AuditXYZ

Lesson 3 of 6

CMMC Compliance Checklist: A 12-Month Roadmap

14 min readIntermediate

CMMC Compliance Checklist

Most CMMC projects do not fail because the controls are impossible. They fail because nobody sequenced the work. Teams buy tools before scoping, write policies before fixing systems, and book assessors before collecting evidence — then discover at month eleven that the FIPS encryption question was never answered.

This lesson is a phased, checkbox-style roadmap for reaching CMMC Level 2 in roughly 12 months. If your environment is small or you adopt an enclave early, you can compress it; if you need a GCC High migration or new facilities controls, stretch it. The sequence, however, stays the same. (Level 1 organizations can run the same phases in miniature over one to three months.)

Before you start, confirm your required level using the process in lesson 1, and skim the CMMC framework overview so the vocabulary below is familiar.

Phase 1: Scoping and Project Setup (Months 1–2)

Scoping decisions made here determine 80 percent of your total cost. Do not rush this phase.

  • Assign an executive sponsor and a project owner with real authority and budget
  • Identify every contract clause driving requirements (DFARS 252.204-7012, -7019/7020, -7021) and the CMMC level each contract demands
  • Inventory where FCI and CUI enter, live, and leave the company — email, file shares, CAD systems, ERP, shipping docs, backups, printers
  • Interview program managers and engineers; CUI often hides in places IT does not know about
  • Decide your boundary strategy: whole-enterprise scope vs a dedicated CUI enclave (smaller scope almost always wins on cost — see the small business guide)
  • Categorize assets per the CMMC scoping guide: CUI assets, security protection assets, contractor risk managed assets, specialized assets, out-of-scope
  • Document data flow diagrams and a network diagram for the intended scope
  • List every external service provider and cloud service that touches the scope; flag any that cannot meet FedRAMP Moderate or equivalent
  • Set the project budget and a target assessment quarter; open conversations with C3PAOs about lead times now

Phase 2: Gap Assessment (Months 2–3)

  • Assess against all 110 NIST SP 800-171 controls and all 320 assessment objectives — objective level, not control level
  • Use the DoD Assessment Methodology to compute your SPRS score (110 down to -203)
  • Submit or update your SPRS score honestly; an inflated score is False Claims Act exposure
  • For each gap, record the fix, the owner, the cost estimate, and whether it is a 1-, 3-, or 5-point control
  • Sequence remediation: 5-point and 3-point controls first, since most are not POA&M-eligible
  • Identify long-lead items immediately — GCC High migration, FIPS-validated VPN replacement, logging platform, MFA rollout, physical security changes
  • Decide DIY vs consultant vs platform support for the remediation phase (covered in lesson 5)
  • Produce a remediation plan with monthly milestones and report it to the executive sponsor

Phase 3: Remediation (Months 3–9)

This is the longest phase. Run it as an engineering program with sprints, not a compliance side project.

Identity and access

  • Enforce MFA for all network access, remote access, and privileged accounts
  • Implement unique IDs, least privilege, and role-based access reviews
  • Build a joiner/mover/leaver process with same-day access revocation

Encryption and communications

  • Verify FIPS 140-validated cryptographic modules for VPN, disk encryption, wireless, and anywhere CUI is protected by cryptography — check certificates, not marketing pages
  • Encrypt CUI at rest and in transit across the boundary
  • Segment the CUI environment from the general network; control and monitor boundary traffic

Cloud and vendors

  • Migrate CUI out of non-compliant SaaS; complete GCC High or equivalent migration if export-controlled data is involved
  • Execute shared responsibility matrices with your MSP and cloud providers

Monitoring and integrity

  • Deploy centralized log collection with retention, review procedures, and alerting
  • Deploy EDR/antimalware across in-scope endpoints and servers
  • Stand up vulnerability scanning on a recurring cadence with remediation SLAs
  • Establish patch management with defined timelines and exception handling

Physical and media

  • Implement visitor logs, escorts, and badge controls for areas where CUI is handled
  • Establish media marking, encryption for removable media, and sanitization/destruction procedures

People

  • Deliver security awareness and insider threat training; keep completion records
  • Screen personnel with CUI access per your policy

Phase 4: Documentation (Months 6–10, overlapping remediation)

Write documentation as systems stabilize — not before (it will be fiction) and not after (you will run out of time). Full detail in CMMC documentation requirements.

  • Write the System Security Plan describing scope, architecture, and how every control is implemented, with named responsible roles
  • Issue policies and procedures covering all 14 control families
  • Maintain the POA&M for any remaining gaps with owners and dates
  • Finalize the incident response plan, including the DFARS 72-hour DoD reporting procedure, and test it with a tabletop exercise
  • Complete asset inventory, network diagrams, and data flow diagrams as assessment-ready artifacts
  • Build an evidence library mapped to assessment objectives: configurations, screenshots, log samples, training records, scan reports, review minutes

Phase 5: Pre-Assessment (Months 10–11)

  • Operate all controls for at least 60–90 days so evidence shows real operation, not day-old settings
  • Run a mock assessment — internally with fresh eyes, or via a readiness consultant — against the full 320 objectives
  • Fix every mock-assessment finding; re-verify the fixes
  • Update the SPRS score to reflect current state
  • Rehearse interviews: sysadmins, HR, facilities, and executives should be able to describe their procedures without reading the policy aloud
  • Confirm the C3PAO booking, scope agreement, assessment plan, and logistics
  • Pre-stage evidence in an organized structure keyed to control numbers so nothing is hunted for live

