Skip to main content

🔔 Notifications Hub: See compliance updates in one place

CMMC & NIST 800-171 Rev 2 Readiness Checklist

Defense contractors handling CUI have to implement all 110 requirements from NIST SP 800-171 Rev 2, submit a supported self-assessment score or proactively complete a C3PAO assessment, and affirm continuous compliance in SPRS to meet current CMMC and DFARS 7012 requirements in contracts. This checklist pairs a ten-step readiness workflow with a scoring worksheet for all underlying security requirements and their point values under the DoD Assessment Methodology. Use it to sequence the work, track what's done, and see where your score actually lands before you report it. Defense contractors handling FCI can also use it to assess their implementation of the subset of 15 NIST 800-171 R2 requirements (also listed in FAR clause 52.204-21) required for CMMC Level 1.

updated 9/4/26 for secureframe

What you'll get:

  • Sequence readiness work across ten steps, from system inventory and categorization through incident response and change management
  • Score all 110 NIST 800-171 requirements using DoD Assessment Methodology point values to see where your SPRS total stands (or score the 15 requirement as MET/NOT MET for Level 1)
  • Track completion status, timelines, and recurring tasks like quarterly access reviews in one place