head count or complicating your cybersecurity setup.


Level 2 CMMC compliance checklist

Reaching CMMC Level 2 means making sure your cybersecurity and information systems are as mature as possible. Here's a step-by-step guide to streamlining the CMMC certification process.

Step 1: Form a team

Assemble a team of your best IT experts—the people who know your information systems and security controls inside and out. Ask them to download all the documentation from the most current NIST revision and start reviewing it. The included change analysis spreadsheet is particularly helpful.

Step 2: Define your assessment boundary to limit scope

Carry out an internal audit to identify the people, processes, and hardware you need to handle sensitive data and secure projects. Start setting up the tools and information architecture people will need to get to work.

Step 3: Conduct a gap analysis against all NIST SP 800-171 requirements

Go through all 110 security controls listed in Chapter Three of NIST SP 800-171 and note every practice you aren't in compliance with. Keep in mind that a third party will audit your efforts later, so be strict in your self-assessment. Get everyone on the team to compare their notes and agree on which criteria you do and don't meet.

Step 4: Document your System Security Plan

Break down compliance gaps into groups, and assign each to a team member. Then, download a copy of the NIST SSP template and have everyone fill in their portion of the document. For example, the person responsible for "Maintenance" and "Media Protection" criteria would complete sections 3.7 and 3.8.

Step 5: Create a plan of action and milestones for identified gaps

Ask each team member to download the CUI Plan of Action & Milestones (PoA&M) template. Get them to fill in a row for each item they marked "Planned to be Implemented" in the SSP. They should include necessary milestones, estimated timelines, and points of contact. Then, combine all these documents into a centralized spreadsheet. This will give everyone a clear view of the project.

Step 6: Implement technical controls

Now the real work begins—putting in place the security controls needed to comply with all 110 checks. This will take time, effort, and collaboration, so schedule regular meetings where team members can provide progress reports. Before you label a milestone as complete, make sure everyone updates the appropriate documents.

Once everyone has completed their part of the project, perform a Level 2 CMMC self-assessment to verify that the company meets all requirements. It might take a few tries to reach this point, so be prepared to take a step back, update your PoA&M, and try again.

Step 7: Contact a CMMC Third-Party Assessment Organization (C3PAO)

Reach out to a reputable C3PAO on the Cyber AB marketplace, and set up a Level 2 CMMC assessment. Hand over any documents and temporary credentials they need to conduct the audit. Don't get disheartened if you fail your assessment; it takes most organizations a few attempts to pass.

When you do pass, the C3PAO will submit your application to the SPRS for approval. Log in to SPRS and complete the forms to request Level 2 CMMC certification.


CMMC self-assessment vs. third-party assessment

While the DoD technically allows contractors to self-assess CMMC Level 2 certification, it only offers those organizations low-risk projects. If you're going through the trouble of assuring compliance with over 100 cybersecurity practices, you may as well follow through with a C3PAO assessment to unlock full Level 2 certification.

Some defense contractors don't pursue C3PAO certification because assessors are strict about the most difficult-to-maintain policies, like continuous monitoring and detailed incident response plans. Huntress offloads 24/7 log monitoring and threat investigation to our SOC, so your team doesn't have to staff the coverage themselves.


How to prepare for your CMMC compliance audit

You'll want to be as prepared as possible when arranging an audit. After all, you don't want to end up having to pay for multiple assessments.

Here are three strategies to make sure you've squared everything away:

  • Conduct mock assessments: Review the documentation your chosen C3PAO has provided to find the audit checklist its assessors use. Then, carry out a mock assessment to catch anything that might fail.
  • Test your team: Review each person's responsibilities. Ensure they can speak to every item they've checked off their list. They should be able to describe how they addressed it and any open PoA&M milestones still in progress.
  • Peer review documentation: Have everyone review each other's documentation to catch any gaps or inconsistencies.

How Huntress Managed SIEM helps with critical CMMC Level 2 logging and monitoring requirements

Huntress Managed SIEM helps address some of the most resource-intensive parts of Level 2, including centralized log collection, retention, and monitoring and supports the broader Huntress platform in satisfying CMMC controls. You can expect:

Huntress provides the technical controls, documentation, and DEFCERT partnership to support your CMMC preparation and assessments, but you still own your policies, procedures, and non-technical requirements. For instance, our collaboration with DEFCERT helped us streamline how cross-functional teams handle shared responsibilities.


Lean team? No problem. Rely on Huntress 24/7 SOC

Level 2 CMMC certification can unlock new opportunities to help your business grow, but it's no picnic, especially for smaller businesses. Huntress offers a way to close any gaps in your coverage with affordable, ready-made solutions that'll knock several items off your to-do list.

We have years of experience offering solutions like our Managed SIEM to small and growing businesses looking to stay eligible for CUI-bearing contracts as CMMC rolls out.


Protect What Matters

Secure endpoints, email, and employees with the power of our 24/7 SOC. Try Huntress for free and deploy in minutes to start fighting threats.
Try Huntress for Free