Free Resource · No Email Required

CMMC 2.0 Level 2 Readiness Checklist

A 14-family working checklist built around NIST SP 800-171 Rev. 2. Used internally on every Gravity CMMC engagement. Yours, ungated.

Download the PDF

PDF · 17 pages · 108 KB

CMMC 2.0 Level 2 Readiness Checklist

No email gate. No download form. Click the button, get the PDF. If you find it useful and want help applying it, we’re right here.

What’s inside

The checklist mirrors the working document we walk every CMMC client through before any implementation work begins. It’s the version we use internally, not a marketing sanitization.

  • Pre-assessment scoping — identifying CUI, mapping data flows, defining the assessment boundary
  • All 14 NIST SP 800-171 control families with the items SMB DIB contractors most often get wrong
  • Common gotchas — service accounts without MFA, baselines that drift, training records that don't reconstruct
  • Documentation deliverables — what the SSP, POA&M, data-flow diagram, and asset inventory actually need to contain
  • Pre-assessment activities — self-assessment scoring, SPRS posting, mock-audit framework
  • What "ready" actually looks like — the 90-day rule, prioritization when the deadline accelerates

Who it’s for

Owners, operators, and IT leads at SMB Defense Industrial Base contractors who:

  • Subcontract to DoD primes and have received a CMMC Level 2 requirement (or expect one in the next 12 months)
  • Handle Controlled Unclassified Information (CUI) in any form — engineering drawings, technical specs, program documentation, export-controlled data
  • Operate in the Utah DIB ecosystem around Hill Air Force Base or the East Tennessee ecosystem around Oak Ridge National Laboratory
  • Want to score themselves internally before paying for a C3PAO assessment

Found gaps? That’s exactly what the checklist is for.

We run CMMC engagements end-to-end for Utah and East Tennessee defense contractors — gap assessment, CUI enclave, technical controls, SSP & POA&M, mock audit, ongoing operation. 30-minute scoping call to see if we’re a fit.

Schedule a CMMC scoping call

Usage: This document is provided for informational purposes only and is not legal, compliance, or assessment advice. Authoritative CMMC and NIST SP 800-171 Rev. 2 references should be consulted directly. May be redistributed in unmodified form with attribution to Gravity Networks.