Mac-First CMMC L2 Readiness Pack

The flagship free download. One master workbook - ten linked tabs that run scoping, architecture decisions, external service providers, control ownership, and a POA&M planner with a 30-60-90 view - plus three companion guides. Built Mac-first, works for mixed fleets. Download directly below; no signup needed. The newsletter is optional and sends updated versions when they ship.

A guided, plain-English implementation pack for small DIB contractors preparing for a CMMC Level 2 (NIST SP 800-171 Rev 2) assessment. Built for Mac-heavy and mixed-OS environments. Use it to scope, plan, assign owners, and track gaps without spending six months figuring out where to start.

Sample of the downloadable workbook - read below

What's included

The Readiness Pack is built around one master workbook (Excel) plus three companion guides (Word docs). Together they walk you from "we just signed a DFARS 7012 contract and don't know what to do next" to "we have a defensible plan, named owners, a 30-60-90 timeline, and a POA&M an assessor can actually read."

The master workbook (cmmc-l2-premium-readiness-workbook.xlsx) - ten linked tabs that progress from scoping through architecture decisions, external service providers, control ownership, and a fully editable POA&M planner with prioritization, due dates, and a 30-60-90 day roadmap view.

Scope Workshop Guide (.docx) - a practical working session for defining your CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Out-of-Scope Assets before you start arguing about controls.

POA&M Prioritization Guide (.docx) - how to turn your gap list into a defensible, ranked plan that survives an assessor's "why this and not that?" questions.

IR Tabletop Exercise Guide (.docx) - a ready-to-run incident response tabletop, scoped to IR.L2-3.6.3, that doubles as evidence for the "test the incident response capability" assessment objective.

The workbook includes:

  • Start Here
  • Dashboard
  • Scope Workshop
  • Architecture Decisions
  • External Providers
  • Control Owners
  • POA&M Planner
  • 30-60-90 Roadmap
  • Platform Quick Checks
  • Data Rules
NEXT: SEE THE STANDARD

Now see what a finished policy looks like.

You have the planning tools. Review one completed Access Control policy and trace its decisions, procedures, evidence, and SSP references.

Review the completed policy

Already ready to compare the full system? See the Suite.