Phase 6: Assessment (Month 12)

  • Hold a kickoff with the assessment team; agree on schedule and points of contact
  • Provide the SSP and evidence promptly; slow evidence production reads as immaturity
  • Make interviewees available and keep answers factual — never guess or embellish
  • Track any findings daily; some can be resolved during the assessment window
  • If conditional: confirm your score is at least 88, verify open items are POA&M-eligible, and launch the 180-day closure plan the same week
  • Receive results via eMASS; senior official submits the affirmation in SPRS

Keeping the Roadmap on Schedule

Three practices separate 12-month projects from 24-month ones:

  • Run a monthly steering review with the executive sponsor. Report three numbers each month: current SPRS score, count of open 3- and 5-point gaps, and days until the booked assessment window. When those numbers are visible to leadership, budget requests stop stalling and competing priorities stop poaching your remediation engineers.
  • Front-load every long-lead dependency. GCC High tenant provisioning and migration, FIPS-validated hardware procurement, DIBNet medium assurance certificates, and C3PAO booking all have lead times measured in months and none of them compress under pressure. Start all four in Phase 1 even though they finish in later phases.
  • Freeze scope after Phase 1. Every system, SaaS tool, or business unit added to the boundary mid-project reopens scoping, gap assessment, and documentation for that addition. New requests wait for the post-certification change process unless a contract demands otherwise.

Also decide your support model early. The DIY-versus-consultant-versus-platform question is covered in lesson 5, but the timing rule is simple: if you are going to buy help, buy it in Phases 1 and 5 — scoping and mock assessment — where expert judgment has the highest leverage, and do the labor-heavy middle phases with internal staff and tooling.

Budgeting the Roadmap

Real numbers vary enormously with scope, but here is a planning-grade budget for a small-to-mid-sized contractor pursuing Level 2 with an enclave-style scope:

PhaseTypical Range (SMB)Biggest Cost Drivers
Scoping & gap assessment$10K–$30KConsultant day rates, internal time
Remediation — technology$25K–$100K+GCC High seats, FIPS-validated hardware, logging/EDR tooling
Remediation — services/MSP$15K–$60KMSP/MSSP fees, migration labor
Documentation$10K–$40KSSP authoring, policy development
Pre-assessment / mock$10K–$25KThird-party readiness review
C3PAO assessment$30K–$60KScope size, team days, travel
First-cycle total$100K–$300K+Scope, scope, scope
Ongoing annual run cost$30K–$80KLicenses, monitoring, affirmations, maintenance

If those numbers alarm you, the two levers that actually move them are shrinking scope and avoiding rework — both covered in our guide to the cheapest path to CMMC. If your problem is a contract deadline rather than budget, see the quickest path to CMMC.

Post-Certification Maintenance

Certification is a snapshot; the obligation is continuous. Falling out of compliance between assessments invalidates your annual affirmation — and the affirmation is what carries legal weight.

  • Submit the annual affirmation in SPRS each year (calendar it; assign a named owner)
  • Close any POA&M items within 180 days and complete the closeout assessment
  • Run continuous monitoring: log review, scan cadence, patch SLAs, access recertification
  • Put change management gates on anything that alters the assessment scope — new SaaS, new site, new business unit
  • Refresh training annually; onboard new hires into scope procedures
  • Re-test the incident response plan at least annually
  • Review the SSP quarterly and after every significant change
  • Begin re-assessment preparation 9–12 months before the three-year expiration; book the C3PAO early
  • Track program changes — including the eventual transition toward NIST SP 800-171 Rev 3 — so nothing surprises you at recompete time

Frequently Asked Questions

Can I really get CMMC Level 2 done in 12 months?

Yes, if scoping is disciplined and remediation starts by month three. Organizations that fail the 12-month timeline usually lost months to indecision about scope or cloud migration, not to the controls themselves. An enclave-first strategy is the most reliable accelerator; enterprise-wide scopes at larger companies commonly need 18 months.

What order should I fix gaps in?

Highest-weighted first. The 5-point controls (like MFA and FIPS-validated encryption) and 3-point controls are generally not POA&M-eligible, so they gate certification outright. Then close 1-point items, which at worst can ride a 180-day POA&M. Within that ordering, start long-lead procurements (GCC High, logging platforms) immediately regardless of weight.

Do I need to run controls for a while before the assessment?

There is no mandated seasoning period like a SOC 2 Type 2 window, but assessors test whether controls are actually operating — log reviews with history, training records with dates, access reviews with minutes. Sixty to ninety days of real operation is the practical minimum to produce credible evidence.

Should I book the C3PAO before I'm ready?

Book early with a realistic target quarter. Reputable C3PAOs are scheduling months out, and you can generally shift dates with notice. Waiting until you are "done" to start shopping typically adds a quarter of dead time to the project.

What if my score is below 88 at assessment time?

Below 88, conditional certification is off the table — the assessment ends without certification and you pay again for a new one after remediating. This is precisely what the Phase 5 mock assessment exists to prevent: never let the C3PAO be the first party to score your environment.

Who in my company should own this checklist?

A single accountable project owner — often the IT/security lead — backed by an executive sponsor who controls budget. But phase tasks span HR (screening, training), facilities (physical controls), contracts (clause tracking), and engineering (CUI handling). CMMC run purely as an IT project stalls at the first cross-functional dependency.


A GRC platform can automate much of the evidence collection and tracking in this checklist — and the right readiness partner can save a failed assessment cycle. AuditXYZ helps you compare compliance automation tools and auditors so you can assemble the right support for each phase of your roadmap.