{"title":"CMMC and NIST 800-171 Templates","description":"\u003cp\u003eCMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense program that checks whether contractors protect Federal Contract Information and Controlled Unclassified Information (CUI), using the 15 FAR 52.204-21 safeguards for Level 1 and the 110 NIST SP 800-171 requirements for Level 2.\u003c\/p\u003e\u003cp\u003eThese editable Excel and Word templates are for small and mid-sized defense suppliers and the MSPs who support them. Start with the \u003ca href=\"\/products\/free-cmmc-level-1-self-assessment-checklist\"\u003efree CMMC Level 1 self-assessment checklist\u003c\/a\u003e. If you handle CUI, begin with the \u003ca href=\"\/products\/cmmc-level-2-nist-800-171-assessment-workbook\"\u003eLevel 2 assessment workbook and SPRS calculator\u003c\/a\u003e, get the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eStarter Bundle\u003c\/a\u003e with the SSP and POA\u0026amp;M, or the complete \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eLevel 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003cp\u003eNew to CMMC? Read our \u003ca href=\"\/pages\/cmmc\"\u003eCMMC guide\u003c\/a\u003e.\u003c\/p\u003e","products":[{"product_id":"free-cmmc-level-1-self-assessment-checklist","title":"Free CMMC Level 1 Self-Assessment Checklist","description":"\u003cp\u003e\u003cstrong\u003eA 15-minute check of your company against the 15 CMMC Level 1 requirements, in plain English, before you affirm in SPRS.\u003c\/strong\u003e One question per requirement, with a next step for every gap.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eLevel 1 Checklist\u003c\/strong\u003e (Excel): 15 questions, one per FAR 52.204-21 safeguarding requirement, each labeled with its CMMC ID, with Yes \/ Partly \/ No answers and scoring.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePrintable checklist\u003c\/strong\u003e (PDF, 2 pages): the same questions, a plain-English explanation of FCI, scoring bands and a do-this-next table.\u003c\/li\u003e\n\u003c\/ul\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eAnswer each question with whoever manages your computers, accounts and office access.\u003c\/li\u003e\n\u003cli\u003eCount your Yes answers. Level 1 has no partial credit: all 15 must be met.\u003c\/li\u003e\n\u003cli\u003eFix each Partly or No using the next-step table, then run the formal self-assessment against the 59 assessment objectives.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWant the full system?\u003c\/h2\u003e\u003cp\u003eThe \u003ca href=\"\/products\/cmmc-level-1-self-assessment-kit\"\u003eCMMC Level 1 Self-Assessment Kit\u003c\/a\u003e ($79) has the 59-objective workbook, a ready-to-adopt policy, records pack and SPRS affirmation guide. If you also handle CUI, you need all 110 NIST SP 800-171 requirements: see the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eCMMC Level 2 Starter Bundle\u003c\/a\u003e ($175).\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eFree instant download. Excel (.xlsx) and PDF; no macros.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eA quick readiness check, not the formal self-assessment. It cannot promise a score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742261442,"sku":"ICC-FREE-CMMC-L1-CHECK","price":0.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/free-cmmc-level-1-self-assessment-checklist.png?v=1790686238"},{"product_id":"cmmc-level-1-self-assessment-kit","title":"CMMC Level 1 Self-Assessment Kit","description":"\u003cp\u003e\u003cstrong\u003eEverything a small defense supplier needs to complete, document and affirm a CMMC Level 1 self-assessment honestly.\u003c\/strong\u003e Written for owners and office managers, not security specialists.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eLevel 1 Self-Assessment Workbook\u003c\/strong\u003e (Excel): the 15 FAR 52.204-21 requirements quoted verbatim with plain-English explanations and typical evidence, all 59 assessment objectives with MET \/ NOT MET \/ N\/A dropdowns, an automatic result, an SPRS worksheet, an annual affirmation checklist and a dashboard.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLevel 1 Security Policy and Procedures\u003c\/strong\u003e (Word, 7 pages): one consolidated small-business policy covering all 15 requirements, with simple procedures, roles, records and a requirement cross-reference.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFCI Scoping and Asset Inventory\u003c\/strong\u003e (Excel): where FCI lives, in-scope people, technology and facilities, external systems and network boundary notes.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLevel 1 Records Pack\u003c\/strong\u003e (Excel): visitor log, access device register, media sanitization record, user account register with quarterly review, patch log and malware scan log.