The GovConCyber Compliance Toolkit
A complete, tiered set of templates, workbooks, and references for meeting CMMC 2.0 and NIST SP 800-171. Every file is built on the same verified control library that powers this site. Start with the Master Guide — it explains what each tool does and the order to use them in.
Master Guide & Toolkit Index (PDF)
These are educational templates, not legal advice. Verify all citations and effective dates against the official source before relying on any document for a contract or assessment.
Tier 1 — Extremely Useful
The core artifacts a DoD assessor or C3PAO will ask for first.
- System Security Plan (SSP) — document how you meet all 110 NIST SP 800-171 requirements.
- Self-Assessment & SPRS Score Workbook — score every requirement and estimate your SPRS number, with a readiness dashboard.
- Plan of Action & Milestones (POA&M) — track every gap to a fix with owners and dates.
- CMMC Readiness Checklist — a fast go/no-go for Level 1 (FCI) and Level 2 (CUI).
Tier 2 — Very Useful
Turn a paper exercise into an operating security program.
- Incident Response Plan — the NIST SP 800-61 lifecycle plus the DFARS 72-hour reporting workflow.
- Information Security Policy Pack — fourteen approved policies, one per control family.
- CUI & Asset Inventory Workbook — CUI data flow, hardware, software, users, and providers; defines your scope.
- Subcontractor Flow-Down & Supply Chain Checklist — flow the right clauses down and track subcontractor compliance.
Tier 3 — Informational
Context and shared language for you and your team.
- CMMC & NIST SP 800-171 Quick-Reference Guide — the whole landscape in a few pages, with a "what do I need to do?" decision guide.
- Glossary of Key Terms — plain-language definitions of the acronyms used throughout.
How to Use the Toolkit
Work the tools in order: orient with the Quick-Reference, inventory your environment, measure with the Self-Assessment, document your SSP, plan fixes in the POA&M, operationalize with the policies and incident response plan, and confirm with the Readiness Checklist before you self-affirm or engage a C3PAO.
- Not sure what applies to you? Start with Find My Requirements.
- Need a step-by-step plan? See Build a Compliance Program.
- Want to measure your current state? Use the Self-Assessment Checklists.
---
Toolkit version 1.0 · Last verified June 8, 2026 · Prepared by Brandon Hancock, J.D., CMMC-RP. Files are provided as locked PDFs for reference. Cybersecurity requirements change over time — confirm the current CMMC level, clauses, and SPRS methodology for your contract against the official source before relying on any template.