Getting Started with CMMC 2.0 Checklist
Achieving CMMC 2.0 certification is a critical step for organizations that handle Controlled Unclassified Information (CUI) and want to do business with the U.S. Department of War.
This guide to CMMC 2.0 Level 2 Certification provides a clear, structured roadmap to help you navigate the certification process efficiently—from understanding the different CMMC levels and scoping your environment to preparing for formal assessments and artifact submission. Whether you’re pursuing Level 1 self-assessment or preparing for Level 2 or 3 third-party certification, following these steps will help you identify gaps early, stay compliant with official requirements, and build a solid foundation for success.
1. Understand CMMC Levels & Scoping
☐ Identify which CMMC level applies to your organization (Level 1, 2, or 3)
☐ Define the assessment scope (systems, assets, environments to be evaluated)
2. Review Official Guidance & Requirements
☐ Download and review official CMMC guides for your required level
☐ For Level 1: Review the 15 safeguarding requirements in FAR 52.204-21
3. Conduct a Self-Assessment (Level 1 + some Level 2)
☐ Perform a self-assessment against CMMC requirements. Take our quiz
☐ Document gaps, findings, and remediation needs
☐ Submit required Level 1 results to SPRS
4. Engage Third Parties When Needed
☐ Determine if you need support from a consultant or RPO
☐ For certification (Level 2/3): Schedule with an accredited C3PAO
5. Follow the Correct Assessment Guide
☐ Download and use the CMMC Assessment Guide for your target level
☐ Prepare for a formal certification assessment (required for higher levels)
6. Prepare for Artifact Handling & Hashing
☐ Gather required artifacts
☐ Follow hashing procedures required for certification reviews
7. Utilize Available Resources
☐ Reference official linked documents and process guides
☐ Contact a CMMC expert or RPO (such as CTI) for support or clarification
