FREE DOWNLOAD

The IT Team's CMMC 2.0 Readiness Checklist

CMMC 2.0 began on November 10, 2025, and your DoD contracts might be at risk. Find out what your IT team needs documented before the auditor arrives. The free CMMC Compliance Checklist outlines exactly how to keep your IT team compliant.

CMMC Checklist OG preview graphic

What’s Inside the Guide

Pass Level 1-3 compliance requirements confidently with the following team-assessment tools:

  • CMMC Compliance Itemized Excel Sheet

  • Detailed CMMC Compliance Checklist

This resource was developed by InfoSec professional Bob Salmans. It was designed to help your IT team ace CMMC compliance and continue winning DoD contracts.

Use this CMMC checklist with:

What CMMC Level 1 Looks Like for Your IT Team

CMMC Level 1 will apply to any organization handling Federal Contract Information (FCI). These will typically be small to mid-sized defense contractors, IT service providers, and government suppliers who don't touch classified data but are still required to demonstrate basic cybersecurity best practices to maintain their DoD contract eligibility.

If your team manages systems, networks, or data under a DoD contract, you'll need to complete a Level 1 assessment. When your next contract renewal or audit comes around, you don't want your team scrambling to create relevant documentation. Here's what Level 1 compliance requires.

  • ready

    1. Review Compliance Requirements

    • Review the CMMC Level 1 Self-Assessment Guide.

    • Understand the 15 required security controls, and 56 objectives.

    • Verify that the security requirements are in place within your organization

  • ready

    2. Identify Assets in Scope

    • Document all assets that store, process, or transmit FCI.

    • Include both physical and virtual assets.

    • Identify and list all personnel who handle FCI, as they require specific training.

  • ready

    3. Perform your Self-Assessment

    • There is no official self-assessment template, so use or create a custom spreadsheet. Our CMMC Checklist includes a downloadable .xlsx that your team can use to perform a self-assessment.

    • Review each control and verify implementation.

    • Update your assessment regularly as requirements evolve.

  • ready

    4. Identify and Implement Missing Requirements ㅤㅤ

    • Collect documentation to prove each control is implemented.

    • Use screenshots, or system & audit logs.

    • Store evidence in a secure place with clear naming conventions, and organize it by control for easy retrieval.

  • ready

    5. Gather Evidence and Documentation ㅤㅤ

    • Collect documentation to prove each control is implemented.

    • Use screenshots, or system & audit logs.

    • Store evidence in a secure place with clear naming conventions, and organize it by control for easy retrieval.

  • ready

    6. Create a System Security Plan (SSP) (Optional but Recommended)

    • While not required for Level 1, a System Security Plan (SSP) is required for Levels 2 and 3. An SSP is a formal document that outlines the security controls and processes that an organization has put in place to meet requirements.

    • Include:

      • A description of each control’s implementation

      • References to evidence in appendices

      • Protect SSP files by marking them Sensitive (headers/footers/watermarks).

      • Store large or sensitive files (e.g., logs) in a secure repository and reference them in the SSP.

Download the CMMC Readiness Checklist.

You'll gain access to a self-assessment template, and full Level 1-3 compliance steps.

Easy to use. Easy to implement. Proven results.

Getting up and training is simple and painless. Here’s why managers train their teams with us.

The way that CBT Nuggets structures their courses allows me to fit in short training sessions throughout the day which has really accelerated my learning.

Andrew R. | Senior Network Architect

Read more reviews

Delivering trusted IT training across industries and around the world.

Schedule a demo
Get CBT Nuggets IT training news and resources

I have read and understood the privacy policy and am able to consent to it.

© 2026 CBT Nuggets. All rights reserved.Terms | Privacy Policy | Accessibility | | Sitemap | 2850 Crescent Avenue, Eugene, OR 97408 | 541-284-5522