Home/Documentation/Programme-level documentation
NIST SP 800-171 R3 & CMMC Level 2 Programme
Everything a defence supplier needs to document CUI handling: policies, standards, procedures, System Security Plan and POA&M, aligned to 800-171A assessment objectives.
What this set does
CMMC assessors work from the assessment objectives in 800-171A, not from the requirement text. This programme is written objective-by-objective: each of the 97 R3 requirements has a policy statement, a standard, a procedure and an SSP entry that together give an assessor the 'examine' evidence they need. The POA&M template follows the DoD-accepted structure.
What's inside
- Policies and standards for all 17 R3 requirement families
- Procedures mapped to each 800-171A assessment objective
- System Security Plan (SSP) template with boundary and data-flow sections
- Plan of Action and Milestones (POA&M) template
- CUI scoping guide and asset categorisation workbook
- Supply chain risk management plan (800-161 aligned)
- R2 to R3 transition worksheet showing changed objectives
- Self-assessment scoring workbook (SPRS-style)
Who it is for
Defence Industrial Base suppliers and their subcontractors preparing for a C3PAO or self-assessment.
How the documents are structured
Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.
Tailoring effort
Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.
Included in these bundles
- NIST 800-171 & CMMC Level 2 Bundle — £1,995
Licence
One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.
Related products
Policies & Standards — NIST SP 800-53 R5 (Moderate)
Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.
£695 · 48 documentsProcedures Library
Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.
£595 · 118 documentsRisk Management Programme
A defensible risk methodology, an assessment procedure, a register that actually gets used, and a third-party risk process, all in one consistent vocabulary.
£445 · 14 documents