Bulwark CMMC Lite Readiness Checklist

A quick self-assessment to gauge your cybersecurity maturity before full CMMC compliance.

Instructions: For each item, select Yes / Partial / No.

1. Do all users have unique IDs (no shared logins)?

2. Is Multi-Factor Authentication (MFA) required for email, VPN, and cloud access?

3. Are user accounts reviewed and updated at least quarterly?

4. Are accounts of terminated employees removed immediately?

5. Do you maintain an inventory of all laptops, servers, and mobile devices?

6. Are all company laptops and portable devices encrypted?

7. Do you have an inventory of all applications and cloud services in use?

8. Do you have a written incident response plan?

9. Has your team conducted an incident response drill in the past 12 months?

10. Do you have a documented data backup plan (with off-site or cloud backups)?

11. Is a firewall in place and actively monitored/updated?

12. Do all endpoints (laptops, servers) run updated antivirus/EDR software?

13. Is a secure VPN required for remote work?

14. Are background checks performed before granting access to systems?

15. Do employees receive annual cybersecurity awareness training?

16. Have you conducted phishing simulations or similar awareness tests in the past year?

17. Are server/network equipment areas physically secured (locked rooms/closets)?

18. Is the use of portable media (USB drives, external disks) restricted or encrypted?

19. Do you maintain a current written Information Security Policy?

20. Are cybersecurity roles and responsibilities formally assigned and documented?