Free CMMC Assessment Resources

CMMC Compliance Resources

Official guides, regulations, and templates to help you achieve CMMC compliance. All resources are free and from authoritative sources.

15
Level 1 Controls
110
Level 2 Controls
General CMMC Resources
Core documentation applicable to all CMMC levels
ResourceSourceTypeLink

CMMC Resources & Documentation Portal

Official DoD hub for all CMMC documentation and resources

DoD CIO

DoD CIOExternalOpen

CMMC Documentation Portal

Complete CMMC program documentation

DoD CIO

DoD CIOExternalOpen

CMMC Assessment Process v2.0

Official C3PAO assessment procedures

Cyber AB

Cyber ABPDFOpen

Cyber AB Marketplace

Find certified C3PAOs and assessors

Cyber AB

Cyber ABExternalOpen

CMMC Program Rule (Federal Register)

Official CMMC program rule published October 2024

Federal Register

Federal RegisterRegulationOpen
Level 1 Resources (FCI)
15 basic safeguarding controls from FAR 52.204-21 for Federal Contract Information

Level 1 applies to contractors handling Federal Contract Information (FCI). It requires a self-assessment against 15 basic safeguarding controls.

ResourceSourceTypeLink

CMMC Assessment Guide - Level 1 v2.13

Official self-assessment guide for Level 1 (15 controls)

DoD CIO

DoD CIOPDFOpen

FAR 52.204-21 - Basic Safeguarding

Federal regulation defining the 15 basic safeguarding requirements

Acquisition.gov

Acquisition.govRegulationOpen

FAR 52.204-21 (Legal Reference)

Legal text of FAR clause for FCI protection

Cornell Law

Cornell LawRegulationOpen
Level 2 Resources (CUI)
110 security requirements from NIST SP 800-171 for Controlled Unclassified Information

Level 2 applies to contractors handling Controlled Unclassified Information (CUI). Requires either self-assessment or third-party C3PAO assessment depending on contract requirements.

ResourceSourceTypeLink

CMMC Scoping Guide - Level 2

Guide for identifying assessment scope and asset categories

DoD CIO

DoD CIOPDFOpen

CMMC Assessment Guide - Level 2 v2.13

Official assessment guide for Level 2 (110 controls)

DoD CIO

DoD CIOPDFOpen

NIST SP 800-171 Rev 2

Protecting Controlled Unclassified Information (CUI) - 110 security requirements

NIST

NISTPDFOpen

NIST SP 800-171 Rev 2 (Web Page)

Official NIST publication page with supplemental materials

NIST CSRC

NIST CSRCExternalOpen

NIST SP 800-171A - Assessment Procedures

Detailed assessment procedures for each control

NIST

NISTPDFOpen
DFARS Clauses Reference
Key Defense Federal Acquisition Regulation Supplement clauses for CMMC
ResourceSourceTypeLink

DFARS 252.204-7012

Safeguarding CUI & Cyber Incident Reporting

DoD

DoDRegulationOpen

DFARS 252.204-7019

NIST 800-171 Assessment & SPRS Score Submission

DoD

DoDRegulationOpen

DFARS 252.204-7020

Government Assessment Access

DoD

DoDRegulationOpen

DFARS 252.204-7021

CMMC Certification Requirement

DoD

DoDRegulationOpen
Free Templates & Tools
SSP, POA&M, and other compliance documentation templates
ResourceSourceTypeLink

NIST CUI SSP Template

Official System Security Plan template (Word format)

NIST

NISTTemplateOpen

NIST CUI POA&M Template

Official Plan of Action & Milestones template (Word format)

NIST

NISTTemplateOpen

Free SSP Template for CMMC 2.0

Community SSP template for CMMC compliance

Hive Systems

Hive SystemsTemplateOpen

Need Help With CMMC Compliance?

iATTEST helps you track compliance, generate policies, and prepare for assessments with AI-powered assistance. Start free today.

Get Started FreeLearn More