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSPRS Submission and Affirmation Guide\u003c\/strong\u003e (PDF, 2 pages): plain-English steps for entering your result and affirming.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAffirmation Memo Template\u003c\/strong\u003e (Word, 2 pages): an internal record of what your affirming official reviewed.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): where things stand in 2026, steps and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eComplete the scoping workbook (2 to 4 hours).\u003c\/li\u003e\n\u003cli\u003eAdopt the policy: fill placeholders, approve it and have staff sign (2 to 3 hours).\u003c\/li\u003e\n\u003cli\u003eStart the records pack now so you build real history.\u003c\/li\u003e\n\u003cli\u003eSelf-assess every objective and fix anything NOT MET.\u003c\/li\u003e\n\u003cli\u003eComplete the SPRS worksheet and memo, then enter the result and affirm using the guide. Repeat every year.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eSmall defense suppliers (roughly 5 to 150 staff) whose contracts include FAR 52.204-21 or require CMMC Level 1, and the MSPs who support them. If you also handle CUI, Level 1 is not enough; you need the 110 NIST SP 800-171 requirements covered by our Level 2 products.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Excel (.xlsx) and Word (.docx), plus PDF guides. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742326978,"sku":"ICC-CMMC-L1-KIT","price":79.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-1-self-assessment-kit.png?v=1790686265"},{"product_id":"cmmc-level-2-nist-800-171-assessment-workbook","title":"CMMC Level 2 \/ NIST 800-171 Assessment Workbook with SPRS Calculator","description":"\u003cp\u003e\u003cstrong\u003eAssess all 110 NIST SP 800-171 requirements and 320 assessment objectives, and calculate your SPRS score, in one Excel workbook.\u003c\/strong\u003e Tested by filling every objective: all MET gives 110 and all NOT MET gives the methodology minimum of -203.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eRequirements sheet\u003c\/strong\u003e (Excel): all 110 requirements with verbatim NIST text, plain-English explanations, typical evidence, DoD point values and POA\u0026amp;M eligibility.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eObjectives sheet\u003c\/strong\u003e (Excel): all 320 assessment objectives from SP 800-171A, quoted verbatim, with MET \/ NOT MET \/ N\/A dropdowns and evidence notes.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAssessment Methods sheet\u003c\/strong\u003e (Excel): what an assessor would examine, who they would interview and what they would test, for each requirement.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSPRS Score calculator\u003c\/strong\u003e (Excel): DoD Assessment Methodology scoring with partial credit for 3.5.3 and 3.13.11, a worst-case score for unassessed items and an SSP check.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eConditional Status check and Dashboard\u003c\/strong\u003e (Excel): whether you meet the 88-point threshold with only eligible items open, and results by family.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps, what good looks like and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eCMMC Level 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eDefine your scope (enclave or whole company) and have your SSP to hand (1 to 2 hours).\u003c\/li\u003e\n\u003cli\u003eWork through the objectives family by family, recording evidence for every MET (2 to 4 days over 2 to 3 weeks).\u003c\/li\u003e\n\u003cli\u003eAnswer the two partial-credit questions on the SPRS sheet.\u003c\/li\u003e\n\u003cli\u003eReview the score, Conditional status and dashboard, and list blocking items.\u003c\/li\u003e\n\u003cli\u003ePut NOT MET items on your POA\u0026amp;M, update the SSP, then enter the score in SPRS.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers that handle CUI and need a NIST SP 800-171 self-assessment and SPRS score, and the MSPs who run assessments for them. CUI is sensitive but unclassified government information, such as export-controlled drawings, that your contract requires you to protect.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Excel (.xlsx) plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742523586,"sku":"ICC-CMMC-L2-WORKBOOK","price":79.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-nist-800-171-assessment-workbook.png?v=1790686287"},{"product_id":"nist-800-171-system-security-plan-ssp-template","title":"NIST 800-171 System Security Plan (SSP) Template","description":"\u003cp\u003e\u003cstrong\u003eA complete System Security Plan template for NIST SP 800-171 and CMMC Level 2, with an example statement for every requirement.