" /> CMMC Level 2 Checklist 2026: Weekly, Monthly, Annual Tasks
Veiledning

CMMC Level 2 Continuous Compliance Checklist: Weekly, Monthly, Quarterly and Annual Tasks, with a Baltimore Case Study (2026)

Declaring CMMC Level 1 or Level 2 is the start. The annual affirmation depends on the routine work done all year: log reviews, stale accounts, vulnerability scans, patching. Here is the full calendar, the hours it takes and a free Excel tracker.

Oppdatert · okt 2026 By ITSECOPS Gratis · Ingen påmelding

Case study and checklist · United States · Updated October 6, 2026

Short answer: declaring CMMC Level 1 or Level 2 is the start, not the finish. Under 32 CFR 170.22 a senior Affirming Official must affirm in SPRS, every year, that the company still meets every requirement. That statement rests on routine work done all year: 37 recurring activities such as security log review, stale user clean-up, SIEM alert review, vulnerability scanning and patching. For about 50 users this takes 43 to 68 hours a month. ITSecOps covers those hours through staff augmentation, estimated by the hour per activity, and files the evidence. The Excel tracker is free on request.

CMMC Level 2 recurring activities by cadence: 6 weekly, 9 monthly, 8 quarterly, 5 semi-annual and 9 annual, about 43 to 68 hours a month

Why this matters now

On September 3, 2026, DFARS Class Deviation 2026-O0025 Revision 3 allowed CMMC Level 1 and Level 2 to be satisfied through self-assessment while Phase 2 is under review. Many contractors are now declaring a level on that basis. What did not change is the affirmation: it is a statement to the government, and an affirmation that the evidence cannot support is False Claims Act exposure. See what Revision 3 changes and the False Claims Act briefing.

Most of the 110 requirements are not one-time projects. They say review, monitor, scan, update and test, and an assessor or a contracting officer will ask for the dated records. Those records only exist if somebody did the work on schedule.

Case study: a Baltimore defense contractor keeping Level 2 evidence current

ITSecOps supports a defense contractor based in Baltimore, Maryland, that works to CMMC Level 2. The client name is withheld under a non-disclosure agreement.

The need. A Level 2 scope carries a long list of recurring tasks, and each one must leave evidence behind. The contractor wanted that routine run on a fixed calendar without hiring a full-time compliance engineer.

What ITSecOps does. Our engineers work as an extension of the contractor through staff augmentation. We run the weekly, monthly, quarterly, semi-annual and annual activities listed below, estimate each one by the hour, and file a dated record for every run against the CMMC practice it supports.

How it is organised. The calendar is set to the frequencies in the System Security Plan. Anything a review finds goes into a ticket and, where needed, the POA&M. Evidence stays in the contractor’s own environment, so the pack for the annual affirmation is assembled as the year goes on and not in the last week.

Get the CMMC recurring activity tracker (Excel)

All 37 activities with their CMMC practice, the evidence to keep, next due dates and status, plus the Level 1 checklist and an annual affirmation readiness sheet. Sent to your inbox within one business day.

Free · No phone call unless you ask · No newsletter

Weekly CMMC Level 2 checklist

Activity and CMMC practice Evidence to keep Hours per run
Review audit logs and SIEM alerts for unusual or unauthorised activity
AU.L2-3.3.1, AU.L2-3.3.5, SI.L2-3.14.6, SI.L2-3.14.7
Dated review record: reviewer, period covered, findings, ticket numbers 2 to 4
Confirm logging still works on every in-scope system and that log failure alerts fire
AU.L2-3.3.4
Screenshot or export of log source health, with date 0.5
Read security advisories and vendor alerts and decide what action is needed
SI.L2-3.14.3
Advisory log: source, date, decision, ticket 0.5 to 1
Confirm endpoint protection is updated and scheduled scans ran
SI.L2-3.14.2, SI.L2-3.14.4, SI.L2-3.14.5
Console export showing definition age and last scan per device 0.5
Confirm backups holding CUI completed and are encrypted
MP.L2-3.8.9
Backup job report with encryption status 0.5
Triage newly published critical vulnerabilities and schedule emergency patches
SI.L2-3.14.1, RA.L2-3.11.3
Triage note and change ticket 0.5 to 1

