Compliance Resources
Understand your obligations. Plan your response.
These resources help you identify which cybersecurity requirements apply to your contract, understand what they require in plain language, and plan a practical response — before engaging counsel, an assessor, or a technical provider.
Educational aids only — not legal advice, not a CMMC assessment, and not a substitute for individualized professional review.
The Resources
Five decision aids, arranged in the order most contractors use them.
01
Find My Requirements
Answer questions about your contract, customer, and data to identify the cybersecurity obligations most likely to apply. Starting point for all other resources.
Open02
Compliance Roadmap
A plain-language guide to the sequence of compliance work — from requirement triage through documentation, remediation, and assessment readiness.
Open03
Educational Self-Check
Review source-mapped requirements in a checklist format and generate a planning snapshot for internal discussion. Not a scored assessment or SPRS submission.
Open04
Templates & Reference Aids
Reference templates for common compliance artifacts — SSPs, POA&Ms, incident response planning, policy mapping, inventories, and flowdown review checklists.
Open05
When to Get Professional Help
Guidance on when and which type of professional — legal counsel, assessor, MSP, or RPO — is the right next step for your situation.
OpenHow to use these resources
- 1. Start with Find My Requirements. Answer the wizard questions to identify which clauses and frameworks likely apply to your contract and data. This scopes everything else.
- 2. Read the Compliance Roadmap. Understand the sequence of work before committing resources. The roadmap maps the full arc from scope to documentation to assessment readiness.
- 3. Run the Educational Self-Check. Walk through requirements in a checklist format and generate a planning snapshot. Use it to structure an internal conversation — not as assessment evidence.
- 4. Reference templates as you build documentation. Use the reference aids to understand what common compliance artifacts look like before drafting your own.
- 5. Engage professionals at the right step. Use the professional-support guide to identify when and which type of provider you need — and what to bring to that conversation.
What these resources are not
- ✕Not a CMMC assessment or certification. Nothing here generates a CMMC score, validates a SPRS entry, or substitutes for a C3PAO assessment.
- ✕Not legal advice. These resources are general educational information. They do not create an attorney-client relationship and do not constitute legal advice for your specific situation.
- ✕Not a definitive obligation determination. Results identify issues likely to require review — they do not interpret your specific contract, resolve ambiguous flowdowns, or determine CUI status.
- ✕Not a substitute for professional review. Contracts, data sensitivity, and performance obligations vary. Use these resources to prepare for professional review, not to replace it.
Unsure where to start? See when to engage professional help →