CMMC Level 2 Readiness Checklist for California Defense Subcontractors Ahead of the November 2026 Deadline

The Department of Defense's CMMC (Cybersecurity Maturity Model Certification) program is no longer theoretical. The 32 CFR CMMC Program final rule took effect December 16, 2024, and the companion DFARS acquisition rule -- the piece that actually puts CMMC clauses into contracts -- took effect November 10, 2025. That second date started a phased rollout: Phase 1 runs through November 10, 2026, during which DoD contracting officers can require CMMC Level 1 or Level 2 self-assessment in new solicitations. Phase 2 begins November 10, 2026, when Level 2 third-party (C3PAO) certification becomes includable, and increasingly mandatory, in new contracts for companies handling Controlled Unclassified Information (CUI). If your business holds or bids on DoD contracts and touches CUI, that November 2026 date is the one to build a plan around.

Before touching a checklist, know which level applies to you. CMMC Level 1 covers companies that only handle Federal Contract Information (FCI) and requires an annual self-assessment against 15 basic safeguarding practices. CMMC Level 2 covers companies that handle CUI and requires alignment with all 110 security controls in NIST SP 800-171, verified either by self-assessment or, for most contracts involving CUI, by a certified third-party assessment organization (C3PAO). Level 3 adds additional controls from NIST SP 800-172 and applies to a small number of contractors handling the most sensitive CUI, assessed directly by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Most California subcontractors in the small-to-midsize prime supply chain will land at Level 2 -- confirm your requirement in your contract's DFARS 252.204-7021 clause or by asking your prime contractor directly.

Your SPRS score is the number that matters most in the run-up to certification. Under NIST SP 800-171, each of the 110 controls contributes to a score ranging from -203 to 110, self-reported into the Supplier Performance Risk System (SPRS). A perfect score of 110 means full implementation; most companies starting this process score well below that. DoD's threshold for conditional certification is a score of at least 80% of the maximum achievable, with the remaining gaps documented in a Plan of Action and Milestones (POA&M) that must be closed within 180 days. Companies scoring below that conditional threshold, or that let a POA&M lapse past 180 days, do not pass. Calculating your current SPRS score honestly -- not aspirationally -- is the real starting point of CMMC readiness, not the final step.

Item 1 on your checklist: run a gap assessment against all 110 NIST SP 800-171 controls, not just the ones that feel obviously relevant. Controls span access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Small subcontractors frequently underestimate how many controls touch physical security and media handling -- a locked server closet and a documented device-disposal process are graded requirements, not just good practice.

Item 2: build or update your System Security Plan (SSP) and POA&M. The SSP documents exactly how your organization implements each of the 110 controls -- what tools, what processes, what boundaries define your CUI environment. Assessors will read this document closely, and it needs to match reality, not describe an aspirational future state. Any control you haven't fully implemented yet belongs in your POA&M with a specific, dated remediation plan. A vague SSP or a POA&M with no real deadlines is one of the most common reasons companies fail their C3PAO assessment on the first attempt.

Close-up of a hand typing on a laptop keyboard representing CMMC readiness for defense subcontractors

Item 3: scope your CUI boundary precisely. One of the most expensive mistakes subcontractors make is treating their entire network as in-scope for CMMC when a properly segmented environment could isolate CUI to a smaller, more defensible boundary. Network segmentation -- separating the systems that touch CUI from general business systems using VLANs, dedicated firewalls, and access controls -- can significantly reduce both your assessment cost and your ongoing compliance burden. This is exactly the kind of physical and network infrastructure work that a licensed low-voltage contractor and MSP working together can execute properly, rather than treating it as a pure software configuration problem.

Item 4: implement multi-factor authentication and encryption across every system touching CUI, if you haven't already. These two controls are consistently where assessors find gaps, because they require both a technology purchase and a policy that's actually enforced -- not just available as an option employees can ignore. MFA needs to cover remote access, privileged accounts, and any cloud services storing CUI. Encryption needs to cover data at rest and in transit, with documented key management, not just a checkbox in a cloud provider's settings panel.

Item 5: address the C3PAO capacity problem in your timeline, because it's real and it's not going away before your deadline. As of this writing, there are roughly 80-100 accredited C3PAOs nationally and only a few hundred certified assessors to cover tens of thousands of companies that will eventually need Level 2 certification. Reported wait times for scheduling an assessment already run six months or longer in some regions, and that bottleneck is expected to worsen as Phase 2 approaches in November 2026 and demand spikes. If your contract requires certification by a specific date, the practical deadline for starting your assessment is likely 6-9 months earlier than that date, not the date itself.

Item 6: confirm your annual affirmation and triennial reassessment obligations don't stop after your first certification. CMMC isn't a one-time achievement -- Level 2 certified companies must submit an annual affirmation confirming continued compliance and undergo full reassessment every three years. Build the cost and staff time for ongoing compliance into your budget now, not as a surprise when the affirmation deadline arrives. Companies that treat certification as a finish line rather than an ongoing program tend to let controls drift and fail their reassessment.

Item 7: don't assume your IT provider or cloud vendor's compliance claims cover you automatically. A cloud service provider being "FedRAMP authorized" or an MSP claiming to be "CMMC compliant" doesn't transfer certification to your business -- you still need your own SSP, your own POA&M, and in most cases your own assessment. If you rely on an External Service Provider (ESP) for any part of your CUI environment, that relationship needs to be documented in your SSP with a clear shared-responsibility breakdown, and your ESP needs to be willing to support your assessment with evidence, not just marketing claims.

For California defense subcontractors specifically -- concentrated around San Diego's naval and shipbuilding supply chain, the Inland Empire's logistics and manufacturing base, and defense-adjacent tech companies statewide -- the practical sequence is: run the gap assessment now, build a realistic SSP and POA&M with real dates, address network segmentation and MFA/encryption gaps, and get on a C3PAO's calendar well before you think you need to. Waiting until a prime contractor asks for proof of certification puts you at the back of an assessor queue that's already backed up, at exactly the moment your contract eligibility depends on moving fast.

Mytek Pros is a licensed managed IT services provider and low-voltage contractor based in Carlsbad, California (License #1116987) with DIR public-works registration (PW-LR-1001158430), and a DBE/DVBE/MBE-certified firm that works directly with California defense subcontractors on CMMC and NIST 800-171 readiness -- gap assessments, SSP and POA&M documentation, network segmentation, and the physical and technical controls that close real findings, not just paperwork. If your business needs to be ready for CMMC Level 2 before the November 2026 deadline tightens further, contact Mytek Pros at 619-353-5702 or inquire@mytekpros.com to start your gap assessment.

Questions about audits? Get in touch or explore our Audits services.