\u003c\/strong\u003e An SSP is required by requirement 3.12.4; without one, your self-assessment cannot be scored.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eSystem Security Plan Template\u003c\/strong\u003e (Word, 81 pages): system identification, scope and boundary using the CMMC asset categories, environment, network and data flow diagrams, external providers and shared responsibility, roles, and all 110 requirements with verbatim NIST text, their 320 assessment objectives, status boxes and a fictional example implementation statement for each. Appendices include a change log.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSSP Implementation Tracker\u003c\/strong\u003e (Excel): a 110-row tracker for drafting, review and approval of each statement, with owners, target dates and a dashboard by family.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps, what good looks like and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eCMMC Level 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eComplete sections 1 to 3 (identification, scope and boundary, roles) and draw the diagrams (1 to 3 days).\u003c\/li\u003e\n\u003cli\u003eAssign an owner and target date to each requirement in the tracker (1 hour).\u003c\/li\u003e\n\u003cli\u003eDraft section 4 family by family, starting with Access Control, Identification and Authentication, and System and Communications Protection. Replace every blue example with your own statement (3 to 6 weeks part time).\u003c\/li\u003e\n\u003cli\u003eReview each statement against its objectives and evidence, and record gaps on your POA\u0026amp;M.\u003c\/li\u003e\n\u003cli\u003eApprove the SSP, use it for your self-assessment and SPRS entry, and review it annually.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eSmall and mid-sized defense suppliers that handle CUI (Controlled Unclassified Information) and need an SSP for a NIST SP 800-171 or CMMC Level 2 self-assessment, and the MSPs who write SSPs for them.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742654658,"sku":"ICC-CMMC-SSP","price":99.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/nist-800-171-system-security-plan-ssp-template.png?v=1790686313"},{"product_id":"cmmc-poam-template","title":"CMMC POA\u0026M Template \u0026 Tracker","description":"\u003cp\u003e\u003cstrong\u003ePlan and track fixes for every NIST SP 800-171 gap, with the CMMC eligibility rules and 180-day deadline built in.\u003c\/strong\u003e A POA\u0026amp;M (Plan of Action and Milestones) is simply the list of requirements you do not yet fully meet, with the fix, owner and dates.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003ePOA\u0026amp;M Register\u003c\/strong\u003e (Excel): pick a requirement ID and the requirement text, point value and eligibility fill in automatically. Each item has three milestones, an owner, resources, a 180-day deadline from your Conditional status date, and warnings for ineligible items. Includes 5 fictional example rows to delete.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDashboard\u003c\/strong\u003e (Excel): items by status, points at risk, items past the 180-day deadline or due within 30 days, and ineligible items that must be cleared.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReference sheet\u003c\/strong\u003e (Excel): all 110 requirements with points and POA\u0026amp;M eligibility.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eHow to Write a Good POA\u0026amp;M Item\u003c\/strong\u003e (Word, 3 pages): a short practical guide with weak versus strong examples.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps, what good looks like and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-starter-bundle\"\u003eCMMC Level 2 Starter Bundle\u003c\/a\u003e and the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eRead the Instructions sheet and the guide (20 minutes).\u003c\/li\u003e\n\u003cli\u003eEnter your Conditional status date and delete the example rows.\u003c\/li\u003e\n\u003cli\u003eAdd one row per NOT MET requirement from your assessment and check the eligibility column (1 to 3 hours).\u003c\/li\u003e\n\u003cli\u003ePlan milestones, owners and resources.\u003c\/li\u003e\n\u003cli\u003eReview monthly; close items with evidence verified by a second person, and update your SSP and SPRS score.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers and MSPs managing gaps from a NIST SP 800-171 or CMMC Level 2 self-assessment who want a POA\u0026amp;M that is specific, dated and within the rules.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Excel (.xlsx) and Word (.docx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742752962,"sku":"ICC-CMMC-POAM","price":29.