{"product_id":"cmmc-level-2-policy-procedure-pack","title":"CMMC Level 2 Policy \u0026 Procedure Pack (14 Families)","description":"\u003cp\u003e\u003cstrong\u003eFourteen editable family policies that cover all 110 NIST SP 800-171 requirements, each statement mapped to its requirement ID.\u003c\/strong\u003e Short procedures and clear parameters, written so staff can actually follow them.\u003c\/p\u003e\u003ch2\u003eWhat you get\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003e14 family policies\u003c\/strong\u003e (Word, 62 pages in total): Access Control (22 requirements), Awareness and Training (3), Audit and Accountability (9), Configuration Management (9), Identification and Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System and Communications Protection (16), and System and Information Integrity (7).\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThe same structure in each\u003c\/strong\u003e: purpose, scope, definitions, roles, policy statements mapped to requirement IDs, short procedures, organization-defined parameters as [placeholders], records to keep and approval.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePolicy-to-Requirement Matrix\u003c\/strong\u003e (Excel): all 110 requirements mapped to a policy statement, with a coverage check and adoption tracker.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStart Here guide\u003c\/strong\u003e (PDF): steps and common mistakes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003cp\u003eAlso included in the \u003ca href=\"\/products\/cmmc-level-2-compliance-toolkit\"\u003eCMMC Level 2 Compliance Toolkit\u003c\/a\u003e.\u003c\/p\u003e\u003ch2\u003eHow to use it\u003c\/h2\u003e\u003col\u003e\n\u003cli\u003eDecide your organization-defined parameters, such as lockout attempts, session lock and log retention, listed in section 7 of each policy (2 to 3 hours).\u003c\/li\u003e\n\u003cli\u003eAdapt each policy: replace placeholders, change procedures to match how you work and delete guidance notes (1 to 2 hours per policy).\u003c\/li\u003e\n\u003cli\u003eHave the owner and senior official approve, communicate to staff and collect acknowledgments where needed.\u003c\/li\u003e\n\u003cli\u003eMark each requirement adopted in the matrix and reference the statements in your SSP.\u003c\/li\u003e\n\u003cli\u003eReview annually and after significant changes.\u003c\/li\u003e\n\u003c\/ol\u003e\u003ch2\u003eWho it is for\u003c\/h2\u003e\u003cp\u003eDefense suppliers and MSPs preparing for a NIST SP 800-171 or CMMC Level 2 self-assessment who need written policies behind every requirement. Policies alone do not meet requirements; assessors look for implementation and evidence, so pair them with an assessment and SSP.\u003c\/p\u003e\u003ch2\u003eGood to know\u003c\/h2\u003e\u003cul\u003e\n\u003cli\u003eInstant download. Editable Word (.docx) and Excel (.xlsx), plus a PDF guide. Works in Excel 2016 or later, Microsoft 365 and LibreOffice; no macros.\u003c\/li\u003e\n\u003cli\u003eLicensed for use within one organization.\u003c\/li\u003e\n\u003cli\u003eNIST SP 800-171\/171A and FAR requirement text is quoted verbatim (public domain). Check your contract and the current rules for what applies to you.\u003c\/li\u003e\n\u003cli\u003eThese templates help you prepare and document an honest self-assessment. They do not guarantee a particular SPRS score, a passing assessment or contract eligibility.\u003c\/li\u003e\n\u003cli\u003e5-day fit guarantee: if it does not fit your system, contact us within 5 days of purchase.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"ISO Cloud Consulting","offers":[{"title":"Default Title","offer_id":67603742851266,"sku":"ICC-CMMC-L2-POLICIES","price":129.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0709\/8361\/4658\/files\/cmmc-level-2-policy-procedure-pack.png?v=1790686360","url":"https:\/\/isocloudconsulting.com\/products\/cmmc-level-2-policy-procedure-pack","provider":"ISO Cloud Consulting","version":"1.0","type":"link"}