This blog was originally published by Justice IT Consulting LLC here

Why a CMMC Checklist Doesn’t Work: Controls vs. Assessment Objectives Explained

Quick answer: A simple checklist doesn’t work for CMMC because you’re not actually graded on the 110 controls themselves. You’re graded on the 320 specific assessment objectives underneath those controls, and each one has to be genuinely met, documented, and provable, not just checked off in general terms. On top of that, CMMC layers additional requirements on top of NIST 800-171, like specific technical rules for virtual desktop infrastructure (VDI) or FedRAMP equivalency for vendors, that a generic checklist won’t capture.

Why People Keep Asking for “The Checklist”

One of the most common things we hear is some version of “can you just give me the checklist?” It’s an understandable ask. CMMC gets talked about like it’s one single thing, one document, one master list you can check off. It isn’t, and treating it that way is one of the most common ways companies end up with a false sense of readiness.

What CMMC Actually Is

CMMC is a collection of Defense Federal Acquisition Regulation (DFARS) rules that live in the Code of Federal Regulations, specifically 32 CFR and 48 CFR. The 32 CFR rule is where CMMC itself gets defined, including its phased rollout. The 48 CFR rule is what actually puts CMMC requirements into effect on contracts. Underneath both of those sits NIST 800-171 Revision 2, which is where the 110 actual security controls live, organized into 14 control families.

Controls vs. Assessment Objectives: The Distinction That Matters Most

Here’s the part that trips up most companies attempting a DIY checklist approach: you are not assessed against the 110 controls as single line items. Each control breaks down into somewhere between one and six specific assessment objectives, adding up to 320 total assessment objectives across the framework. Those objectives, not the high-level control descriptions, are what an assessor actually evaluates.

Take a control like maintaining an authorized user list. On paper, that sounds simple: “yeah, we’ve got Active Directory.” But the assessment objectives underneath that control ask more specific questions than that, and a generic “yes, we do that” answer, without understanding exactly what’s being asked, is one of the most common ways companies self-inflate a compliance score that doesn’t reflect reality.

The CMMC Overlay: What Sits on Top of NIST 800-171

Beyond the base controls, CMMC adds its own specific technical requirements on top of NIST 800-171, sometimes called the CMMC overlay. A few concrete examples:

If you implement virtual desktop infrastructure (VDI) to keep an endpoint out of scope, the DoD has specific technical requirements for that VDI session to actually count: no clipboard access between the endpoint and the session, no mapped drives, no screen capture, and no other pathway for data to leave the session. Get any of that wrong and the endpoint connecting to your VDI session comes back into scope, which changes your entire assessment boundary.

If you use an External Service Provider (ESP) that handles CUI, that provider generally needs to be FedRAMP authorized or meet the DoD’s specific definition of FedRAMP equivalent, which is its own separate thing to research and confirm, not something you can assume based on a vendor’s general security marketing.

Neither of these shows up on a simple control checklist, but both can determine whether your actual environment passes an assessment.

Why This Requires Real Learning, Not Just a Document

Getting comfortable with CMMC tends to follow a predictable arc: early on, you feel confident, because it looks like a manageable list of requirements. Then, as you actually dig into 32 CFR, DFARS clauses like 252.204-7012, 7019, and 7021, NIST 800-171 itself, the CMMC assessment guide, and the DoD’s own FAQ documents (which aren’t officially binding but are treated as authoritative in practice), your confidence tends to drop as you realize how much cross-referencing is actually required. That’s a normal part of the process, not a sign you’re doing something wrong. Confidence tends to come back once you’ve actually put the pieces together, but that only happens through real engagement with the material, not a one-page checklist.

What to Do Instead of Looking for a Checklist

Download the DoD’s official Level 2 Assessment Guide directly from the DoD CIO’s site and use it to walk through your environment control by control, objective by objective. If you don’t have someone in-house who has been through formal CMMC training, been to industry conferences, or listened through the Cyber AB town halls, seriously consider bringing in outside help, even if you have a capable general IT person. Understanding the assessment objectives, not just the control titles, is what actually determines whether your environment is ready.

Bottom Line

A checklist treats CMMC’s 110 controls as the finish line. In reality, the 320 assessment objectives underneath those controls, plus the additional CMMC-specific requirements layered on top of NIST 800-171, are what actually determine whether you pass an assessment. Skipping straight to a checklist mentality is one of the fastest ways to end up with a compliance program that looks complete on paper and falls apart under real scrutiny.

Published by Austin Justice, Justice IT Consulting LLC