Back to blogTips & Guides

CMMC Level 2 Compliance Checklist for Chicago Contractors

||5 min read
Share
Blue cybersecurity checklist with shield icon over Chicago skyline in a sleek dark interface.

Is Your Business Ready?

Don't wait for a breach. Assess your security posture in 60 seconds with our free tool.

Run Free Assessment

Protect Chicago DoD Revenue with CMMC Compliance

CMMC Level 2 compliance is now a business-development requirement, not just an IT project, for Chicago contractors handling CUI. If you cannot meet the CMMC status named in a solicitation, you may be excluded from an award, lose renewal opportunities, or create risk for a prime contractor that depends on your work.

With the federal fiscal year ending September 30, we recommend reviewing upcoming recompetes, new bids, subcontractor flow-down clauses, and pipeline opportunities for the following year now. Owners, compliance leaders, IT teams, facility-security staff, and business-development professionals all own part of the outcome. Level 2 includes 110 practices based on NIST SP 800-171, documented implementation, objective evidence, and an assessment path that matches the contract requirement.

Scope CUI and Control Access

Start by defining where CUI enters, lives, moves, and leaves your business. Before buying tools or writing policies, we help Chicago contractors inventory DoD contracts, users, devices, cloud apps, manufacturing systems, office locations, and warehouse operations. Build a system security plan, data-flow diagram, asset inventory, and responsibility matrix.

For Access Control, complete AC 3.1.1 through 3.1.11: limit access to authorized users, devices, and functions; control CUI flow; separate duties; apply least privilege; require routine users to use nonprivileged accounts; prevent unauthorized privileged execution; limit failed logons; show security notices; lock inactive sessions; and end sessions under defined conditions.

Continue with AC 3.1.12 through 3.1.22: monitor and encrypt remote access, route it through managed points, approve remote privileged commands, authorize and secure wireless access, control mobile devices, encrypt CUI on mobile platforms, limit external-system use, restrict portable storage, and control public posting of CUI. We recommend role-based groups, MFA, conditional access, managed remote access, quarterly reviews, and documented approvals.

  • Train all users under AT 3.2.1, provide role-based training under AT 3.2.2, and cover insider-threat awareness under AT 3.2.3.
  • Meet AU 3.3.1 through 3.3.9 with logs that identify users, support review and alerts, synchronize time, protect records, and restrict audit administration.
  • Address CM 3.4.1 through 3.4.9 through secure baselines, change control, impact reviews, least functionality, approved software, deny-by-default settings, and controls on user-installed software.

Make Identity, Incident, and Media Evidence Ready

Identity controls must work in practice and leave evidence an assessor can test. IA 3.5.1 through 3.5.11 require identifying and authenticating users, processes, and devices; MFA for privileged and network accounts; replay-resistant authentication; identifier controls; inactive-account disabling; password complexity and reuse limits; temporary-password changes; cryptographic password protection; and hidden authentication feedback.

Centralized identity management, phishing-resistant MFA where practical, device certificates, password managers, and inactive-account reports help create repeatable proof. Pay close attention to remote engineers, third-party support staff, shared shop-floor devices, and subcontractor access.

Incident Response includes IR 3.6.1 through 3.6.3: maintain an incident-handling capability, track and report incidents, and test the plan. Maintenance controls, MA 3.7.1 through 3.7.6, cover authorized maintenance, tool and media control, offsite sanitization, malware checks, MFA for nonlocal work, and supervision of unauthorized personnel. Tabletop exercises should cover ransomware, a compromised supplier account, a lost laptop, and suspicious activity at a Chicago facility.

Media Protection, MP 3.8.1 through 3.8.9, requires protection, access limits, marking, transport safeguards, accountability, encryption, removable-media controls, portable-storage restrictions, and proper disposal. Chain-of-custody logs, approved encrypted media, secure shredding, and sanitization certificates turn these controls into evidence.

Secure People, Facilities, Recovery, and Risk

Personnel Security starts with PS 3.9.1 and 3.9.2: screen people before granting CUI access and protect CUI during termination or transfer. Physical Protection, PE 3.10.1 through 3.10.6, requires controlled facility access, monitoring, visitor escorts and logs, access records, physical-device management, and protection for alternate work sites.

A secure downtown office does not automatically protect CUI used by hybrid employees. Badge reports, visitor procedures, locked network closets, clean-desk rules, offboarding checklists, and approved home-office arrangements should all be documented.