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-poam-template.png?v=1790686333"},{"product_id":"cmmc-level-2-policy-procedure-pack","title":"CMMC Level 2 Policy \u0026 Procedure Pack (14 Families)","description":"\u003cp\u003e\u003cstrong\u003eFourteen editable family policies that cover all 110 NIST SP 800-171 requirements, each statement mapped to its requirement ID.\u003c\/strong\u003e Short procedures and clear parameters, written so staff can actually follow them.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e14 family policies\u003c\/strong\u003e (Word, 62 pages in total): Access Control (22 requirements), Awareness and Training (3), Audit and Accountability (9), Configuration Management (9), Identification and Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System and Communications Protection (16), and System and Information Integrity (7).\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThe same structure in each\u003c\/strong\u003e: purpose, scope, definitions, roles, policy statements mapped to requirement IDs, short procedures, organization-defined parameters as [placeholders], records to keep and approval.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePolicy-to-Requirement Matrix\u003c\/strong\u003e (Excel): all 110 requirements mapped to a policy statement, with a coverage check and adoption tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eDecide your organization-defined parameters, such as lockout attempts, session lock and log retention, listed in section 7 of each policy (2 to 3 hours).\u003c\/li\u003e\n\u003cli\u003eAdapt each policy: replace placeholders, change procedures to match how you work and delete guidance notes (1 to 2 hours per policy).\u003c\/li\u003e\n\u003cli\u003eHave the owner and senior official approve, communicate to staff and collect acknowledgments where needed.\u003c\/li\u003e\n\u003cli\u003eMark each requirement adopted in the matrix and reference the statements in your SSP.\u003c\/li\u003e\n\u003cli\u003eReview annually and after significant changes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers and MSPs preparing for a NIST SP 800-171 or CMMC Level 2 self-assessment who need written policies behind every requirement. Policies alone do not meet requirements; assessors look for implementation and evidence, so pair them with an assessment and SSP.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742851266,"sku":"ICC-CMMC-L2-POLICIES","price":129.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-policy-procedure-pack.png?v=1790686360"},{"product_id":"cmmc-level-2-starter-bundle","title":"CMMC Level 2 Starter Bundle (Workbook, SSP, POA\u0026M)","description":"\u003cp\u003e\u003cstrong\u003eThe three documents at the center of a defensible CMMC Level 2 self-assessment: the assessment workbook, the System Security Plan and the POA\u0026amp;M.\u003c\/strong\u003e Bought separately these cost $207; the bundle is $175, a saving of $32.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-level-2-nist-800-171-assessment-workbook\"\u003eCMMC Level 2 \/ NIST 800-171 Assessment Workbook\u003c\/a\u003e\u003c\/strong\u003e (Excel, $79 on its own): 110 requirements, 320 objectives, SPRS score calculator and Conditional status check.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/nist-800-171-system-security-plan-ssp-template\"\u003eNIST 800-171 System Security Plan Template\u003c\/a\u003e\u003c\/strong\u003e (Word and Excel, $99 on its own): an 81-page SSP with verbatim requirement text and example statements, plus a 110-row implementation tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-poam-template\"\u003eCMMC POA\u0026amp;M Template \u0026amp; Tracker\u003c\/a\u003e\u003c\/strong\u003e (Excel and Word, $29 on its own): a register with eligibility checks and 180-day deadlines, plus a guide to writing good items.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBundle Start Here guide\u003c\/strong\u003e (PDF): how the files connect and a 4-week plan.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 4 weeks\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 1, scope and baseline:\u003c\/strong\u003e decide enclave or whole company, list the people, systems and locations that touch CUI, draw the diagrams, and set owners and dates in the SSP tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 2, assess:\u003c\/strong\u003e work through the objectives family by family with the people who run each area and your MSP, recording evidence as you go. Anything without evidence is NOT MET.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 3, write the SSP:\u003c\/strong\u003e draft section 4 from what you learned, replacing every example with your own statement and ticking status honestly.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWeek 4, plan, score and decide:\u003c\/strong\u003e put every NOT MET requirement on the POA\u0026amp;M, check eligibility, review the score and Conditional status, and have the senior official review everything before anything goes into SPRS.