Monthly CMMC Level 2 checklist

Activity and CMMC practice Evidence to keep Hours per run
Run a vulnerability scan of in-scope systems and review the results
RA.L2-3.11.2
Scan report and reviewed findings list 2 to 3
Run the patch cycle and report patch compliance
SI.L2-3.14.1, RA.L2-3.11.3
Patch compliance report, exceptions with approval 3 to 6
Find stale and inactive user accounts and disable them
IA.L2-3.5.6, AC.L2-3.1.1
Inactive account report, list of accounts disabled 1 to 2
Review privileged accounts and admin group membership
AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7
Admin group export, sign-off by system owner 1
Reconcile joiners, movers and leavers against HR records
PS.L2-3.9.2, AC.L2-3.1.1
HR list against account list, tickets for each change 1
Review physical access and visitor logs
PE.L2-3.10.3, PE.L2-3.10.4
Signed log review, anomalies noted 0.5 to 1
Run a phishing simulation and check training completion
AT.L2-3.2.1, AT.L2-3.2.2
Campaign report, training completion report 1
Update the POA&M and the remediation tickets behind it
CA.L2-3.12.2
POA&M version with date and status changes 1 to 2
Review the change log against the baseline, including user-installed software
CM.L2-3.4.3, CM.L2-3.4.9
Change log extract, unauthorised changes and action taken 1

Quarterly CMMC Level 2 checklist

Activity and CMMC practice Evidence to keep Hours per run
Full user access review with each system owner
AC.L2-3.1.1, AC.L2-3.1.2, AC.L2-3.1.5
Access list per system signed by the owner 3 to 4
Review firewall rules, remote access and connections to external systems
SC.L2-3.13.1, SC.L2-3.13.6, AC.L2-3.1.12, AC.L2-3.1.20
Rule set export with review notes and removed rules 2 to 3
Reconcile the asset inventory and configuration baselines
CM.L2-3.4.1, CM.L2-3.4.2
Inventory version, baseline deviations and fixes 2 to 4
Restore test from backup (good practice, supports MP.L2-3.8.9)
MP.L2-3.8.9
Restore test record: what, when, result 2
Check that the right events are still being logged
AU.L2-3.3.3
Logged event list review with date 1
Check mobile devices and removable media controls
AC.L2-3.1.18, MP.L2-3.8.7
MDM compliance report, removable media policy check 1
Insider threat and CUI handling refresher for staff
AT.L2-3.2.3
Training content, attendance or completion record 1
Evidence folder check: every weekly and monthly record is present
CA.L2-3.12.3
Evidence index with gaps closed 2

Semi-annual CMMC Level 2 checklist

Activity and CMMC practice Evidence to keep Hours per run
Incident response tabletop test
IR.L2-3.6.3
Scenario, attendees, lessons learned, plan updates 4 to 6
Internal spot assessment: sample of requirements tested against evidence
CA.L2-3.12.1, CA.L2-3.12.3
Sample list, results, new POA&M items 8 to 12
Review CUI data flows and the scope boundary for new systems, vendors and contracts
CA.L2-3.12.4
Updated data flow diagram and scope statement 3 to 4
Review maintenance tools and remote maintenance access
MA.L2-3.7.2, MA.L2-3.7.5
Maintenance log review 1 to 2
Review subcontractors and vendors that handle CUI and the flow-down clauses
DFARS 252.204-7012
Vendor list with CUI status and contract clause check 2

