US Defense · CMMC 2.0 · Free Excel template

CMMC Level 2 Checklist and Self-Assessment Workbook (Free Excel Template)

This free CMMC Level 2 checklist helps defense contractors find out where they stand before an assessor does. It contains the official requirements, word for word: the 15 FAR 52.204-21 requirements for Level 1 and all 110 NIST SP 800-171 Revision 2 requirements for Level 2.

Mark each requirement MET, NOT MET or N/A and the workbook calculates your SPRS score using the DoD scoring method, flags gaps that are not allowed on a POA&M, and tells you whether you are on track for final status, conditional status or neither.

  • 110Level 2 requirements
  • 15Level 1 requirements
  • 14domains
  • Freeno sign-up
Download the free template .xlsx · 87 KB · Excel 2016+ / Microsoft 365 · Updated Oct 2026

What's inside the workbook

For: US defense contractors and subcontractors, Australian and allied suppliers to US prime contractors, compliance leads and consultants preparing for CMMC.

  1. 01

    Introduction🔒

    How to use the workbook, the official sources it is built on, and the colour legend.

  2. 02

    Scope & Profile

    Organization, CAGE code and UEI, contracts, target CMMC status, asset categories, SSP details and the 180-day POA&M deadline.

  3. 03

    Level 1 (FCI)

    The 15 FAR 52.204-21 requirements with CMMC identifiers, NIST SP 800-171 equivalents, status, implementation and evidence.

  4. 04

    Level 2 (CUI)

    All 110 requirements across 14 domains with typical evidence, responsibility, point values, deductions and POA&M eligibility.

  5. 05

    POA&M

    Plan of action for each NOT MET requirement with milestones, owners, status and days left to the 180-day closeout deadline.

  6. 06

    Dashboard

    SPRS score, Level 1 result, Level 2 outcome, gaps that block conditional status and % MET by domain with a chart.

  • Official requirement text
  • Automatic SPRS score (110 to -203)
  • POA&M eligibility rules built in
  • Partial credit for MFA and FIPS
  • Shared responsibility column for cloud and MSPs
  • Works in Microsoft Excel 2016 and later

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) program is how the US Department of Defense (DoD) verifies that contractors protect the information it shares with them. The program rule, 32 CFR Part 170, took effect on 16 December 2024, and the contract clause DFARS 252.204-7021 began appearing in solicitations from 10 November 2025.

CMMC protects two types of information. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Controlled Unclassified Information (CUI) is more sensitive information that requires safeguarding under law, regulation or government policy, such as technical drawings and specifications for defense systems.

CMMC levels at a glance

  • Level 1 (Foundational): for contractors handling FCI only. 15 requirements from FAR 52.204-21. An annual self-assessment and affirmation in SPRS. Every requirement must be met, and POA&Ms are not allowed.
  • Level 2 (Advanced): for contractors handling CUI. The 110 requirements of NIST SP 800-171 Revision 2. Either a self-assessment or a certification assessment by an authorized C3PAO every three years, depending on the contract, plus an annual affirmation.
  • Level 3 (Expert): for the most sensitive programs. Level 2 certification plus 24 selected requirements from NIST SP 800-172, assessed by the DoD's DIBCAC.

This workbook covers Level 1 and Level 2, which is where the vast majority of the defense industrial base sits.

How the SPRS score is calculated

Level 2 uses the DoD Assessment Methodology, written into 32 CFR 170.24. You start with 110 points and subtract a value for every requirement that is NOT MET:

  • 5 points for 44 requirements whose absence has the greatest impact, such as access control, MFA, incident response and malware protection.
  • 3 points for 14 requirements.
  • 1 point for the remaining 51 requirements.

Two requirements allow partial credit. Multifactor authentication (IA.L2-3.5.3) and FIPS-validated cryptography (SC.L2-3.13.11) lose only 3 points instead of 5 when they are partly implemented. The System Security Plan (CA.L2-3.12.4) has no point value, because without an SSP an assessment cannot be completed. The lowest possible score is -203. Requirements marked N/A are scored as MET.