Recovery is not a separate domain in the 110-practice Level 2 model, but tested recovery supports incident response, risk management, security assessment, and uninterrupted contract performance. Maintain encrypted, immutable backups; set recovery time and recovery point goals; test CUI restoration; assign recovery roles; and preserve proof from every exercise.

Risk Assessment controls, RA 3.11.1 through 3.11.3, require periodic risk reviews, vulnerability scanning, and risk-based remediation. Keep a risk register that assigns owners and due dates for exposed remote-access tools, unsupported systems, unpatched engineering applications, cloud misconfigurations, supplier connections, and aging operational technology.

Prove Technical Safeguards and Assessment Readiness

Policies alone do not satisfy CMMC compliance. CA 3.12.1 through 3.12.4 require periodic control assessments, plans of action and milestones, ongoing monitoring, and a maintained system security plan. Assessors need to see configurations, interviews, tickets, screenshots, logs, reports, and consistent evidence, not just written promises.

System and Communications Protection, SC 3.13.1 through 3.13.16, covers boundary defense, secure architecture, separation of user and security functions, shared-resource protections, public-system separation, deny-by-default traffic, split-tunneling limits, encryption in transit, inactive connections, cryptographic keys, FIPS-validated cryptography, collaborative computing, mobile code, session authenticity, and CUI encryption at rest.

System and Information Integrity, SI 3.14.1 through 3.14.7, requires flaw remediation, malware protection and updates, alert monitoring, scanning, attack detection, and identification of unauthorized system use. Managed detection and response, endpoint protection, vulnerability management, patch service levels, and 24/7 monitoring can help keep these safeguards operating when your internal team is off the clock.

Plan the Work Before Bids Create Pressure

A focused CUI environment may reach assessment readiness in roughly 90 to 180 days. Multiple locations, legacy systems, unmanaged cloud tools, or widespread CUI can require six to 12 months. A 90-day timeline depends on the existing environment, CUI scope, available resources, remediation needs, and the assessment requirements in the applicable contract.

Budget planning should account for readiness review, documentation, identity improvements, endpoint and logging tools, network segmentation, secure backups, managed security operations, training, remediation labor, and third-party assessment fees. Delays often come from unclear CUI boundaries, unmanaged personal devices, missing FIPS requirements, weak log retention, untested recovery, unresolved POA&M items, or business-development teams learning the requirement after a proposal is submitted.

Protect contract eligibility by identifying current and future DoD opportunities, locating CUI, assessing all 110 practices, prioritizing high-risk gaps, assigning accountable owners, and building an evidence calendar. Starting before a solicitation gives your team more control, makes readiness a condition of participation, strengthens prime-contractor confidence, and reduces avoidable contract risk.

Turn CMMC Readiness Into Contract Confidence

EFROS helps Chicago contractors create a practical path from assessment findings to defensible evidence and accountable remediation. See how we support CMMC compliance with structured guidance tailored to operational realities. When you are ready to strengthen your compliance program, contact us to discuss your next steps.

Frequently Asked Questions

What is CMMC Level 2 compliance for Chicago defense contractors?

CMMC Level 2 is a cybersecurity certification level for contractors that handle Controlled Unclassified Information, or CUI, on Department of Defense work. It includes 110 security practices based on NIST SP 800-171 and requires documented implementation and evidence that controls are working.

Do subcontractors need CMMC Level 2 certification?

Subcontractors may need CMMC Level 2 if they handle CUI or if the prime contract includes a Level 2 requirement that flows down to them. The required certification status depends on the solicitation, contract terms, and the subcontractor's role in accessing or processing CUI.

How do I prepare for a CMMC Level 2 assessment?

Start by identifying where CUI enters, is stored, moves, and leaves the organization. Create a system security plan, data-flow diagram, asset inventory, and responsibility matrix, then collect objective evidence for access controls, MFA, logging, training, incident response, and other required practices.

What is the difference between CMMC Level 1 and CMMC Level 2?

CMMC Level 1 focuses on basic cyber hygiene for contractors that handle Federal Contract Information, or FCI. Level 2 applies to organizations handling CUI and requires 110 practices aligned with NIST SP 800-171, documented policies and procedures, and assessment evidence.

What evidence is needed for CMMC Level 2 compliance?

Assessors typically need evidence that controls are implemented and operating, not just written policies. Useful evidence includes access review records, MFA configurations, audit logs, asset inventories, security training records, incident response test results, change-control documentation, and approvals for remote access or portable media.