12 files · generated from the current datasets · by email
The CMMC templates pack
What a result proves: that your program is built on the requirement text, the weights and the objectives an assessor will use, not on a consultant's paraphrase. The tools stay free on the page; the files arrive by email.
POA&M register
01-poam-register.csvOne row per NIST SP 800-171 Rev 2 requirement with its SPRS weight and whether 32 CFR 170.21 lets a Level 2 POA&M carry it, plus the columns an assessor expects.
What it proves: That every open item has an owner, a date and a reason it is allowed to be open at all.
3.1.1 Authorized access control 5 pt not eligible 3.1.2 Transaction and function control 5 pt not eligible 3.1.3 Control CUI flow 1 pt eligible System Security Plan skeleton
02-ssp-skeleton.mdA section per requirement, by family: the requirement text, its weight, the objectives an assessor determines, and the fields the SSP must carry (implementation, responsible role, evidence location).
What it proves: That 3.12.4 exists at all; without an SSP no score can be submitted to SPRS.
SSP control matrix
03-ssp-control-matrix.csvThe 110 as a spreadsheet: id, family, name, weight, objective count, then the SSP fields to fill.
What it proves: Coverage: every requirement has a status, an owner and an evidence location, or a visible blank.
3.1.1 Authorized access control 6 objectives 3.1.2 Transaction and function control 2 objectives 3.1.3 Control CUI flow 5 objectives Assessment objectives checklist (all 320)
04-assessment-objectives-checklist.csvEvery NIST SP 800-171A objective as a row with the assessment methods, and columns for your determination and the evidence that supports it.
What it proves: That you assessed the way an assessor will: objective by objective, not requirement by requirement.
3.1.1 [a] authorized users are identified. 3.1.1 [b] processes acting on behalf of authorized users are identified. 3.1.1 [c] devices (including other systems) authorized to connect to the system are identified. Level 1 self-assessment checklist
05-level1-self-assessment.csvThe 17 CMMC Level 1 practices with the FAR 52.204-21 paragraph each comes from and the 800-171 requirement it maps to.
What it proves: Level 1 status, which has no POA&M and no conditional state: all 17 met, or not Level 1.
AC.L1-3.1.1 52.204-21(b)(1)(i) Limit system access to authorized users, processes acting on… AC.L1-3.1.2 52.204-21(b)(1)(ii) Limit system access to the types of transactions and functio… AC.L1-3.1.20 52.204-21(b)(1)(iii) Verify and control/limit connections to and use of external … Level 2 asset scoping inventory
06-asset-scoping-inventory.csvAn asset inventory with the five CMMC Level 2 asset categories, what each means, how each is assessed, what must be documented, and the mistake most often made with it.
What it proves: The boundary: which assets are assessed, which are only documented, and why.
CUI Asset Assessed against all applicable Level 2 requirements. Security Protection Asset Assessed against the Level 2 requirements relevant to the security protections it provides. Contractor Risk Managed Asset Not assessed against every requirement, but the assessor may check that the risk-based policies are documented and actually followed. If they are not, the assessor may assess the asset as a CUI Asset. CUI data-flow inventory
07-cui-data-flow-inventory.csvWhere CUI enters, moves, rests and leaves: one row per flow, with the marking, the protection in transit and at rest, and the requirement that governs it.
What it proves: 3.1.3, control of CUI flow, and the scope claim behind every enclave.
Common CUI categories reference
07b-cui-categories.csvThe CUI categories a defense contractor most often handles, their markings, what they are, and the trap each one carries.
What it proves: That the data-flow inventory names real categories, not "sensitive stuff".
Controlled Technical Information (CTI) CUI//SP-CTI Export Controlled CUI//SP-EXPT Procurement and Acquisition CUI//PROCURE FIPS-validated cryptography inventory
08-fips-crypto-inventory.csvEvery place cryptography protects CUI, the module doing it and its CMVP certificate, so 3.13.11 is answered module by module.
What it proves: Whether 3.13.11 scores 0, −3 (encryption in place, not validated) or −5 (no encryption), and it is the one 3-point gap a POA&M may carry.
Flow-down clause checklist
09-flowdown-clause-checklist.csvThe seven FAR and DFARS clauses that carry cyber obligations, when each applies, what each requires, how it flows down and the deadlines most often missed.
What it proves: For a prime: that every sub touching CDI carries the right clauses unaltered. For a sub: what you actually signed.
52.204-21 Basic Safeguarding of Covered Contractor Information Systems 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting Separation of duties matrix
10-separation-of-duties-matrix.csvRoles across the top, security-relevant duties down the side, with the pairs that must never sit with one person marked.
What it proves: 3.1.4: that no single individual can both make a privileged change and approve or audit it.
SF 1408 accounting system checklist
11-sf1408-accounting-system-checklist.csvThe pre-award survey criteria a cost-type contract needs your accounting system to meet, as a checklist with evidence columns.
What it proves: Whether you can bid cost-reimbursement work at all; a deficiency here arrives as a payment withhold after award.
Want the number before the paperwork? Compute your SPRS score or estimate what closing the gap costs.
Before you fill them in
- Are these the same as the free tools?
- The tools run in your browser and stay free with no email. The templates are files you take away and fill in, so they arrive by email: one message with a link that works for 14 days, and each file can be downloaded on its own.
- Where do the rows come from?
- Every template is generated on request from the same datasets the MacTech CMMC MCP server answers from: the 110 NIST SP 800-171 Rev 2 requirements with their DoD Assessment Methodology weights, the 320 NIST SP 800-171A objectives, the 17 CMMC Level 1 practices, the seven FAR and DFARS cyber clauses, and the CMMC Level 2 asset categories. A correction to a dataset reaches the pack in the same deploy; there is no stale PDF.
- Why CSV and Markdown rather than Word and Excel?
- So they open in anything, diff cleanly, and can be loaded into the GRC or ticketing system you already use. Excel and Google Sheets open the CSVs directly; the SSP skeleton is Markdown so it can go straight into a wiki or be converted to Word in one step.
- Is the SSP skeleton a complete System Security Plan?
- No. It is the structure an assessor expects, with the requirement text, the weight and the objectives already in place under each requirement, and bracketed fields for what only you know: how each requirement is implemented, by whom, and where the evidence lives. Without an SSP no score can be submitted to SPRS, so the skeleton is the first file to fill in.
From MacZine