If your contract calls for CMMC Level 3, you need a working plan, not just an understanding of the rules. This checklist breaks the path into ordered tasks. Work through it top to bottom. Each section is a stage you should clear before moving to the next.
Start Here: Confirm You Actually Need Level 3
Before anything else, verify the requirement. Read the contract solicitation. It states the minimum CMMC level for systems that process or transmit CUI. If it does not name Level 3, you may be planning for a tier you do not need. Most contractors handling CUI fall under CMMC Level 2.
Checklist:
- Confirm the solicitation explicitly requires CMMC Level 3.
- Identify which systems and data the requirement applies to.
- Confirm whether the requirement covers a full environment or a defined enclave.
Prerequisite Stage: Lock Down Level 2
CMMC Level 3 cannot begin until your CMMC Level 2 house is in order. Under 32 CFR 170.18, a Final Level 2 (C3PAO) status for the same scope is a hard prerequisite.
Checklist:
- Hold a Final Level 2 (C3PAO) certification, not a self-assessment, and not a Conditional status.
- Confirm the Level 2 certification covers the same scope as your planned Level 3 assessment.
- Close every open Level 2 POA&M item. None can remain when Level 3 begins.
- Record your Level 2 certification assessment unique identifier. You will need it to start Level 3.
A Final Level 2 status requires a maximum score on the Level 2 assessment. If you scraped through on a Conditional basis, finish that work first.
Scoping Stage: Define Your Level 3 Boundary
Scoping decides what DIBCAC assesses. The rules sit in 32 CFR 170.19(d). The Level 3 scope must equal or be a subset of your Level 2 scope.
Checklist:
- Decide whether to assess your full Level 2 environment or a smaller Level 3 enclave.
- Build the enclave with tighter restrictions if a subset makes sense. Many contractors do this.
- Categorize every in-scope asset into one of three types.
- Produce a current network diagram showing the full assessment boundary.
The three asset categories at CMMC Level 3:
- CUI Assets. Anything that can process, store, or transmit CUI, whether intended to or not. Assets you labeled Contractor Risk Managed Assets at CMMC Level 2 are treated as CUI Assets here.
- Security Protection Assets. Systems providing security functions, such as firewalls, SIEM tools, and monitoring platforms. They get a full assessment.
- Specialized Assets. IoT and IIoT devices, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment. Document them in your SSP and assess them against relevant Level 3 requirements.
Implementation Stage: The 24 Enhanced Requirements
CMMC Level 3 adds 24 enhanced security requirements drawn from NIST SP 800-172. They are listed in Table 1 to 32 CFR 170.14(c)(4). They sit atop the 110 NIST SP 800-171 controls already required at Level 2.
Checklist:
- Confirm all 110 CMMC Level 2 controls are implemented and verifiable for the Level 3 scope.
- Implement each of the 24 enhanced requirements as a working control rather than a written policy.
- Apply the DoD Organization-Defined Parameters (ODPs) where the rule assigns specific values.
- Test each control to confirm it functions as intended.
ODPs are a Level 3-specific detail. Level 2 follows NIST SP 800-171 Revision 2, which has no ODPs. At CMMC Level 3, the DoD assigns fixed values inside certain controls, so you cannot set your own. The 24 requirements span domains including Access Control, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Personnel Security, Risk Assessment, and System and Communications Protection.
Cloud Stage: Verify Provider Compliance
If any cloud service processes, stores, or transmits CUI within your CMMC Level 3 scope, it must meet a baseline.
Checklist:
- Confirm the cloud product is FedRAMP Authorized at the Moderate baseline or higher.
- If it is not FedRAMP Authorized, confirm it meets security requirements equivalent to FedRAMP Moderate under DoD policy.
- Document the provider, the services used, and the split of responsibilities in your SSP and a customer responsibility matrix.
Using a compliant provider does not transfer your obligations. You still have to implement all 24 Level 3 requirements yourself.
Evidence Stage: Prepare for the Assessment
DIBCAC verifies implementation through three methods: interviews, examinations, and tests. Interviews show what the staff believes is true. Documentation shows policies and procedures exist. Testing shows whether a control actually works. You need evidence for all three.
Checklist:
- Gather evidence for every assessment objective behind each requirement.
- Confirm all evidence is in final form. Under 32 CFR 170.24, draft evidence does not count toward a MET finding.
- Keep an updated System Security Plan that reflects the current environment.
- Prepare staff to speak to the controls they own.
- Retain the hashed artifacts used as evidence, as required by the rule.
A requirement is scored as MET only when all applicable assessment objectives are satisfied. One unmet objective drops the whole requirement to NOT MET.
Submission Stage: Initiate the DIBCAC Assessment
CMMC Level 3 certification assessments are conducted by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC). It is a government-led audit, not a third-party one.
Checklist:
- Email a Level 3 assessment request to the DCMA DIBCAC point of contact.
- Include your CMMC Level 2 certification assessment unique identifier in the request.
- Wait for DIBCAC to validate your Level 2 status and schedule the assessment.
Scoring Stage: Understand the Pass Bar
Each CMMC Level 3 requirement is worth one point. Under the scoring methodology, your score equals the number of requirements assessed as MET. The maximum drops by one point for each requirement found NOT MET.
Checklist:
- Aim for a MET result on all 24 requirements to reach Final Level 3 (DIBCAC) directly.
- Know the Conditional threshold: your score divided by the total must be at least 0.8.
- Confirm none of your gaps fall on requirements barred from a POA&M.
POA&M Stage: If You Land on Conditional Status
If you qualify for Conditional Level 3 (DIBCAC), the clock starts immediately. Under 32 CFR 170.21, you have 180 days from the Conditional CMMC Status Date to close every POA&M item.
Checklist:
- Build a POA&M with detailed tasks, owners, milestones, and evidence of progress.
- Remediate every NOT MET item within the 180-day window.
- Schedule the DIBCAC closeout assessment, which covers only the NOT MET items.
- Track the date closely. If the window expires, the Conditional status does as well.
If Conditional status lapses during a contract’s period of performance, standard contractual remedies apply, and you lose eligibility for new Level 3 awards until you earn a fresh status.
Maintenance Stage: Keep the Certification Active
Certification is not a one-time event. It runs on a three-year cycle with annual obligations.
Checklist:
- Repeat the CMMC Level 3 assessment every three years for all in-scope systems.
- Maintain a current Level 2 (C3PAO) certification, which is reassessed every 3 years and is a prerequisite.
- Submit annual affirmations in the Supplier Performance Risk System (SPRS).
- Appoint an Affirming Official to sign those affirmations.
One scheduling note: the CMMC Status Date does not reset when you close a POA&M. Using the full 180 days gives you about 2.5 years of full certification before the next assessment.
Working the Checklist Effectively
Treat the stages in order. Scoping mistakes cascade into wasted implementation work. Evidence gaps surface as NOT MET findings that could have been caught months earlier. The contractors who pass cleanly are usually the ones who tested their controls against the NIST SP 800-172A assessment objectives before DIBCAC arrived, rather than assuming a documented policy would carry the finding.
If your contract pipeline points toward a CMMC Level 3 requirement, begin at the prerequisite stage now. The Level 2 foundation and the enclave build take the longest, and they are the items you cannot rush once a solicitation deadline is in front of you.



