Skip to product information
1 of 5

CMMC Level 2 Policy & Procedure Pack (14 Families)

CMMC Level 2 Policy & Procedure Pack (14 Families)

Regular price $129.00 USD
Regular price Sale price $129.00 USD
Sale Sold out

Instant download. Editable files. One-organization licence. 5-day fit guarantee.

Upgrade and save

The CMMC Level 2 Compliance Toolkit includes this pack plus the assessment workbook, SSP template, POA&M tracker, incident response, scoping and training templates. All 32 templates for $279 instead of $336 for the 4 main tools bought separately.

See the CMMC Level 2 Compliance Toolkit (32 Templates)

Not ready to buy? Get the free CMMC Level 1 self-assessment checklist

5-day fit guarantee. If it does not fit your CMMC program, ask for a refund within 5 days. Conditions.

Fourteen editable family policies that cover all 110 NIST SP 800-171 requirements, each statement mapped to its requirement ID. Short procedures and clear parameters, written so staff can actually follow them.

What you get

  1. 14 family policies (Word, 62 pages in total): Access Control (22 requirements), Awareness and Training (3), Audit and Accountability (9), Configuration Management (9), Identification and Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System and Communications Protection (16), and System and Information Integrity (7).
  2. The same structure in each: purpose, scope, definitions, roles, policy statements mapped to requirement IDs, short procedures, organization-defined parameters as [placeholders], records to keep and approval.
  3. Policy-to-Requirement Matrix (Excel): all 110 requirements mapped to a policy statement, with a coverage check and adoption tracker.
  4. Start Here guide (PDF): steps and common mistakes.

Also included in the CMMC Level 2 Compliance Toolkit.

How to use it

  1. Decide your organization-defined parameters, such as lockout attempts, session lock and log retention, listed in section 7 of each policy (2 to 3 hours).
  2. Adapt each policy: replace placeholders, change procedures to match how you work and delete guidance notes (1 to 2 hours per policy).
  3. Have the owner and senior official approve, communicate to staff and collect acknowledgments where needed.
  4. Mark each requirement adopted in the matrix and reference the statements in your SSP.
  5. Review annually and after significant changes.

Who it is for

Defense suppliers and MSPs preparing for a NIST SP 800-171 or CMMC Level 2 self-assessment who need written policies behind every requirement. Policies alone do not meet requirements; assessors look for implementation and evidence, so pair them with an assessment and SSP.

Good to know

  • Instant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.
  • Licensed for use within one organization.
  • NIST SP 800-171/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.
  • These templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.
  • 5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.
View full details

What every download includes

Instant downloadLink on the confirmation page and by email within minutes.
Fully editableWord (.docx), Excel (.xlsx) and PDF. No macros. Works in Microsoft 365 and Google Workspace.
5-day fit guaranteeIf the files do not fit your CMMC program, ask for a refund within 5 days. Conditions apply.
Free updatesRevised files for the NIST SP 800-171 revision that CMMC enforces are sent to you at no charge. One-organization licence.

Built from the official NIST SP 800-171 Rev 2 and SP 800-171A text (US Government works). Templates help you prepare for a self-assessment or an assessment; they do not guarantee a passing score, a contract award or legal compliance.

Questions about CMMC Level 2 Policy & Procedure Pack (14 Families)

Does CMMC Level 2 require written policies?

Assessors expect documented policies and procedures behind the requirements, and several requirements refer directly to defined parameters, procedures or plans. This pack gives you one policy per NIST SP 800-171 family, with every statement tagged to its requirement ID, so the link from requirement to written rule is easy to show.

What are organization-defined parameters?

They are values NIST leaves for you to decide, such as how many failed logins trigger a lockout, when sessions lock, or how long logs are kept. Section 7 of each policy lists them as [placeholders]. Decide them first, make sure they match your actual system settings, and use the same values in your SSP.

Can we adopt the policies unchanged?

You should not. Adopting policies unchanged, including placeholder values, is one of the most common mistakes. Each policy needs your names, tools and procedures. Policies that promise controls not yet in place create problems; record those gaps on your POA&M instead and keep the policy truthful.

How do the policies connect to the SSP?

The matrix maps every requirement to a policy statement. In your System Security Plan, each requirement's implementation statement can reference the relevant policy section, then describe the tools and settings that put it into practice. The CMMC Level 2 Compliance Toolkit includes the SSP template alongside this pack.

How will I receive the files?

A download button appears on the order confirmation page and the same link is emailed to you within a few minutes. Bundles arrive as one ZIP file.

Can I get a refund?

Yes. With our 5-day fit guarantee, if the files do not fit your CMMC compliance program you can ask for a full refund within 5 days of your order. It applies once per customer and organization, covers the whole product, and requires you to confirm you have deleted the files. We also refund non-delivery, defective files, wrong items and duplicate purchases within 30 days. Read the full refund policy.

Can I see the files before I buy?

Yes. The images above show real pages from the files, and the free CMMC Level 1 self-assessment checklist lets you check where you stand before you buy.

Can I use the templates with more than one company?

Each purchase is licensed to one organization. Consultants and groups need one licence per client or legal entity. See the licence agreement.

Templates that work with this one

Useful next steps for a CMMC and NIST SP 800-171 self-assessment.