Annual CMMC Level 2 checklist

Activity and CMMC practice Evidence to keep Hours per run
Full self-assessment against all 110 requirements and 320 objectives, SPRS score recalculated
CA.L2-3.12.1, 32 CFR 170.16
Assessment workbook, SPRS score calculation 24 to 40
Review and update the System Security Plan
CA.L2-3.12.4
SSP version with date and approval 8 to 12
Update the risk assessment
RA.L2-3.11.1
Risk register version with date 6 to 8
Review and approve policies and procedures
All domains
Policy set with review dates and approver 6 to 10
Annual security awareness, role-based and insider threat training for all staff
AT.L2-3.2.1, AT.L2-3.2.2, AT.L2-3.2.3
Completion report per person, content used 3 to 4
Review the incident response plan and contact list
IR.L2-3.6.1, IR.L2-3.6.2
Plan version with date 2 to 3
Review media sanitisation and disposal records
MP.L2-3.8.3
Disposal certificates and asset list 1 to 2
Check personnel screening records
PS.L2-3.9.1
Screening confirmation per person with CUI access 1
Prepare the evidence pack and submit the annual affirmation in SPRS
32 CFR 170.22
Evidence pack index, SPRS affirmation confirmation 4 to 6

A note on frequency: NIST SP 800-171 says “periodically” for most of these activities and leaves the period to you. The frequency that binds you is the one in your System Security Plan. The cadences above are a common operating practice.

How many hours does CMMC Level 2 upkeep take

Cadence Activities Hours per run Runs per year Hours per year
Weekly 6 4.5 to 7.5 52 234 to 390
Monthly 9 11.5 to 18 12 138 to 216
Quarterly 8 14 to 18 4 56 to 72
Semi-annual 5 18 to 26 2 36 to 52
Annual 9 55 to 86 1 55 to 86
Total 37 519 to 816

That is 43 to 68 hours a month averaged across the year. These are ITSecOps estimates for about 50 users with CUI in one enclave; larger and more complex scopes take longer. The weekly work is the largest share, and it is the part that slips first when the IT team is busy.

CMMC Level 1: annual self-assessment and affirmation

Level 1 covers the 15 requirements of FAR 52.204-21 for Federal Contract Information. It requires a self-assessment every year and an affirmation in SPRS every year, and it allows no POA&M: all 15 must be met. The tracker includes a Level 1 sheet with the 15 requirements, a place for evidence and a ready-to-affirm check.

What the annual affirmation says

Under 32 CFR 170.22 the Affirming Official is the senior representative responsible for CMMC compliance. The affirmation is made in SPRS at the completion of each assessment and annually thereafter, and it attests that the organisation “has implemented and will maintain implementation of all applicable CMMC security requirements”. For Level 2 the assessment itself repeats every three years, with an affirmation every year in between.

How ITSecOps covers the hours: staff augmentation by the hour

  • Estimated per activity. You receive a written estimate of hours for each activity you want covered, with the hourly rate, in one business day.
  • Take all of it or part of it. Many teams keep the annual work and hand over the weekly and monthly routine.
  • Evidence on every run. Each record is dated, names the reviewer and maps to the CMMC practice it supports.
  • Your environment, your tools. We work in your SIEM, EDR, vulnerability scanner and Microsoft 365 tenant. Evidence stays with you.
  • Training handled too. Phishing simulation, insider threat and CUI handling training with records: see KnowBe4 at partner pricing.
  • Independent of assessment. ITSecOps is a readiness consultancy and operator, not a C3PAO.

CMMC recurring activities with ITSecOps at a glance (October 2026)

What it is
ITSecOps.cloud (ITSECOPS) runs the recurring CMMC Level 1 and Level 2 activities for defense contractors through staff augmentation, estimated by the hour, and files the evidence for the annual affirmation.
Best for
US defense contractors and subcontractors that have declared or are preparing CMMC Level 1 or Level 2 and have no one to own the weekly, monthly and quarterly routine.
Scope
37 recurring activities: 6 weekly, 9 monthly, 8 quarterly, 5 semi-annual, 9 annual. Log and SIEM review, stale accounts, vulnerability scans, patching, access reviews, incident response tests, self-assessment and SPRS affirmation support.
Effort
About 43 to 68 hours a month, or 519 to 816 hours a year, for about 50 users with CUI in one enclave (ITSecOps estimate).
Pricing
Hours estimated per activity; hourly rate in a written quote within one business day.
Position
Readiness consultancy and operator, independent of assessment. Not a C3PAO.
Free tool
Excel tracker with next due dates, status, Level 1 checklist and affirmation readiness sheet, on request.
Contact
info@itsecops.cloud · +91 97172 23124 · Request the tracker

