Skip to content
Back to blog

CMMC

CMMC Readiness Checklist: What to Have Ready Before Your Assessment

A CMMC readiness checklist covering the documentation, evidence, and technical controls assessors and self-assessment scoring actually look for: SSP, POA&M, network diagrams, access control evidence, and more. Built for Hampton Roads defense contractors preparing for Level 2.

By Wakeem Williams 5 min read Last updated:
Binder of security documentation and a laptop open to a compliance checklist
Assessors don't grade intentions. They grade whether your documentation matches what's actually running. Pexels

Before a CMMC assessment, whether self-assessment or C3PAO third-party, you need a System Security Plan matching your actual environment, a POA&M for any open items, network diagrams showing your CUI boundary, and evidence (not just policies) for each of the 110 implemented controls. Assessors test what’s provable, not what’s written down as intended.

That is the answer most contractors are looking for. The rest of this article is the specifics, organized as a checklist you can actually work through.

If your Hampton Roads business has a CMMC Level 2 assessment on the horizon, whether self-assessment or a C3PAO visit, the readiness gap that trips people up isn’t usually the controls themselves. It’s the documentation and evidence trail that proves the controls are real. This checklist covers the artifacts assessors and self-assessment scoring consistently look for. For the underlying control requirements this checklist assumes you’ve already worked through, see CMMC Level 2 Requirements.

Core documentation to have ready

System Security Plan (SSP). The single most important artifact. It must describe your actual CUI boundary (not an aspirational one), the systems and personnel in scope, and how each of the 110 NIST SP 800-171 requirements is implemented. An SSP that describes a network you don’t actually run is worse than no SSP, because it signals to an assessor that your documentation process isn’t trustworthy.

Plan of Action and Milestones (POA&M). Any control that isn’t fully implemented needs a documented remediation plan with realistic dates. The CMMC Program rule limits which controls can remain open on a POA&M at assessment time, so this document should shrink as readiness work progresses, not stay static.

Network diagrams. A clear picture of your CUI boundary: what systems touch CUI, how they’re segmented from everything else, and where CUI enters and exits. This is one of the first things requested in most assessments, and it’s the fastest way to expose a flat, unsegmented network if that’s what you’re running.

Asset inventory. A current list of hardware, software, and systems in your CUI environment. Assessors use this to cross-check what your SSP claims against what actually exists.

Evidence to organize by control family

Documentation alone doesn’t satisfy an assessor. Evidence does. Organize proof by control family so it’s retrievable on request, not scattered across email threads and shared drives.

Access control evidence: account provisioning and deprovisioning records, MFA enrollment and enforcement logs, evidence of least-privilege access reviews.

Audit and accountability evidence: log retention configuration, examples of logs actually being generated and reviewed, evidence that logs are protected from tampering.

Incident response evidence: a documented IR plan, records of any tabletop exercises or drills, and if applicable, records of actual incident handling and DFARS 252.204-7012 reporting.

Configuration management evidence: system baselines, change control records, evidence that unauthorized software installation is actually restricted, not just prohibited on paper.

System and information integrity evidence: patch management records, vulnerability scan results, malware protection configuration and alert logs.

Training records

Assessors expect evidence that security awareness and role-based training actually happened, not just a policy stating that it should. CMMC’s Awareness and Training control family breaks into two pieces: general security awareness training for everyone with system access, covering phishing recognition, CUI handling, removable media, and password and device hygiene, plus role-based training for anyone with elevated system responsibilities, such as system administrators, network engineers, incident response personnel, or anyone managing access control systems. Personnel also need awareness of insider threat indicators, both to recognize concerning behavior and to understand their own CUI handling responsibilities.

NIST SP 800-171 doesn’t mandate a specific training platform or a specific frequency in the control text itself, but the practice assessors consistently expect is annual training for all users at minimum, plus training triggered by new hires, role changes, or significant changes to the threat environment or your systems. No Learning Management System is required; a spreadsheet tracking name, training date, content covered, and repeat cycle is enough. What an assessor is checking for is not whether training happened once, but whether it’s documented well enough to prove it happened, on schedule, for the right people.

Attendance records, training completion dates, and content coverage for both general users and personnel with elevated system responsibilities all belong in this file, organized alongside the rest of the evidence by control family above.

A readiness self-check before you schedule anything

Before committing to an assessment date, ask honestly: does the SSP match the network as it exists today, not as it was designed two years ago? Can you produce evidence for at least 90% of the 110 controls without scrambling? Is the POA&M limited to lower-severity items with real remediation dates, not a parking lot for everything unfinished? Do people in scope actually know their role in the security program, or would they be caught flat-footed by an interview question?

If the honest answer to any of those is no, that’s readiness work still to do, not a reason to cancel the assessment plan, just a reason to sequence it correctly. Getting the sequencing wrong (scheduling an assessment before evidence exists) is one of the more expensive mistakes contractors make, because a failed or incomplete assessment costs both money and the relationship with whichever prime is waiting on the result.

Where Helix Stax fits

Helix Stax works with small Hampton Roads defense contractors to build the readiness package before it becomes a deadline problem: SSP development that matches your actual environment, evidence organization by control family, and the underlying technical work (MFA, logging, segmentation) that makes the evidence real instead of aspirational.

The free Helix Score gives you a directional read on where your gaps are in about three minutes. For a full readiness picture before you schedule an assessment, book the free 60-minute assessment through cybersecurity compliance services.

Questions

Frequently asked questions about Helix Stax managed IT services

At minimum: a System Security Plan (SSP) describing your CUI boundary and how each of the 110 controls is addressed, a Plan of Action and Milestones (POA&M) for any open items, network diagrams showing the CUI environment, access control and account management records, incident response documentation, configuration management baselines, and evidence for control implementation such as MFA logs, patch records, and vulnerability scan results.

You're ready when your SSP accurately describes your environment (not an idealized version of it), you can produce evidence for each implemented control on request, your CUI boundary is clearly defined and technically enforced, and any open items are documented in a POA&M with realistic remediation dates. Most organizations find gaps between what they thought was implemented and what evidence actually shows during this step, which is the point of doing it before an assessor does.

Evidence that matches the SSP. Contractors often write policies that describe how things should work, then fail to produce logs, screenshots, or configuration exports proving the policy is actually enforced. An assessor tests implementation, not intentions.

Yes. Assessors and self-assessment scoring both expect a clear picture of your CUI boundary: what systems process or store CUI, how they're segmented from the rest of your network, and where CUI enters and exits your environment. A network diagram is usually the fastest way to communicate that boundary and is often requested directly during assessment.

For most small contractors with some existing IT maturity, 3 to 6 months before a target assessment date is realistic for readiness-specific work, assuming the underlying gap remediation (MFA rollout, logging, segmentation) is already substantially complete. Organizations starting from a significant gap should budget considerably more, since readiness prep can't fix what hasn't been built yet.

For limited items, yes. The CMMC Program rule allows certain lower-severity control gaps to remain open under a documented POA&M with a remediation timeline. High-severity or foundational controls generally cannot be left open on a POA&M at assessment time, so readiness prep should prioritize closing those first.

A gap assessment identifies which of the 110 NIST SP 800-171 controls are missing or incomplete, typically producing an SPRS score. A readiness checklist is the next step: confirming the documentation, evidence, and artifacts an assessor will actually ask for are organized and accessible, assuming the underlying controls are already substantially implemented.