Calling a C3PAO before you are ready is an expensive mistake. A Level 2 assessment that falls short costs you the assessment fee, the cost of a second attempt, and eligibility for awards that require the status while you re-work. The DoD cost estimate in the CMMC final rule (89 FR 83092) puts the C3PAO engagement alone at $31,234 for a small entity and $52,056 for a larger one, so a repeat is real money. This checklist is the readiness gate. Score yourself against 14 items. If you cannot honestly check every box, do not book the assessment yet. (We are a readiness Agent-as-a-Service (AaaS) provider; we are not a C3PAO and do not issue certifications.)
Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.
Why a readiness checklist matters
32 CFR 170.17 sets three outcomes. Every requirement MET earns Final Level 2 (C3PAO). A score of at least 80 percent of the maximum, with only the NOT MET requirements that 32 CFR 170.21 allows on a POA&M, earns Conditional Level 2 (C3PAO), and those items must pass a C3PAO closeout assessment within 180 days or the status expires. Anything less earns no CMMC status. Conditional is recoverable but costly.
The checklist below follows the NIST SP 800-171 Rev 2 requirement families and the evidence an assessor works from. Treat it as a gate, not a guide.
The 14-item CMMC readiness checklist
Items 1 to 4: Scope and documentation
- CUI data flow diagram. Every system, application, user, and external party that touches CUI is mapped. No dotted lines, no "unknown" boxes.
- System Security Plan (SSP) covering all 110 NIST SP 800-171 controls. Each control has an implementation statement, an evidence reference, and a named owner.
- Plan of Action and Milestones (POA&M) listing every NOT MET requirement with a target close date and owner. CMMC findings are MET, NOT MET or NOT APPLICABLE (32 CFR 170.24), and only the requirements 32 CFR 170.21 allows may sit on an assessment POA&M, so know which of your open items qualify.
- Asset inventory complete. Every endpoint, server, mobile device, network device, and cloud resource in the CUI scope is enumerated with owner and configuration baseline.
Items 5 to 9: Technical controls
- Multi-factor authentication enforced for local and network access to privileged accounts and for network access to non-privileged accounts (NIST SP 800-171 Rev 2, requirement 3.5.3).
- FIPS-validated cryptography wherever cryptography protects the confidentiality of CUI (requirement 3.13.11), at rest and in transit. The cipher list and validation certificates are documented.
- Centralized logging in place. Authentication events, access to CUI, configuration changes, and security tool alerts are captured in a SIEM or equivalent, with retention that meets your policy.
- Malicious code protection (requirement 3.14.2), such as endpoint detection and response (EDR), on every CUI-touching endpoint, with alerts routed to a defined responder.
- Configuration management with documented baselines and change control. Drift is detected and either approved or remediated.
Want a fast directional read before you work through the list? The free gap check asks ten questions on ten NIST SP 800-171 requirements. It is a directional self-assessment, not an official SPRS score, and it does not score the 14 items below. Run the free gap check →
Items 10 to 12: Operational controls
- Incident response plan tested. A current tabletop exercise on record, with documented outcome and lessons learned.
- Security awareness training completed by all in-scope users on a recurring basis, with training records retained.
- Vendor and supply chain controls. Every subcontractor or vendor that touches CUI has flow-down clauses and documented assurance.
Items 13 to 14: Evidence and self-score
- Evidence library complete. Every implementation statement in the SSP has at least one piece of supporting evidence (screenshot, config export, log sample, policy excerpt) with date and source.
- Self-assessment score recorded. Score your environment with the CMMC Scoring Methodology (32 CFR 170.24) so you walk in with an honest number and know which controls are still open.
How to score yourself honestly
The CMMC Scoring Methodology (32 CFR 170.24) gives each of the 110 requirements a value of 1, 3 or 5 points and subtracts that value from a maximum score of 110 for each requirement NOT MET. The score is only honest if the evidence backs the rating. A common failure mode is rating a control "Met" because the tool is purchased and licensed, when the evidence shows it is misconfigured or not collecting data on the in-scope systems. Confirm the current passing thresholds and scoring rules against published DoD guidance before you treat a number as a go decision.
What a conditional outcome costs you
A conditional outcome gives you 180 days to close the POA&M items, and Conditional Level 2 (C3PAO) meets the CMMC requirement for contract award during that window. But you commit your team to remediation under time pressure, you pay for the C3PAO closeout assessment, and if the closeout does not pass within 180 days the status expires (32 CFR 170.17). After a Conditional result, the three-year clock for the next certification assessment runs from the Conditional status date (32 CFR 170.17(a)(1)). For budgeting, the DoD estimate for the small-entity C3PAO engagement is $31,234, and the three-year Level 2 certification cost is $104,670 for a small entity and $117,768 for a larger one (89 FR 83092, at 83185 to 83186). Avoiding a re-do is worth the discipline of this checklist. For a deeper budget view, see our coverage of CMMC Level 2 cost.
How AI-native readiness differs from spreadsheet readiness
Spreadsheet readiness is a checklist someone walks through by hand. It records intentions, not a measurement of operating state, and it can drift away from the environment as it actually runs.
AI-native readiness is re-measured on a schedule. Enclave AI re-scans the read-only configuration of the cloud and identity sources you connect about every seven days and compares each scan with the last. Requirements those sources can show are measured, and the relevant excerpt of the API response behind each measured finding is kept on file with a SHA-256 hash. Requirements no connected source can show are answered from your own attestations and evidence. Your Affirming Official decides what gets affirmed. That is the difference between walking into a C3PAO with a checklist you filled out months ago and walking in with a readiness picture measured within the last week for what your connected sources show. For the path from here to the assessment date, see our CMMC certification process timeline, and if self-assessment is on the table, read CMMC self-assessment requirements.