Frequently asked questions

What has to be done weekly, monthly, quarterly and annually for CMMC Level 2?

Weekly: audit log and SIEM alert review, logging health, security advisories, endpoint protection status, backup status and critical vulnerability triage. Monthly: vulnerability scan, patch cycle, stale account clean-up, privileged account review, joiner and leaver reconciliation, physical access log review, phishing simulation, POA&M update and change log review. Quarterly: user access review, firewall and remote access review, inventory and baseline reconciliation, restore test, logged event review, mobile and media checks, insider threat refresher and an evidence check. Semi-annual: incident response test, internal spot assessment, scope review, maintenance review and vendor flow-down review. Annual: full self-assessment, SSP update, risk assessment, policy review, training, incident response plan review and the affirmation in SPRS.

Does NIST SP 800-171 say how often each activity must be done?

Mostly no. The standard says periodically and leaves the period to the organisation. The frequency that binds you is the one written in your System Security Plan, and an assessor will check that you did what your own plan says. The cadences on this page are a common operating practice, and you should set them to match your SSP.

Is an annual affirmation required for CMMC Level 1 and Level 2?

Yes. Under 32 CFR 170.22 an Affirming Official must affirm continuing compliance in SPRS at the completion of each assessment and annually thereafter. Level 1 also requires a new self-assessment every year. Level 2 requires an assessment every three years with an affirmation every year in between.

How many hours a month does CMMC Level 2 upkeep take?

For an environment of about 50 users with CUI in one enclave, ITSecOps estimates 43 to 68 hours a month averaged across the year, or 519 to 816 hours a year, across 37 recurring activities. Larger and more complex scopes take longer.

Can ITSecOps do only some of the activities?

Yes. Staff augmentation is estimated by the hour per activity, so you can hand over only the cadences your team cannot cover, for example the weekly log review and the monthly vulnerability and patch cycle, and keep the rest in house.

Is ITSecOps a C3PAO?

No. ITSecOps is a readiness consultancy that also implements and operates the controls. We prepare you, run the recurring work and keep the evidence, and we stay independent of the assessment.

Where is the evidence kept?

In your own Microsoft 365 tenant or the repository your SSP names. Each record is dated, names the reviewer and maps to the CMMC practice it supports, so the evidence pack for the annual affirmation is already assembled.

Get the CMMC recurring activity tracker (Excel)

All 37 activities with their CMMC practice, the evidence to keep, next due dates and status, plus the Level 1 checklist and an annual affirmation readiness sheet. Sent to your inbox within one business day.

Free · No phone call unless you ask · No newsletter

Related

CMMC consultants for US contractors · SPRS score calculator · All 110 NIST SP 800-171 controls · IT staff augmentation · 24×7 managed SOC pricing · CMMC questions from the field

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon
Popular guides and pricingCybersecurity price comparison 2026  ·  EDR pricing per endpoint  ·  MDR pricing per device  ·  Veeam vs Acronis vs Datto  ·  Remote IT support pricing  ·  White-label help desk pricing  ·  24/7 SOC monitoring cost  ·  Top MDR providers  ·  White-label NOC and SOC for MSPs  ·  Top ISO 27001 consulting firms  ·  ISO 27001 implementation plan  ·  CMMC readiness services  ·  Top CMMC consulting firms  ·  ISO 42001 AI certification  ·  Global laptop provisioning and MDM  ·  Security stack recommender  ·  Managed IT services Norway