Practical tools for building and maintaining a defensible CMMC program.
Nine working documents, in the order an engagement uses them. Each one is a worksheet, tracker or checklist you fill in, not an article: they are the structure CMMCg brings to a Cybersecurity Maturity Model Certification (CMMC) engagement, published so you can start before anyone quotes you for anything.
They will not replace an engagement, and they are not meant to. What they should do is make one thing obvious by the time you have worked through two of them: CMMC involves considerably more than buying security products or completing a checklist. Every document carries a resource number and a version, so you can tell which edition you are holding.
Together the nine documents walk one path: Discover, Scope, Inventory, Assess, Document, Remediate, Collect Evidence, Validate, Prepare. The library groups that path into five stages so you can find the document for where you are.
- 01
Understand
Find out what Controlled Unclassified Information you actually hold and where it moves.
- 02
Scope
Draw the boundary around the people, systems and services that touch it, and defend every exclusion.
- 03
Build
Review the 110 requirements, write the policies and procedures, and track every gap to closure.
- 04
Prove
Collect the evidence for each practice and validate that it shows what it needs to show.
- 05
Prepare
Confirm scope, documents, evidence, people and systems are ready before the assessor arrives.
Understand
Find out what Controlled Unclassified Information you actually hold and where it moves.
CUI Identification Worksheet
Worksheet to list the information your organization receives, creates, processes or transmits that may constitute CUI, with origin, access, storage and marking.
Open →CUI Flow Mapping Template
Template to trace each CUI type from receipt through processing, storage, transmission, sharing and disposition, and mark where it leaves your boundary.
Open →
Scope
Draw the boundary around the people, systems and services that touch it, and defend every exclusion.
CMMC Scoping Worksheet
Worksheet to sort people, systems, endpoints, networks, cloud services, facilities and providers into CMMC asset categories, and defend every exclusion.
Open →CMMC Technology Inventory
Inventory of endpoints, servers, network, identity, cloud, security products, SaaS and external services with owner, location, scope status and CUI handling.
Open →
Build
Review the 110 requirements, write the policies and procedures, and track every gap to closure.
CMMC Level 2 Readiness Checklist
High-level readiness review across all 14 NIST SP 800-171 Rev 2 requirement families that CMMC Level 2 assesses, 3 to 5 review prompts per family.
Open →CMMC Policy & Procedure Matrix
Matrix to record, for each of the 14 requirement families, which policies and procedures exist, who owns them, when they were reviewed and what they support.
Open →CMMC Gap & POA&M Tracker
Register for every deficiency against NIST SP 800-171 Rev 2: remediation, owner, dependencies, target date, status and the evidence that closes it.
Open →
Prove
Collect the evidence for each practice and validate that it shows what it needs to show.
Prepare
Confirm scope, documents, evidence, people and systems are ready before the assessor arrives.
Find your industry first.
The industry pages show what Controlled Unclassified Information (CUI) tends to look like in your kind of organisation, where it travels, and which of these documents to open first. See the six industries →
Worked through two of these and want the real number?
The readiness call assesses your environment rather than your recollection of it. Bring the worksheets; an engineer runs the call.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.