A CMMC self assessment is how a Defense Industrial Base contractor checks its own security controls against the CMMC practices before a formal review. This free CMMC self assessment checklist gives you a 63-item Excel workbook to run that check yourself, score each practice, and see where you stand before a certified third-party assessment organisation (C3PAO) or a contracting officer ever looks. It is built for the person who owns compliance at a defense supplier: the CISO, the IT lead, or the compliance manager who needs a clear picture of readiness against the NIST SP 800-171 security requirements that CMMC Level 2 aligns to. Download it below, work through it row by row, and turn a vague sense of "we should be fine" into an evidenced position you can defend when the certified assessor arrives.
Get the CMMC Level 2 Self-Assessment Checklist
Self-assess against the CMMC practices before a formal assessment. 63 items. Not a substitute for a C3PAO assessment.

What the CMMC Level 2 Self-Assessment Checklist covers
The checklist is a single Excel workbook with one row per practice and a set of columns designed to mirror how a real assessment runs. For each item you get:
- Practice reference - the identifier and a plain-language description of what the requirement asks for.
- Status - a dropdown to mark each practice Met, Partially Met, or Not Met, so the sheet reflects your true position.
- Evidence and notes - where you record the policy, configuration, or artifact that proves the practice is in place.
- Owner - the person or team accountable for that control.
- POA&M reference - a pointer to the Plan of Action and Milestones entry for anything not yet met.
The 63 items are grouped to follow the NIST SP 800-171 security requirement families that CMMC Level 2 aligns to, so the structure matches what an assessor will walk through. A summary tab rolls up your Met, Partially Met, and Not Met counts so you can read your readiness at a glance without building your own formulas. Treat the file as a way to get organised, and verify the exact practice set against the current NIST SP 800-171 revision. It is a preparation aid, not a substitute for a formal C3PAO assessment.

CMMC the honest way: what actually matters
CMMC (Cybersecurity Maturity Model Certification) applies to contractors in the US Defense Industrial Base that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The model sets three levels, and the level you need is driven by the contract and the type of information you touch.
Level 1 covers basic safeguarding and is met by self-assessment. Level 2 aligns to the NIST SP 800-171 security requirements and is where most contractors handling CUI land; depending on the contract, Level 2 is assessed either by self-assessment or by a certified third-party assessment organisation (C3PAO). Level 3 sets higher requirements for the most sensitive work.
Three artifacts do the heavy lifting. A System Security Plan (SSP) documents how each requirement is implemented across your environment. A Plan of Action and Milestones (POA&M) records what is not yet met and when you will close it. And you post a score in the Supplier Performance Risk System (SPRS) so the government can see your self-assessed position. A CMMC self assessment is the internal exercise that produces all three: it tells you what to write in the SSP, what to log in the POA&M, and what score to submit to SPRS.
The honest part: passing your own checklist is not the same as passing a C3PAO assessment. Where a Level 2 contract requires third-party certification, an assessor will test your evidence, not just your claims. Use the self assessment to find the gaps early, fix the ones you can, and document the rest - so there are no surprises when the formal review arrives.

How to use the CMMC Level 2 Self-Assessment Checklist
- Define your scope. Identify every system, cloud service, and location where FCI or CUI is stored, processed, or transmitted. The assessment only means something if the boundary is right.
- Work through each practice. For every row, decide honestly whether the control is Met, Partially Met, or Not Met, and record the evidence that backs the decision.
- Log gaps in the POA&M column. Anything not fully met becomes a Plan of Action and Milestones entry with an owner and a target date.
- Feed the results into your SSP. Use the completed rows as the raw material for your System Security Plan.
- Calculate and post your SPRS score. Roll up the results and submit your self-assessed score where the contract requires it.
- Re-run before the formal assessment. Close what you can, then repeat the checklist so your evidence is current when a C3PAO or contracting officer reviews it.

Do this automatically in Venvera
The checklist is a solid starting point, but a spreadsheet goes stale the moment your environment changes. In Venvera, the same CMMC Level 2 work lives in the CMMC framework as a maintained control set, so status, evidence, and ownership stay current instead of drifting in a file someone last touched months ago. Evidence you attach once is reused across every framework that asks for the same control, so the access-management proof you gather for CMMC also answers the equivalent NIST SP 800-171 or ISO 27001 requirement without re-uploading. Pricing starts from EUR 399/month. The workbook gets you oriented; the platform keeps you assessment-ready between now and your next C3PAO review.
Frequently Asked Questions
Is a CMMC self assessment enough for certification?
For Level 1, and for Level 2 contracts that allow self-assessment, a self assessment can be the basis of the score you post. But where a Level 2 contract requires certification, only a certified third-party assessment organisation (C3PAO) can certify you. Use this checklist to prepare, not to replace that formal assessment.
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers basic safeguarding of Federal Contract Information and is met by self-assessment. Level 2 aligns to the NIST SP 800-171 security requirements, applies to contractors handling Controlled Unclassified Information, and is met by self-assessment or by a C3PAO depending on the contract.
Do I need an SSP and POA&M to complete a CMMC self assessment?
In practice, yes. Contractors typically produce a System Security Plan (SSP) documenting how each requirement is implemented and a Plan of Action and Milestones (POA&M) for anything not yet met, then post a score in the Supplier Performance Risk System (SPRS). The checklist is structured to feed all three.
How many practices are in the checklist?
This checklist contains 63 items grouped by the NIST SP 800-171 security requirement families that CMMC Level 2 aligns to. Always verify the exact practice set against the current NIST SP 800-171 revision, since the requirements are periodically updated.




