13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not

12 files · generated from the current datasets · by email

The CMMC templates pack

What a result proves: that your program is built on the requirement text, the weights and the objectives an assessor will use, not on a consultant's paraphrase. The tools stay free on the page; the files arrive by email.

  1. POA&M register

    01-poam-register.csv

    One row per NIST SP 800-171 Rev 2 requirement with its SPRS weight and whether 32 CFR 170.21 lets a Level 2 POA&M carry it, plus the columns an assessor expects.

    What it proves: That every open item has an owner, a date and a reason it is allowed to be open at all.

    Serves 3.12.2 · 32 CFR 170.21 · Source: DoD Assessment Methodology Annex A weights; 32 CFR 170.21 eligibility

    3.1.1Authorized access control5 ptnot eligible
    3.1.2Transaction and function control5 ptnot eligible
    3.1.3Control CUI flow1 pteligible
  2. System Security Plan skeleton

    02-ssp-skeleton.md

    A section per requirement, by family: the requirement text, its weight, the objectives an assessor determines, and the fields the SSP must carry (implementation, responsible role, evidence location).

    What it proves: That 3.12.4 exists at all; without an SSP no score can be submitted to SPRS.

    Serves 3.12.4 · Source: NIST SP 800-171 Rev 2 catalog; NIST SP 800-171A objectives

  3. SSP control matrix

    03-ssp-control-matrix.csv

    The 110 as a spreadsheet: id, family, name, weight, objective count, then the SSP fields to fill.

    What it proves: Coverage: every requirement has a status, an owner and an evidence location, or a visible blank.

    Serves 3.12.4 · Source: NIST SP 800-171 Rev 2 catalog; NIST SP 800-171A objective counts

    3.1.1Authorized access control6 objectives
    3.1.2Transaction and function control2 objectives
    3.1.3Control CUI flow5 objectives
  4. Assessment objectives checklist (all 320)

    04-assessment-objectives-checklist.csv

    Every NIST SP 800-171A objective as a row with the assessment methods, and columns for your determination and the evidence that supports it.

    What it proves: That you assessed the way an assessor will: objective by objective, not requirement by requirement.

    Serves NIST SP 800-171A · CMMC Level 2 assessment · Source: NIST SP 800-171A (June 2018), 110 requirements, 320 objectives

    3.1.1[a]authorized users are identified.
    3.1.1[b]processes acting on behalf of authorized users are identified.
    3.1.1[c]devices (including other systems) authorized to connect to the system are identified.
  5. Level 1 self-assessment checklist

    05-level1-self-assessment.csv

    The 17 CMMC Level 1 practices with the FAR 52.204-21 paragraph each comes from and the 800-171 requirement it maps to.

    What it proves: Level 1 status, which has no POA&M and no conditional state: all 17 met, or not Level 1.

    Serves FAR 52.204-21 · CMMC Level 1 · Source: FAR 52.204-21(b)(1); DoD CMMC Level 1 Self-Assessment Guide

    AC.L1-3.1.152.204-21(b)(1)(i)Limit system access to authorized users, processes acting on…
    AC.L1-3.1.252.204-21(b)(1)(ii)Limit system access to the types of transactions and functio…
    AC.L1-3.1.2052.204-21(b)(1)(iii)Verify and control/limit connections to and use of external …
  6. Level 2 asset scoping inventory

    06-asset-scoping-inventory.csv

    An asset inventory with the five CMMC Level 2 asset categories, what each means, how each is assessed, what must be documented, and the mistake most often made with it.

    What it proves: The boundary: which assets are assessed, which are only documented, and why.

    Serves 3.12.4 · CMMC Level 2 Scoping Guide · Source: CMMC Level 2 Scoping Guide asset categories

    CUI AssetAssessed against all applicable Level 2 requirements.
    Security Protection AssetAssessed against the Level 2 requirements relevant to the security protections it provides.
    Contractor Risk Managed AssetNot assessed against every requirement, but the assessor may check that the risk-based policies are documented and actually followed. If they are not, the assessor may assess the asset as a CUI Asset.
  7. CUI data-flow inventory

    07-cui-data-flow-inventory.csv

    Where CUI enters, moves, rests and leaves: one row per flow, with the marking, the protection in transit and at rest, and the requirement that governs it.

    What it proves: 3.1.3, control of CUI flow, and the scope claim behind every enclave.

