All resources
CMMCL1 / L2Checklist

CMMC 2.0 checklist: Level 1 & Level 2 practices for CUI

Official source: DoD CMMC 2.0

CMMC 2.0 Level 1 & 2 practices for CUI, mapped to the evidence assessors expect, with each control flagged for what a platform can automate.

What CMMC requires

CMMC 2.0 Level 2 is assessed against 14 domains containing 110 practices, built on NIST SP 800-171: Access Control, Awareness & Training, Audit & Accountability, Configuration Management, Identification & Authentication, and more. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

All 14 CMMC 2.0 Level 2 domains (110 practices, built on NIST SP 800-171). Use the table below as your working checklist — 14 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
CMMC 2.0 Level 2 domains
ACAccess Control (22 practices)Auto
ATAwareness & Training (3)Manual
AUAudit & Accountability (9)Auto
CASecurity Assessment (4)Manual
CMConfiguration Management (9)Auto
IAIdentification & Authentication (11)Auto
IRIncident Response (3)Manual
MAMaintenance (6)Manual
MPMedia Protection (9)Manual
PEPhysical Protection (6)Manual
PSPersonnel Security (2)Manual
RARisk Assessment (3)Auto
SCSystem & Communications Protection (16)Auto
SISystem & Information Integrity (7)Auto

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of CMMC controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Frequently asked questions

What is the difference between CMMC Level 1 and Level 2?
Level 1 covers 17 basic practices to protect Federal Contract Information (FCI). Level 2 aligns with NIST SP 800-171 — 110 practices across 14 domains to protect Controlled Unclassified Information (CUI).

How many domains and practices does Level 2 have?
14 domains containing 110 practices, built directly on NIST SP 800-171.

Does CMMC require a third-party assessment?
Level 1 and some Level 2 scopes allow self-assessment; most Level 2 (CUI) scopes require a triennial assessment by a Certified Third-Party Assessment Organization (C3PAO).

Which CMMC practices can be automated?
Technical domains — Access Control, Audit & Accountability, Configuration Management, Identification & Authentication, and System & Communications Protection — can be monitored continuously with timestamped evidence.

Turn this checklist into a live dashboard

SBCMSP tracks every CMMC control continuously across all your clients.