Free CMMC templates.
Starting-point templates for NIST 800-171 and CMMC Level 2: an SSP, a POA&M, and a policy template for every control family. No form, no email. Download them, tailor them to your environment, and talk to us when you want them assessment-ready.
16 free templates: an SSP, a POA&M, and a policy template for every NIST 800-171 family.
- Word .docx
System Security Plan (SSP)
A Level 2 SSP shell across the 14 NIST 800-171 families, with a fillable status / responsibility / implementation row for each of the 110 requirements.
Download - Excel .xlsx
Plan of Action & Milestones (POA&M)
A POA&M workbook with the columns an assessor expects (requirement, weakness, remediation, resources, milestones, dates, status), plus an instructions sheet and a worked example.
Download - Word .docx
Access Control Policy
Policy template for the 22 Access Control requirements (3.1).
Download - Word .docx
Awareness and Training Policy
Policy template for the 3 Awareness and Training requirements (3.2).
Download - Word .docx
Audit and Accountability Policy
Policy template for the 9 Audit and Accountability requirements (3.3).
Download - Word .docx
Configuration Management Policy
Policy template for the 9 Configuration Management requirements (3.4).
Download - Word .docx
Identification and Authentication Policy
Policy template for the 11 Identification and Authentication requirements (3.5).
Download - Word .docx
Incident Response Policy
Policy template for the 3 Incident Response requirements (3.6).
Download - Word .docx
Maintenance Policy
Policy template for the 6 Maintenance requirements (3.7).
Download - Word .docx
Media Protection Policy
Policy template for the 9 Media Protection requirements (3.8).
Download - Word .docx
Personnel Security Policy
Policy template for the 2 Personnel Security requirements (3.9).
Download - Word .docx
Physical Protection Policy
Policy template for the 6 Physical Protection requirements (3.10).
Download - Word .docx
Risk Assessment Policy
Policy template for the 3 Risk Assessment requirements (3.11).
Download - Word .docx
Security Assessment Policy
Policy template for the 4 Security Assessment requirements (3.12).
Download - Word .docx
System and Communications Protection Policy
Policy template for the 16 System and Communications Protection requirements (3.13).
Download - Word .docx
System and Information Integrity Policy
Policy template for the 7 System and Information Integrity requirements (3.14).
Download
A template is a starting point, not a pass.
An SSP has to describe your real systems and how you actually meet each control. A generic, untailored SSP fails an assessment. We help you fill these in, close the gaps, and walk in ready for your C3PAO.
Want them assessment-ready? Talk to an engineer.