Conditional status and POA&M rules

You do not need a perfect score to win work. Under 32 CFR 170.21, an organization can achieve conditional Level 2 status with a plan of action and milestones (POA&M) if:

  • the assessment score is at least 88 (80% of 110),
  • no gap on the POA&M is worth more than 1 point, except SC.L2-3.13.11 when encryption is used but not FIPS-validated, and
  • none of these six requirements is NOT MET: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5.

Every POA&M item must then be closed and verified within 180 days. The workbook applies all of these rules automatically and counts down to the deadline.

Why Australian defence suppliers should care

CMMC requirements flow down from US prime contractors to their subcontractors, wherever those subcontractors are based. If your organisation supplies a US defense program, including work linked to AUKUS, you may be asked to show CMMC compliance alongside your obligations under Australia's Defence Industry Security Program (DISP). The two programs are separate, but there is real overlap, and NIST SP 800-171 maps closely to NIST SP 800-53, which many Australian organisations already use. Read more in Defence supply chain security.

How to use the CMMC Level 1 & 2 Readiness Workbook

  1. 1

    Define your scope

    On Scope & Profile, record the organization, contracts, target CMMC status and the assets that handle FCI or CUI, including cloud and managed service providers.

  2. 2

    Assess Level 1

    If you handle FCI only, mark each of the 15 Level 1 requirements MET, NOT MET or N/A, with your implementation statement and evidence.

  3. 3

    Assess Level 2

    If you handle CUI, assess all 110 requirements. Record who is responsible, how each requirement is implemented and where the evidence is.

  4. 4

    Apply partial credit

    For MFA (IA.L2-3.5.3) and FIPS cryptography (SC.L2-3.13.11), set Partial credit to Yes if the requirement is partly in place.

  5. 5

    Build the POA&M

    Log every NOT MET requirement on the POA&M tab with milestones, owners and dates. The tab shows whether each gap is allowed on a POA&M.

  6. 6

    Read the dashboard

    Check your SPRS score, Level 1 result and Level 2 outcome, then fix the gaps that block conditional status first.

Get the CMMC Level 1 & 2 Readiness Workbook

Free download. No sign-up, no email required.

Download (.xlsx, 87 KB)

Frequently asked questions

Is this CMMC checklist based on the official requirements?

Yes. Level 1 uses the 15 requirements in FAR 52.204-21, and Level 2 uses the 110 requirements in NIST SP 800-171 Revision 2, word for word. Scoring and POA&M rules follow 32 CFR 170.24 and 170.21.

Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?

Revision 2. NIST published Revision 3 in May 2024, but the CMMC program rule specifies Revision 2, so Level 2 assessments are performed against Revision 2.

What SPRS score do I need?

A perfect score of 110 gives final Level 2 status. With a score of at least 88 and only POA&M-eligible gaps, you can achieve conditional status, but every POA&M item must be closed within 180 days.

Can I use this for a C3PAO certification assessment?

Use it to prepare. A C3PAO assessor tests each requirement against the assessment objectives in NIST SP 800-171A, so keep evidence for every objective, not just every requirement. Completing this workbook first shows you where you stand before you book the assessment.

Does CMMC apply to Australian companies?

It can. CMMC requirements flow down to subcontractors that handle FCI or CUI on US defense contracts, regardless of where they are based. Australian suppliers to US prime contractors should check their contracts for DFARS 252.204-7021.

Is this template endorsed by the DoD or The Cyber AB?

No. It is an independent template built from the official public sources. Always confirm requirements against the current rule and your contract.

Muhammad Anwar

Built by

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader, ISO 27001 Lead Auditor and Certified GRC Auditor. This template is based on the approach I use in real assessments across Defence, Federal Government and critical infrastructure.

More free templates