Self-assessment guide

    The CMMC Level 2 Self-Assessment Checklist (All 110 Controls)

    CMMC Level 2 is aligned to the 110 security requirements of NIST SP 800-171 Rev. 2, organized into 14 domains. This checklist walks through every domain, what a self-assessment actually involves, and how the SPRS score comes out of it — so you know what you're being measured on before an assessor shows up.

    How the self-assessment works

    A CMMC L2 self-assessment is only permitted for a limited set of CUI programs — most CUI-carrying contracts require a C3PAO third-party assessment. But every organization should run an internal self-assessment first: it produces your SPRS score, drives your SSP, and tells you whether you're ready to invite a C3PAO.

    The workflow, at a glance:

    1. Scope — identify which assets store, process, or transmit CUI. Wrong scope = wrong score.
    2. Assess every objective in each of the 110 requirements against NIST 800-171A. All-or-nothing per control.
    3. Score — start at 110, subtract 1/3/5 points per unmet control (DoD Assessment Methodology weights).
    4. POA&M the gaps you can close in 180 days (score must be ≥ 88 and control must be POA&M-eligible).
    5. Submit the score, scope, and assessment date to SPRS with an affirming-official attestation.

    Doing this by hand takes days.

    Athena runs the same 110-control assessment in ~60 seconds and shows you exactly where the deductions land. Free — no signup.

    Start the free Quick Score

    The 14 domains — 110 controls total

    CodeDomainControlsWhat it covers
    ACAccess Control22Least privilege, session control, remote access, external systems.
    ATAwareness & Training3Security awareness for users and privileged roles.
    AUAudit & Accountability9Logging, review, protection, and retention of audit records.
    CMConfiguration Management9Baselines, change control, least functionality, USB/software allow-lists.
    IAIdentification & Authentication11Unique IDs, MFA, password complexity, credential management.
    IRIncident Response3IR plan, handling, reporting, and testing.
    MAMaintenance6Controlled maintenance, media sanitization, remote maintenance MFA.
    MPMedia Protection9Marking, storage, transport, and sanitization of media and CUI.
    PSPersonnel Security2Screening and termination/transfer procedures.
    PEPhysical Protection6Facility access, visitor logs, alternate sites, monitoring.
    RARisk Assessment3Risk assessments and vulnerability scanning cadence.
    CASecurity Assessment4SSP, control assessment, POA&M, continuous monitoring.
    SCSystem & Communications Protection16Boundary protection, FIPS crypto, session termination, DNS.
    SISystem & Information Integrity7Flaw remediation, malicious code protection, monitoring, alerts.
    Total110

    How SPRS scoring works, in one paragraph

    You start at 110. Each of the 110 requirements is worth 1, 3, or 5 points, weighted by risk under the DoD Assessment Methodology. Scoring is all-or-nothing per control — miss one objective (per NIST 800-171A) and you lose the full point value. The lowest possible score is -203. A Final CMMC L2 status requires 110 with all controls met; Conditional is available at 88–109 with a valid POA&M closed within 180 days; below 88 there is no CMMC status.

    Full walkthrough with worked examples: how to calculate your SPRS score.

    Checklist structure — how to run it by domain

    For each of the 14 domains, do the same four passes:

    1. Read every requirement's objectives in NIST 800-171A. This is what an assessor grades against — not the requirement summary.
    2. Ask "who does this, on what asset, and how do I know?" — the answer is the evidence.
    3. Mark met / not met per objective. If any objective is not met, the whole control is not met.
    4. Capture the evidence artifact (policy, config export, log sample, screenshot) with the date and the person who produced it.

    For domain-specific evidence examples, see the Athena CMMC control evidence library, which has per-control pages for the highest-weighted requirements (3.1.1 access control, 3.5.3 MFA, 3.13.11 FIPS encryption, and more).

    Run all 110 automatically.

    Get an evidence-backed SPRS score projection in 60 seconds — free, no signup, no credit card.

    • All 110 controls
    • SPRS score projection
    • No signup required
    Start the free Quick Score

    Frequently asked questions

    How many controls are in CMMC Level 2?

    110 — the same 110 security requirements as NIST SP 800-171 Rev. 2, organized into 14 domains.

    Can I self-assess for CMMC Level 2?

    Only for a limited set of CUI programs designated as self-assessment-eligible. Most CUI-carrying DoD contracts require a C3PAO third-party assessment. Check the specific contract or solicitation.

    What's the passing SPRS score for CMMC Level 2?

    110 with all controls met supports Final status. 88–109 with a valid POA&M supports Conditional status (180 days to close). Below 88 is no CMMC status.

    What's the difference between a requirement and an objective?

    A requirement is the top-level control (e.g. 3.5.3, Use multifactor authentication). Objectives are the specific determinations an assessor makes about that requirement, per NIST 800-171A. Scoring is per-control, but grading is per-objective — miss one objective and the control fails.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.