Three documentation layers
This resource does not score compliance. It helps the organization determine which records can be produced today and which documentation layer may need internal attention.
Contract and information boundary
Solicitation and contract clauses, FCI/CUI handling, systems, users, providers, and subcontractor dependencies.
Policy and document control
Security policy, acceptable use, information handling, ownership, approvals, versions, and review dates.
Mapping and evidence
Requirement mapping, action ownership, access records, incident documentation, evidence, training, and change records.
Locate. Review. Route.
Produce the record
Confirm that the current approved record can be located and its owner is known.
Inspect the control
Review scope, approval, ownership, mapping, version status, or document currency.
Assign the gap
Identify who will locate or construct the record and where the controlled version will reside.
This checklist is a general documentation reference. It is not an audit, assessment, legal opinion, certification, applicability determination, government contracting service, or guarantee of compliance, contract eligibility, or assessment outcome. CMMC implementation status and solicitation language can change. Confirm current requirements with qualified counsel and the appropriate contracting authority.