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eFour weeks is realistic for a small company with an engaged owner and a responsive MSP. Fixing gaps usually takes longer than documenting them.\u003c\/p\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers of roughly 5 to 150 staff that handle CUI and need a defensible NIST SP 800-171 self-assessment and SPRS score, and the MSPs who support them. No security specialist needed.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Excel (.xlsx) and Word (.docx), plus PDF guides. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742949570,"sku":"ICC-CMMC-L2-STARTER","price":175.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-starter-bundle.png?v=1790686381"},{"product_id":"cmmc-level-2-compliance-toolkit","title":"CMMC Level 2 Compliance Toolkit (32 Templates)","description":"\u003cp\u003e\u003cstrong\u003eEverything for a defensible NIST SP 800-171 \/ CMMC Level 2 self-assessment and SPRS score, and for keeping it true afterward: 33 files and a 90-day path.\u003c\/strong\u003e The four Level 2 products cost $336 separately; the toolkit is $279, a saving of $57, and adds four folders sold only here.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-level-2-nist-800-171-assessment-workbook\"\u003eLevel 2 Assessment Workbook\u003c\/a\u003e\u003c\/strong\u003e (folder 01): 110 requirements, 320 objectives and SPRS calculator.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/nist-800-171-system-security-plan-ssp-template\"\u003eSystem Security Plan Template\u003c\/a\u003e\u003c\/strong\u003e (folder 02): 81-page SSP and implementation tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-poam-template\"\u003ePOA\u0026amp;M Template \u0026amp; Tracker\u003c\/a\u003e\u003c\/strong\u003e (folder 03): register with eligibility checks and a how-to guide.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-level-2-policy-procedure-pack\"\u003eLevel 2 Policy \u0026amp; Procedure Pack\u003c\/a\u003e\u003c\/strong\u003e (folder 04): 14 family policies and the requirement matrix.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIncident Response\u003c\/strong\u003e (Word, folder 05): a plan built around DFARS 252.204-7012 72-hour reporting, an incident report worksheet, and a 90-minute tabletop exercise with three scenarios.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eScoping and Assets\u003c\/strong\u003e (Excel, folder 06): CUI scoping and data flow workbook with enclave decision, asset inventory, and an external service provider shared responsibility matrix for all 110 requirements.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTraining\u003c\/strong\u003e (folder 07): a 22-slide CUI and security awareness deck with speaker notes, a 15-question quiz and a training record.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOngoing Compliance\u003c\/strong\u003e (folder 08): a 12-month calendar of 25 recurring activities, a Level 2 SPRS score and affirmation guide, and a senior official affirmation template.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): file map, which file answers which family, and the 90-day path.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 90 days\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 1 to 15, scope:\u003c\/strong\u003e categorize assets, decide enclave or whole company, build the inventory and shared responsibility matrix, complete SSP sections 1 to 3.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 16 to 40, assess:\u003c\/strong\u003e self-assess all 320 objectives, record gaps on the POA\u0026amp;M, fix blocking items first, set your parameters.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 41 to 70, policies and readiness:\u003c\/strong\u003e approve the 14 policies, deliver training, adopt the incident plan and run the tabletop.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 71 to 90, score and affirm:\u003c\/strong\u003e finish the SSP, re-test, recalculate, complete the affirmation record, enter the score in SPRS and start the calendar.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers of roughly 5 to 150 staff and their MSPs. Written for owners, office managers and IT generalists. Technical fixes such as MFA everywhere or FIPS-validated encryption can take longer than 90 days; the POA\u0026amp;M exists for that, within its rules.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx), Excel (.xlsx) and PowerPoint (.pptx), plus PDF. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603743047874,"sku":"ICC-CMMC-L2-TOOLKIT","price":279.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-compliance-toolkit.png?v=1790686406"}],"url":"https:\/\/isocloudconsulting.com\/collections\/cmmc-templates.oembed","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}