Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

The CMMC Compliance Checklist for an Internal Self-Assessment

CMMC
ComplianceForge Support
July 24, 2026
The CMMC Compliance Checklist for an Internal Self-Assessment

Editorial note: This checklist is informational, not legal or compliance advice. The Department of War suspended CMMC Phase II on July 13, 2026 and opened a 60 day review, so confirm your current contract requirements before relying on any single approach.

If you want the fastest possible answer, here it is. A CMMC compliance checklist for the internal self-assessment path has seven parts: define your scope, confirm your obligations, implement the NIST 800-171 controls, assess and score honestly, write your SSP and POA&M, gather your evidence, and have a senior official affirm the result. Everything below expands each of those into what good actually looks like.

This checklist is written for the moment we are in. With CMMC Phase II suspended and the interim path relying on NIST 800-171 Rev 2 self-assessments and select government led assessments, the checklist you need is the one that makes your own attestation defensible.

Key Takeaways

• The self-assessment path still requires real implementation of NIST 800-171, not just paperwork.

• Scope drives cost and risk, so define your CUI boundary before anything else.

• Your score, SSP and POA&M have to tell the same story.

• Evidence is the difference between a checklist you completed and one you can defend.

• A senior official affirmation is the final step and it carries legal weight.

The CMMC Self-Assessment Checklist

1. Define Your Scope

Identify where Controlled Unclassified Information (CUI) is received, processed, stored and transmitted. Draw the boundary. Decide whether an enclave will concentrate CUI into a smaller, cleaner scope. Document what is in scope and what is out, and why. If you cannot draw your boundary on one page, your scope is not yet defined.

2. Confirm Your Contractual Obligations

Read your contracts for DFARS 252.204-7012 and any CMMC or NIST 800-171 flow down. Confirm which CMMC level applies and which verification method your contracts currently require. Note that these requirements are shifting after the Phase II suspension, so recheck rather than assume.

3. Implement the NIST 800-171 Controls

Work through the 14 families and 110 requirements of NIST 800-171 Rev 2 and implement each one in your environment. Cover access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Implementation means the control is actually operating, not just written down.

4. Assess and Score Honestly

Assess each requirement against your real environment and score using the DoD Assessment Methodology, which starts at 110 and deducts weighted points for unmet requirements. Record the score, the date, and the scope. A number you cannot support with evidence is worse than a lower number you can.

5. Write Your SSP and POA&M

Document how each requirement is met in your System Security Plan (SSP). Record every gap, owner and target date in your Plan of Action and Milestones (POA&M). Make sure the SSP, the POA&M and the score agree with each other. Inconsistency between these three is the first thing a reviewer notices.

6. Gather and Organize Evidence

For each implemented requirement, keep the artifact that proves it, such as configuration settings, policies, procedures, logs, and training records. Store evidence so it maps to the requirement it supports. Doing this continuously is far easier than assembling it under the deadline of a government led assessment.

7. Affirm the Result

Have the appropriate senior official review and affirm the self-assessment. This affirmation is a representation to the government, so it should only be made once the SSP, POA&M, score and evidence actually support it.

Where Most Checklists Fall Apart

The steps are simple to list and hard to finish, and the place they usually stall is documentation. Writing a complete SSP, a set of policies and standards that cover every family, and procedures that describe how controls actually run is a large project on its own. Teams that try to write it from a blank page while also implementing controls tend to ship thin documentation, and thin documentation is exactly what a select government led assessment flags.

How the NCP Completes the Checklist Faster

The NIST 800-171 Compliance Program (NCP) exists to take the documentation half of this checklist off your plate. It provides editable policies, standards, procedures, an SSP template and a POA&M template aligned to NIST 800-171 and CMMC 2.0, and it covers the CUI controls, the Non-Federal Organization (NFO) controls, and the Assessment Objectives from NIST 800-171A. It is designed to get you roughly 80 to 90 percent of the way there, so your team spends its time on scoping, implementation and evidence instead of drafting policy language.

Because the NCP has been used to pass DIBCAC and C3PAO assessments, it is built to the standard your self-attestation should meet. Start with the NCP and you turn steps 5 and much of step 3 from a writing project into a tailoring exercise.

Frequently Asked Questions

Is there a CMMC self-assessment spreadsheet or tool I should use? Many teams track requirements and scoring in a spreadsheet, and that works. The risk is treating a green spreadsheet as proof. The spreadsheet tracks status. Your SSP, POA&M and evidence are the proof.

How many controls are on the CMMC checklist? For the NIST 800-171 Rev 2 baseline used in the interim, there are 110 security requirements across 14 families. NIST 800-171 Rev 3 restructures this, which is covered in our Rev 2 versus Rev 3 article.

Who signs off on a CMMC self-assessment? A senior official affirms the result. Because the affirmation is a representation to the government, it should rest on documentation and evidence that genuinely support the claim.

Sources: NIST SP 800-171 Rev 2 for the family and requirement structure, and the DoD Assessment Methodology for scoring. Department of War CMMC Phase II suspension release, July 13, 2026, at war.gov. Product details from the ComplianceForge NIST 800-171 Compliance Program (NCP) product page.