simpl.
Cybersecurity GRC 19 items

NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment

Self-assessment of Controlled Unclassified Information (CUI) safeguards required for CMMC 2.0 Level 2, mapped to NIST SP 800-171 control families.

NIST 800-171 Rev 2CMMC 2.0

Free PDF · enter your email to download.

Access Control (3.1)

  • Is system access limited to authorized users, processes, and devices? *
  • Is the flow of CUI controlled in accordance with approved authorizations? *
  • Are CUI connections from external systems controlled and monitored? *

Identification & Authentication (3.5)

  • Are users and devices uniquely identified before system access? *
  • Is multifactor authentication used for local and network access to privileged accounts? *
  • Is password complexity and reuse enforced? *

Audit & Accountability (3.3)

  • Are audit logs created and retained to enable monitoring and investigation? *
  • Can actions be traced to individual users for accountability? *
  • Are audit logs reviewed and analyzed for indications of inappropriate activity? *

Configuration Management (3.4)

  • Are baseline configurations established and maintained for systems? *
  • Are security configuration settings enforced on IT products? *
  • Is the principle of least functionality applied by disabling nonessential services? *

Incident Response & Media Protection (3.6, 3.8)

  • Is an operational incident-handling capability established (prepare, detect, contain, recover)? *
  • Are incidents tracked, documented, and reported to designated authorities? *
  • Is CUI on media protected and access limited to authorized users? *
  • Is media sanitized or destroyed before disposal or reuse? *

Scoring & POA&M

  • Has an SPRS score been calculated against the 110 controls? *
  • What is the current SPRS assessment score?
  • Is a Plan of Action and Milestones (POA&M) maintained for open items? *

Download the full NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment checklist

Get it as a clean, printable PDF — free.