CMMC 2.0 checklist: Level 1 & Level 2 practices for CUI
CMMC 2.0 Level 1 & 2 practices for CUI, mapped to the evidence assessors expect, with each control flagged for what a platform can automate.
What CMMC requires
CMMC 2.0 Level 2 is assessed against 14 domains containing 110 practices, built on NIST SP 800-171: Access Control, Awareness & Training, Audit & Accountability, Configuration Management, Identification & Authentication, and more. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.
The control checklist
All 14 CMMC 2.0 Level 2 domains (110 practices, built on NIST SP 800-171). Use the table below as your working checklist — 14 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.
| Control | Requirement | Coverage |
|---|---|---|
| CMMC 2.0 Level 2 domains | ||
| AC | Access Control (22 practices) | Auto |
| AT | Awareness & Training (3) | Manual |
| AU | Audit & Accountability (9) | Auto |
| CA | Security Assessment (4) | Manual |
| CM | Configuration Management (9) | Auto |
| IA | Identification & Authentication (11) | Auto |
| IR | Incident Response (3) | Manual |
| MA | Maintenance (6) | Manual |
| MP | Media Protection (9) | Manual |
| PE | Physical Protection (6) | Manual |
| PS | Personnel Security (2) | Manual |
| RA | Risk Assessment (3) | Auto |
| SC | System & Communications Protection (16) | Auto |
| SI | System & Information Integrity (7) | Auto |
Evidence you must collect
For every control, an auditor expects evidence it operated throughout the review period. Common examples:
- Access reviews with timestamps and approver
- Change tickets linked to deployments
- Encryption and configuration snapshots
- Vendor / supplier risk assessments on file
Automating the checklist
Roughly two-thirds of CMMC controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.
Frequently asked questions
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers 17 basic practices to protect Federal Contract Information (FCI). Level 2 aligns with NIST SP 800-171 — 110 practices across 14 domains to protect Controlled Unclassified Information (CUI).
How many domains and practices does Level 2 have?
14 domains containing 110 practices, built directly on NIST SP 800-171.
Does CMMC require a third-party assessment?
Level 1 and some Level 2 scopes allow self-assessment; most Level 2 (CUI) scopes require a triennial assessment by a Certified Third-Party Assessment Organization (C3PAO).
Which CMMC practices can be automated?
Technical domains — Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, and System & Communications Protection — can be monitored continuously with timestamped evidence.