Cybersecurity GRC 19 items
NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment
Self-assessment of Controlled Unclassified Information (CUI) safeguards required for CMMC 2.0 Level 2, mapped to NIST SP 800-171 control families.
NIST 800-171 Rev 2CMMC 2.0
Free PDF · enter your email to download.
Access Control (3.1)
- Is system access limited to authorized users, processes, and devices? *
- Is the flow of CUI controlled in accordance with approved authorizations? *
- Are CUI connections from external systems controlled and monitored? *
Identification & Authentication (3.5)
- Are users and devices uniquely identified before system access? *
- Is multifactor authentication used for local and network access to privileged accounts? *
- Is password complexity and reuse enforced? *
Audit & Accountability (3.3)
- Are audit logs created and retained to enable monitoring and investigation? *
- Can actions be traced to individual users for accountability? *
- Are audit logs reviewed and analyzed for indications of inappropriate activity? *
Configuration Management (3.4)
- Are baseline configurations established and maintained for systems? *
- Are security configuration settings enforced on IT products? *
- Is the principle of least functionality applied by disabling nonessential services? *
Incident Response & Media Protection (3.6, 3.8)
- Is an operational incident-handling capability established (prepare, detect, contain, recover)? *
- Are incidents tracked, documented, and reported to designated authorities? *
- Is CUI on media protected and access limited to authorized users? *
- Is media sanitized or destroyed before disposal or reuse? *
Scoring & POA&M
- Has an SPRS score been calculated against the 110 controls? *
- What is the current SPRS assessment score?
- Is a Plan of Action and Milestones (POA&M) maintained for open items? *
Download the full NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment checklist
Get it as a clean, printable PDF — free.
