sha3:560a3f362b6e2526905b3ef5534b700e726d0b2ab71a6e0e30be3c5544750a66IntactCMMC LEVEL 2 / NIST SP 800-171 REV 2
110 controls, 14 families, one checklist.
The CMMC Level 2 checklist lists all 110 NIST SP 800-171 Rev 2 controls, organized by the 14 control families, with implementation status tracking, an evidence documentation guide, and a POA&M template. It is sent by email as a PDF at no cost. The families and their control counts are printed below.
2cbf775204c30a66d4ac339593889eb4d5be1e8e62f3b99c7e9aaf3ab2049734prev:5ac0b879f165Fourteen families, 110 controls
The checklist covers every control family in NIST SP 800-171 Rev 2, required for CMMC Level 2 certification. Fourteen families; the counts below sum to 110.
- AC
Access Control
22 controls - AT
Awareness and Training
3 controls - AU
Audit and Accountability
9 controls - CM
Configuration Management
9 controls - IA
Identification and Authentication
11 controls - IR
Incident Response
3 controls - MA
Maintenance
6 controls - MP
Media Protection
9 controls - PE
Physical and Environmental Protection
6 controls - PS
Personnel Security
2 controls - RA
Risk Assessment
3 controls - CA
Security Assessment
4 controls - SC
System and Communications Protection
16 controls - SI
System and Information Integrity
7 controls
Total: 110 controls across 14 families
f8e860e5736a5fc56f4bf19436043b3d1505a4bfc8077972c747f915e261204eprev:2cbf775204c3What the document contains
One PDF. Built for defense contractors validating Phase I self-assessments now and preserving readiness for the CMMC model that follows the Phase II review.
- 01
All 110 NIST 800-171 controls
- 02
Organized by 14 control families
- 03
Implementation status tracking
- 04
Evidence documentation guide
- 05
POA&M template included
f5e39cb809ed68130eb7d53bc4290e1c75d1e349d73363af384f1794924ccf2eprev:f8e860e5736aThe same 110, as evidence
A checklist lists the requirements; it does not observe your environment. PolicyCortex records the evidence for the same 110 requirements inside your tenant: every observation content hashed with SHA3-256, timestamped, appended to the chain, retained seven years. A control that stopped being observed produces a declared gap, not a stale green.
Work the checklist requirement by requirement, then hand the assessor a package built to be verified rather than believed. Read what the assessor receives.
560a3f362b6e2526905b3ef5534b700e726d0b2ab71a6e0e30be3c5544750a66prev:f5e39cb809edQuestions about the checklist
- Q-01
How many controls are in the CMMC Level 2 checklist?
110, the full set of NIST SP 800-171 Rev 2 requirements, organized into 14 control families. The counts per family are printed on this page and sum to 110.
- Q-02
What is included besides the control list?
Implementation status tracking, an evidence documentation guide, and a POA&M template, in one PDF sent by email.
- Q-03
Does completing the checklist make us CMMC compliant?
No. It organizes the requirements. CMMC Level 2 certification assessments are performed by a C3PAO against all 110 requirements; PolicyCortex is not a C3PAO and does not certify anything.
From a checklist to a record you can verify.