Skip to content
CMMC Guidance
← Resource LibraryCMMCg-R006 | CMMC Policy & Procedure Matrix | v1.0 | August 2026
Stage 03 · Build

CMMC Policy & Procedure Matrix

Filled in by the compliance lead with whoever owns each document today, this matrix produces an honest map of your written program: for each of the 14 NIST SP 800-171 Rev 2 requirement families, whether a policy exists, whether a procedure exists, what the document is called, who owns it, when it was last reviewed and which requirements it supports. The gaps it exposes are usually not missing security; they are security nobody wrote down, which an assessor cannot credit.

How to use this resource
  1. 01

    Collect every document that claims to be a security policy, standard, procedure, plan or work instruction. Include the ones the managed service provider wrote and the ones nobody has opened since they were signed.

  2. 02

    For each family row, answer "Policy exists?" and "Procedure exists?" separately. A policy says what the organization requires; a procedure says how a person does it. One document can be both only if it actually contains both.

  3. 03

    Record the document name exactly as it appears on the file, the owner by name, and the last review date from the document itself, not from memory.

  4. 04

    In "Requirements supported", list the requirement identifiers the document actually addresses (for example AC.L2-3.1.1, AC.L2-3.1.2). If you cannot name any, the document is a gap, however long it is.

  5. 05

    Fill the Gap column with one of: none, missing, outdated, not followed, does not match the environment. Carry every gap into the CMMC Gap & POA&M Tracker (CMMCg-R007).

What is inside

2 working tables, 2 checklists, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.

  • Part 1 — Documents you hold
  • Document register
  • Part 2 — The matrix
  • Policy and procedure coverage by requirement family
  • Part 3 — Documents the program usually needs and often lacks
  • Tick only if the document exists, is current, and someone can find it in under 5 minutes
  • Part 4 — Review questions
  • Before you call the matrix complete
Recommended next steps
  • Enter every gap as a row in the CMMC Gap & POA&M Tracker (CMMCg-R007) with an owner and a target date.
  • Set a review cycle for every document in the register and record the next review date on the document itself.
  • When policies and procedures exist and are followed, collect the proof with the CMMC Evidence Collection Tracker (CMMCg-R008).
Downloadv1.0 · August 2026

Four fields, nothing else. We use them to see which documents get used and may follow up once by email. No automated sequence.

This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.

Filled it in and found gaps?

That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.

CMMC Policy & Procedure Matrix (CMMCg-R006) — CMMCg