All resources
CMMCL1 / L2Checklist

CMMC 2.0 checklist: Level 1 & Level 2 practices for CUI

Official source: DoD CMMC 2.0

CMMC isn’t a one-time certification — it’s evidence your controls operate continuously. This checklist walks every control an auditor examines, and flags which a platform can automate.

What CMMC requires

CMMC is assessed against 110 controls across 5 families: Access & identity, System protection, Audit & monitoring, Configuration mgmt, Documentation. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

All 14 CMMC 2.0 Level 2 domains (110 practices, built on NIST SP 800-171). Use the table below as your working checklist — 14 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
CMMC 2.0 Level 2 domains
ACAccess Control (22 practices)Auto
ATAwareness & Training (3)Manual
AUAudit & Accountability (9)Auto
CASecurity Assessment (4)Manual
CMConfiguration Management (9)Auto
IAIdentification & Authentication (11)Auto
IRIncident Response (3)Manual
MAMaintenance (6)Manual
MPMedia Protection (9)Manual
PEPhysical Protection (6)Manual
PSPersonnel Security (2)Manual
RARisk Assessment (3)Auto
SCSystem & Communications Protection (16)Auto
SISystem & Information Integrity (7)Auto

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of CMMC controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Turn this checklist into a live dashboard

SBCMSP tracks every CMMC control continuously across all your clients.