Mac-first CMMC Level 2 for small DIB contractors
Practical guidance for taking Apple-first environments through NIST 800-171 and CMMC Level 2, and the Mac-first documentation suite that takes your SSP, policies, procedures, and workbooks off the blank page.
See the Suite - from $450CMMC Level 2 is 110 requirements and 320 assessment objectives. The Suite is the 54 documents and 7 workbooks that answer them.
Start with these



Start where you are
You are not sure what is in scope.
Sort the Macs first. CUI asset, Security Protection Asset, CRMA, or out of scope: that call sets the boundary, and everything you write afterward inherits it.
Read the asset classification decision tree →
You have to write the SSP.
What a System Security Plan has to contain, what assessors read first, and how to describe a Mac environment without hand waving.
You need the documents, not another article.
The documentation system itself: 54 documents, 7 workbooks, and a training deck, written Mac-first and mapped to all 110 Level 2 requirements.
Not ready to spend anything yet? Start where it costs nothing: the readiness pack is the scoping worksheet, the POA&M prioritization guide, the tabletop, and the macOS checklist, free.
The scope and evidence path
Five free pages, in the order the questions actually come up. Nothing to install, nothing to sign up for, and the classifier runs entirely in your browser.
- Which category is this Mac?Four questions, answered in the browser. CUI asset, Security Protection Asset, Contractor Risk Managed Asset, or out of scope.Mac scope classifier
- What does that category cost me?The documentation obligation and the assessment consequence for each category, taken from 32 CFR 170.19 Table 3, with the macOS implementation delta called out separately as judgement.Mac scope categories
- What evidence does that generate?What an assessor asks to see, at assessment objective level, with the artifact named rather than the activity described.Assessment evidence
- How often do I have to refresh it?Why your own policies set the cadence rather than CMMC, and how much recurring work a Level 2 program actually creates once you count it.Continuous monitoring
- Which requirement is which?All 110 requirements with SPRS weight, POA&M eligibility, and whether the macOS implementation differs from the Windows one.CMMC Level 2 controls list
These pages are reference and planning material. They are not legal advice, not an assessment finding, and not a substitute for a C3PAO.
Browse by topic
Scoping & CUI
- Mac Asset Classification: CUI Asset, SPA, CRMA, or Out of Scope?
- CUI vs. FCI: How to Tell Them Apart
- GCC vs. GCC High vs. Commercial Microsoft 365
macOS Controls & Baselines
- FIPS-Validated Encryption for CUI: Why Enabled Is Not Enough
- MFA for CMMC: Satisfying IA.L2-3.5.3 on macOS
- mSCP vs CIS vs STIG: Which Mac Baseline
MDM & the Management Plane
Documentation & Assessment
- Writing a CMMC SSP That Survives Assessment
- CMMC Self-Assessment Checklist
- Documentation Options and Real Costs: DIY vs. Bundles
Field Notes
- Why Blocking AI Is the Wrong CMMC Strategy
- What I Took Away From the 2026 NCMS Seminar
- Free macOS CMMC Resources