{"product_id":"cmmc-level-2-compliance-toolkit","title":"CMMC Level 2 Compliance Toolkit (32 Templates)","description":"\u003cp\u003e\u003cstrong\u003eEverything for a defensible NIST SP 800-171 \/ CMMC Level 2 self-assessment and SPRS score, and for keeping it true afterward: 33 files and a 90-day path.\u003c\/strong\u003e The four Level 2 products cost $336 separately; the toolkit is $279, a saving of $57, and adds four folders sold only here.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-level-2-nist-800-171-assessment-workbook\"\u003eLevel 2 Assessment Workbook\u003c\/a\u003e\u003c\/strong\u003e (folder 01): 110 requirements, 320 objectives and SPRS calculator.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/nist-800-171-system-security-plan-ssp-template\"\u003eSystem Security Plan Template\u003c\/a\u003e\u003c\/strong\u003e (folder 02): 81-page SSP and implementation tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-poam-template\"\u003ePOA\u0026amp;M Template \u0026amp; Tracker\u003c\/a\u003e\u003c\/strong\u003e (folder 03): register with eligibility checks and a how-to guide.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003e\u003ca href=\"\/products\/cmmc-level-2-policy-procedure-pack\"\u003eLevel 2 Policy \u0026amp; Procedure Pack\u003c\/a\u003e\u003c\/strong\u003e (folder 04): 14 family policies and the requirement matrix.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIncident Response\u003c\/strong\u003e (Word, folder 05): a plan built around DFARS 252.204-7012 72-hour reporting, an incident report worksheet, and a 90-minute tabletop exercise with three scenarios.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eScoping and Assets\u003c\/strong\u003e (Excel, folder 06): CUI scoping and data flow workbook with enclave decision, asset inventory, and an external service provider shared responsibility matrix for all 110 requirements.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTraining\u003c\/strong\u003e (folder 07): a 22-slide CUI and security awareness deck with speaker notes, a 15-question quiz and a training record.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOngoing Compliance\u003c\/strong\u003e (folder 08): a 12-month calendar of 25 recurring activities, a Level 2 SPRS score and affirmation guide, and a senior official affirmation template.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): file map, which file answers which family, and the 90-day path.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eYour first 90 days\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 1 to 15, scope:\u003c\/strong\u003e categorize assets, decide enclave or whole company, build the inventory and shared responsibility matrix, complete SSP sections 1 to 3.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 16 to 40, assess:\u003c\/strong\u003e self-assess all 320 objectives, record gaps on the POA\u0026amp;M, fix blocking items first, set your parameters.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 41 to 70, policies and readiness:\u003c\/strong\u003e approve the 14 policies, deliver training, adopt the incident plan and run the tabletop.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDays 71 to 90, score and affirm:\u003c\/strong\u003e finish the SSP, re-test, recalculate, complete the affirmation record, enter the score in SPRS and start the calendar.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers of roughly 5 to 150 staff and their MSPs. Written for owners, office managers and IT generalists. Technical fixes such as MFA everywhere or FIPS-validated encryption can take longer than 90 days; the POA\u0026amp;M exists for that, within its rules.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx), Excel (.xlsx) and PowerPoint (.pptx), plus PDF. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603743047874,"sku":"ICC-CMMC-L2-TOOLKIT","price":279.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-compliance-toolkit.png?v=1790686406","url":"https:\/\/isocloudconsulting.com\/products\/cmmc-level-2-compliance-toolkit","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}