A CMMC compliance tracker is not a to-do list. It is the record you hand an assessor, or read back to yourself at affirmation time, and for every one of the 110 NIST SP 800-171 Revision 2 requirements it has to answer three questions: what is the status, what evidence proves it, and who decided that and when. Most trackers answer only the first one. That is why they fall apart in the week the assessment actually starts.

The status question has a fixed answer set, and this is the part people get wrong. Under 32 CFR 170.24, every requirement resolves to one of three findings: MET, NOT MET, or Not Applicable. There is no "in progress" in the rule. If your tracker has status values the scoring methodology does not recognize, you are storing an opinion rather than a score.

The three findings, verbatim from the rule. MET means all applicable objectives are satisfied based on evidence, and that evidence must be in final form: working papers, drafts and unapproved policies are explicitly unacceptable. NOT MET means one or more objectives is not satisfied. Not Applicable means the requirement does not apply to your scope, and for scoring purposes N/A counts the same as MET.

What a CMMC compliance tracker has to hold

Eight columns. Fewer than this and you will rebuild the missing ones by hand under time pressure, which is the expensive way to find out they were load bearing.

ColumnWhat goes in itWhy it earns its place
RequirementThe 800-171 number (3.1.1) and the CMMC practice ID (AC.L2-3.1.1)Primes ask in CMMC IDs, NIST documents use the other. You need both to answer either.
StatusMET, NOT MET, or N/A. Nothing else.These are the only findings the scoring methodology accepts.
Point value5, 3 or 1It is what a NOT MET costs you. Without it you cannot see your score move.
Objective coverageWhich 800-171A objectives you checked, by letterA requirement is MET only when every objective under it is satisfied.
EvidenceThe artifact name and where it lives, in final formDrafts do not count. A status with no evidence is a guess.
OwnerA person, not a departmentAt affirmation time somebody has to stand behind the entry.
Date decidedWhen the status was set, and when it was last reviewedA status set 14 months ago against a network that has since changed is not a status.
DeferrableYes or no, per the rule belowSix requirements can never go on a plan of action. Flag them before you plan around them.

The point value column, and why partial credit is a trap

Under 32 CFR 170.24 the maximum Level 2 score equals the total number of requirements, and each NOT MET subtracts that requirement's value from the maximum. The values are 5, 3 or 1, set by how badly an unimplemented requirement could lead to exploitation of the network or exfiltration of CUI. Because deductions are not floored at zero, the score can go negative, and for a shop that has not started, it usually does. The arithmetic is in our walkthrough on calculating your SPRS score, and the free SPRS calculator will run the numbers without a signup.

The rule says the methodology "is designed to credit partial implementation only in limited cases," and it names multifactor authentication (IA.L2-3.5.3) as the example. So a tracker column called "percent complete" is not measuring anything the score recognizes. Ninety percent of a requirement is NOT MET, and it costs the full five points. Track the work somewhere if it helps you manage it, but keep it out of the status column.

The evidence column decides the assessment

This is where trackers quietly fail. A row that says MET with an evidence cell reading "in Group Policy" is not evidence, it is a memory. The fix is boring: name the artifact, say where it lives, and note the date it was produced. A screenshot of the MFA enforcement policy exported 2026-09-18 and filed in the evidence folder is a different thing from a person's recollection that MFA is on.

Two rules from the text are worth pinning above the tracker. First, evidence has to be final. Working papers, drafts and unofficial or unapproved policies are called out by name as unacceptable, so a policy that has been written but never signed does not carry a requirement. Second, the finding is per objective, not per requirement. Requirement 3.1.1 breaks into several assessment objectives, and missing one makes the whole requirement NOT MET. We worked two of these end to end in the post on 800-171A assessment objectives.

There is one piece of relief in the rule that small shops rarely use. An enduring exception, something you genuinely cannot implement, is assessed as MET if it is described in the system security plan along with its mitigations. So is a temporary deficiency that is tracked in an operational plan of action with deficiency reviews showing progress. Both of those live in documents, not in a tracker cell, which is a good argument for having the tracker point at the system security plan rather than trying to be it.

The six requirements your tracker must flag as not deferrable

Most people learn this rule too late, after they have built a plan around deferring something that cannot be deferred. 32 CFR 170.21 sets three conditions for a Conditional Level 2 status, and your tracker should be able to test all three in one look.

The 180-day clock. A Conditional status is not a resting place. The rule requires a closeout assessment confirming the plan of action is closed within 180 days of the Conditional CMMC Status Date, and if it is not, the Conditional status for that system expires. A tracker with no date column cannot warn you about that.

What goes in the plan itself, and how the rows are written, is covered in our POA&M template post. The tracker and the plan are different documents: the tracker holds all 110 rows, the plan holds only the NOT MET ones you are allowed to defer.

Level 1 tracking works differently

If you handle Federal Contract Information but not CUI, you are tracking the 15 basic safeguarding requirements in FAR 52.204-21, which CMMC counts as 17 practices. There is no scoring and no partial anything: the rule states that all Level 1 requirements must be fully implemented to be MET, and results are scored as MET or NOT MET in their entirety. No plan of action is permitted at any time for a Level 1 self-assessment, so a Level 1 tracker is a pass or fail list with an evidence column. Our free Level 1 checklist is that list, and if you are not sure which level you are on, start with whether you actually handle CUI.

When the spreadsheet stops paying for itself

A spreadsheet is a reasonable place to start and a bad place to finish. It holds status fine. What it cannot do is keep the evidence next to the row, show you which objective is missing, recalculate the score when someone edits a cell, or turn 110 rows into a system security plan and a plan of action that match each other. We went through those failure modes in detail in why your CMMC spreadsheet will fail you. The short version: the spreadsheet stops paying for itself the day two people edit it, because from then on nobody can tell which version the affirmation was based on.

That is the gap CMMC Map, CMMC compliance software for small defense contractors, was built to close. The assessment is free forever and covers all 110 requirements with the DoD point weights, a live score and a gap list. The documents that have to agree with the tracker, the system security plan, the plan of action and the policies, are the one paid plan at $149 a month.

Set up your tracker this week

  1. Monday. Create the eight columns. If you already have a tracker, add the ones it is missing rather than starting over, usually objective coverage, date decided and deferrable.
  2. Tuesday. Fill the point value column from the scoring methodology, then sort by it. Your 5-pointers are the whole game.
  3. Wednesday. Flag the six non-deferrable requirements and SC.L2-3.13.11 so nobody plans around them by accident.
  4. Thursday. Walk the rows marked MET and make each evidence cell name a real, final artifact. Anything that cannot be named goes back to NOT MET. Expect this to hurt.
  5. Friday. Put an owner and a date on every row, then check your ratio. If it is under 0.8, you now know which rows to work, in value order.

None of this is legal advice, and your contract clauses govern. But a tracker built this way answers the questions an assessor asks in the order they ask them, which is most of what a good assessment day is.

Let the tracker keep itself

The free CMMC Map assessment holds all 110 requirements with the DoD point weights, the status, the evidence note and the date, and recalculates your score as you go. No credit card.

Start free in CMMC Map
Free to assess · Documents $149/mo · No credit card