CMMC Readiness Checklist for Defense Subcontractors

A practical first-quarter checklist for contractors who touch federal contract information or CUI and need to get ready for CMMC 2.0 requirements in contracts.

3 min readBy Ironfield Cyber Team

If you build, fabricate, haul or supply anything for a company that holds Department of Defense work, CMMC probably landed in your inbox at some point. The program has moved from announcement to contract language, and prime contractors are asking their subcontractors pointed questions about how they protect information. A new year is a good time to stop treating it as someone else's problem.

This checklist is written for owners, controllers and operations leaders, not just IT staff. It will not make you certified, but it will tell you where you stand and what to do first.

Where CMMC stands

The CMMC 2.0 program rule (32 CFR Part 170) took effect on December 16, 2024. The related acquisition rule in the DFARS (48 CFR) took effect on November 10, 2025, which started a phased rollout of CMMC requirements in DoD contracts. In practical terms, that means solicitations can now specify a required CMMC level, and primes must flow those requirements down to subcontractors that handle the relevant information.

The level you need depends on the information you handle:

  • Level 1 covers federal contract information (FCI) and uses a self-assessment against 15 basic safeguarding requirements.
  • Level 2 covers controlled unclassified information (CUI) and is built on the 110 requirements of NIST SP 800-171. Depending on the contract, it is validated by a self-assessment or by a third-party assessment.
  • Level 3 applies to a smaller set of the most sensitive programs.

Step 1: Find out what you actually handle

Ask your prime or contracting officer, in writing, whether you receive FCI or CUI and which contract clauses apply. Many firms assume they handle CUI when they only handle FCI, and some assume the opposite. Get the answer in an email you can file.

Step 2: Map where the information lives

List every place contract documents, drawings, specifications or emails with government data might sit:

  • Email mailboxes and shared mailboxes
  • File servers, SharePoint, OneDrive and Teams
  • Laptops, tablets and phones, including personal devices
  • Project management and document platforms
  • Printers, scanners and USB drives
  • Vendors who touch the data, such as engineers, estimators and outside IT

This map is the foundation of your scope. The smaller and cleaner the scope, the cheaper compliance becomes.

Step 3: Consider an enclave

Many small contractors do better by creating a separate, locked-down environment for CUI work rather than bringing every laptop and every user into scope. A properly built enclave limits the number of people, devices and systems that must meet the full set of requirements. Whether this fits depends on how your business works, so talk it through before you buy anything.

Step 4: Run a gap assessment against NIST SP 800-171

Score yourself honestly against the requirements. For each one, mark it as met, partly met or not met, and write down the evidence. Common weak spots for contractors include:

  • Multifactor authentication that covers email but not remote access or admin accounts
  • No central logging or log review
  • Missing or outdated incident response plan
  • Laptops without full-disk encryption
  • Shared accounts on shop-floor or jobsite computers
  • No documented process for adding and removing user access

Step 5: Write the documents

Assessors look for documentation as much as technology. At minimum you will need a system security plan describing how each requirement is met, and a plan of action and milestones (POA&M) for gaps you are still closing. Policies should match what you really do. A beautiful policy that nobody follows is a liability.

Step 6: Budget time and money

Remediation is rarely only a software purchase. Plan for staff time, possible hardware replacement, a managed security service for monitoring, and an assessment cost if your contract requires a third-party assessment. Build the work into your annual budget instead of reacting when a bid requires it.

Step 7: Talk to your own subcontractors

If you pass CUI downstream, you carry responsibility for those flow-down requirements. Make a list of who receives what, and ask them where they stand.

A realistic timeline

A hypothetical 40-person fabrication shop starting from scratch might spend the first month scoping and the second and third closing the easiest gaps, with larger items such as monitoring and device replacement stretching further. Your pace depends on contract timing, so work backward from your next bid or renewal.

Where Ironfield Cyber fits

Ironfield Cyber helps contractors and energy suppliers scope CMMC work, run gap assessments against NIST SP 800-171, and build the controls that close the gaps. If you want a straight answer on where you stand, ask us for a readiness review and we will walk you through it in plain English.