Free Resource · No Email Required
CMMC 2.0 Level 2
Readiness Checklist
A 14-family working checklist built around NIST SP 800-171 Rev. 2. Used internally on every Gravity CMMC engagement. Yours, ungated.
PDF · 17 pages · 108 KB
CMMC 2.0 Level 2 Readiness Checklist
No email gate. No download form. Click the button, get the PDF. If you find it useful and want help applying it, we’re right here.
What’s inside
The checklist mirrors the working document we walk every CMMC client through before any implementation work begins. It’s the version we use internally, not a marketing sanitization.
- →Pre-assessment scoping — identifying CUI, mapping data flows, defining the assessment boundary
- →All 14 NIST SP 800-171 control families with the items SMB DIB contractors most often get wrong
- →Common gotchas — service accounts without MFA, baselines that drift, training records that don't reconstruct
- →Documentation deliverables — what the SSP, POA&M, data-flow diagram, and asset inventory actually need to contain
- →Pre-assessment activities — self-assessment scoring, SPRS posting, mock-audit framework
- →What "ready" actually looks like — the 90-day rule, prioritization when the deadline accelerates
Who it’s for
Owners, operators, and IT leads at SMB Defense Industrial Base contractors who:
- Subcontract to DoD primes and have received a CMMC Level 2 requirement (or expect one in the next 12 months)
- Handle Controlled Unclassified Information (CUI) in any form — engineering drawings, technical specs, program documentation, export-controlled data
- Operate in the Utah DIB ecosystem around Hill Air Force Base or the East Tennessee ecosystem around Oak Ridge National Laboratory
- Want to score themselves internally before paying for a C3PAO assessment
Found gaps? That’s exactly what the checklist is for.
We run CMMC engagements end-to-end for Utah and East Tennessee defense contractors — gap assessment, CUI enclave, technical controls, SSP & POA&M, mock audit, ongoing operation. 30-minute scoping call to see if we’re a fit.
Schedule a CMMC scoping callUsage: This document is provided for informational purposes only and is not legal, compliance, or assessment advice. Authoritative CMMC and NIST SP 800-171 Rev. 2 references should be consulted directly. May be redistributed in unmodified form with attribution to Gravity Networks.
Related
CMMC 2.0 Compliance Services
The full engagement model — gap assessment, control deployment, SSP/POA&M, mock audit, ongoing operation.
Learn more →Defense Contractors Industry
How we work with DIB primes and subs across Utah and East Tennessee.
Learn more →SPRS Score Explained
Plain-English walkthrough of the DoD's self-assessment math and what primes see.
Learn more →