Home/Documentation/Programme-level documentation

NIST SP 800-171 R3 & CMMC Level 2 Programme

Everything a defence supplier needs to document CUI handling: policies, standards, procedures, System Security Plan and POA&M, aligned to 800-171A assessment objectives.

Programme

What this set does

CMMC assessors work from the assessment objectives in 800-171A, not from the requirement text. This programme is written objective-by-objective: each of the 97 R3 requirements has a policy statement, a standard, a procedure and an SSP entry that together give an assessor the 'examine' evidence they need. The POA&M template follows the DoD-accepted structure.

What's inside

  • Policies and standards for all 17 R3 requirement families
  • Procedures mapped to each 800-171A assessment objective
  • System Security Plan (SSP) template with boundary and data-flow sections
  • Plan of Action and Milestones (POA&M) template
  • CUI scoping guide and asset categorisation workbook
  • Supply chain risk management plan (800-161 aligned)
  • R2 to R3 transition worksheet showing changed objectives
  • Self-assessment scoring workbook (SPRS-style)

Who it is for

Defence Industrial Base suppliers and their subcontractors preparing for a C3PAO or self-assessment.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Included in these bundles

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Policies & Standards — NIST SP 800-53 R5 (Moderate)

Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.

£695 · 48 documents

Procedures Library

Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.

£595 · 118 documents

Risk Management Programme

A defensible risk methodology, an assessment procedure, a register that actually gets used, and a third-party risk process, all in one consistent vocabulary.

£445 · 14 documents