    Serves 3.1.3 · 3.13.8 · 3.13.16 · Source: NIST SP 800-171 Rev 2 requirements 3.1.3, 3.13.8, 3.13.16

  8. Common CUI categories reference

    07b-cui-categories.csv

    The CUI categories a defense contractor most often handles, their markings, what they are, and the trap each one carries.

    What it proves: That the data-flow inventory names real categories, not "sensitive stuff".

    Serves 3.8.4 · CUI Registry · Source: National Archives CUI Registry; MacTech field notes

    Controlled Technical Information (CTI)CUI//SP-CTI
    Export ControlledCUI//SP-EXPT
    Procurement and AcquisitionCUI//PROCURE
  9. FIPS-validated cryptography inventory

    08-fips-crypto-inventory.csv

    Every place cryptography protects CUI, the module doing it and its CMVP certificate, so 3.13.11 is answered module by module.

    What it proves: Whether 3.13.11 scores 0, −3 (encryption in place, not validated) or −5 (no encryption), and it is the one 3-point gap a POA&M may carry.

    Serves 3.13.11 · 32 CFR 170.21 · Source: NIST CMVP; DoD Assessment Methodology sliding scale for 3.13.11

  10. Flow-down clause checklist

    09-flowdown-clause-checklist.csv

    The seven FAR and DFARS clauses that carry cyber obligations, when each applies, what each requires, how it flows down and the deadlines most often missed.

    What it proves: For a prime: that every sub touching CDI carries the right clauses unaltered. For a sub: what you actually signed.

    Serves FAR 52.204-21 · DFARS 252.204-7008/7012/7019/7020/7021 · 252.239-7010 · Source: acquisition.gov clause text; MacTech clause obligations dataset

    52.204-21Basic Safeguarding of Covered Contractor Information Systems
    252.204-7008Compliance with Safeguarding Covered Defense Information Controls
    252.204-7012Safeguarding Covered Defense Information and Cyber Incident Reporting
  11. Separation of duties matrix

    10-separation-of-duties-matrix.csv

    Roles across the top, security-relevant duties down the side, with the pairs that must never sit with one person marked.

    What it proves: 3.1.4: that no single individual can both make a privileged change and approve or audit it.

    Serves 3.1.4 · 3.1.5 · 3.1.7 · Source: NIST SP 800-171 Rev 2 requirements 3.1.4, 3.1.5, 3.1.7

  12. SF 1408 accounting system checklist

    11-sf1408-accounting-system-checklist.csv

    The pre-award survey criteria a cost-type contract needs your accounting system to meet, as a checklist with evidence columns.

    What it proves: Whether you can bid cost-reimbursement work at all; a deficiency here arrives as a payment withhold after award.

    Serves SF 1408 · DFARS 252.242-7005 · Source: Standard Form 1408, Preaward Survey of Prospective Contractor Accounting System

Send me the pack

All 12 files as one zip, generated today from the current datasets, in your inbox in a minute; the link works for 14 days.

One email with the link. No sales sequence, no sharing your address; MacZine only if you tick the box.

Want the number before the paperwork? Compute your SPRS score or estimate what closing the gap costs.

Before you fill them in

Are these the same as the free tools?
The tools run in your browser and stay free with no email. The templates are files you take away and fill in, so they arrive by email: one message with a link that works for 14 days, and each file can be downloaded on its own.
Where do the rows come from?
Every template is generated on request from the same datasets the MacTech CMMC MCP server answers from: the 110 NIST SP 800-171 Rev 2 requirements with their DoD Assessment Methodology weights, the 320 NIST SP 800-171A objectives, the 17 CMMC Level 1 practices, the seven FAR and DFARS cyber clauses, and the CMMC Level 2 asset categories. A correction to a dataset reaches the pack in the same deploy; there is no stale PDF.
Why CSV and Markdown rather than Word and Excel?
So they open in anything, diff cleanly, and can be loaded into the GRC or ticketing system you already use. Excel and Google Sheets open the CSVs directly; the SSP skeleton is Markdown so it can go straight into a wiki or be converted to Word in one step.
Is the SSP skeleton a complete System Security Plan?
No. It is the structure an assessor expects, with the requirement text, the weight and the objectives already in place under each requirement, and bracketed fields for what only you know: how each requirement is implemented, by whom, and where the evidence lives. Without an SSP no score can be submitted to SPRS, so the skeleton is the first file to fill in.

From MacZine

Working notes for the files

The full run →