CMMC Operator Suite: Release Status
Suite R2026.3 release manifest
This public manifest lists the current v0.6.5 deliverables. Every document ships as editable DOCX with a matching PDF review copy. Workbooks ship as XLSX. Complete also includes the PPTX training deck.
| Deliverable | Core | Complete |
|---|---|---|
| Documents | 44 | 54 |
| Workbooks | 6 | 7 |
| Training deck | - | 1 |
| PDF review copies | 44 | 54 |
| Versioned updates | 12 months | 12 months |
Open each category to inspect every artifact ID and title.
System Security Plan 1 document, Core and Complete
CMO-SSP-001System security plan template
Policies 14 documents, Core and Complete
CMO-POL-AC-001Access control policyCMO-POL-AT-001Awareness and training policyCMO-POL-AU-001Audit and accountability policyCMO-POL-CA-001Security assessment policyCMO-POL-CM-001Configuration management policyCMO-POL-IA-001Identification and authentication policyCMO-POL-IR-001Incident response policyCMO-POL-MA-001Maintenance policyCMO-POL-MP-001Media protection policyCMO-POL-PE-001Physical protection policyCMO-POL-PS-001Personnel security policyCMO-POL-RA-001Risk assessment policyCMO-POL-SC-001System and communications protection policyCMO-POL-SI-001System and information integrity policy
Procedures 15 documents, Core and Complete
CMO-PRO-AU-001Audit log procedureCMO-PRO-CFG-001Configuration management procedureCMO-PRO-CM-001Change management procedureCMO-PRO-CONMON-001Cybersecurity maintenance checklistCMO-PRO-CUI-001CUI marking procedureCMO-PRO-DR-001Backup and disaster recovery procedureCMO-PRO-DS-001Data spillage procedureCMO-PRO-FAC-001Facilities security procedureCMO-PRO-IR-001Incident response procedureCMO-PRO-OFF-001Personnel offboarding procedureCMO-PRO-ONB-001Personnel onboarding procedureCMO-PRO-PUB-001Publication review procedureCMO-PRO-RM-001Risk management procedureCMO-PRO-SCRM-001Supply chain risk management procedureCMO-PRO-VM-001Vulnerability and patch management procedure
Agreements and forms 8 documents, Core and Complete
CMO-FRM-AR-001Access request formCMO-FRM-BYOD-001BYOD agreementCMO-FRM-EQ-001Issued equipment agreementCMO-FRM-PA-001Privileged access agreementCMO-FRM-PSI-001Protection of sensitive information agreementCMO-FRM-RA-001Risk acceptance memoCMO-FRM-TW-001Telework agreementCMO-FRM-UA-001Information systems user agreement
Mac implementation overlay 5 documents, Core and Complete
CMO-MAC-ARCH-001Mac implementation reference architectureCMO-MAC-EVID-001Mac evidence collection guideCMO-MAC-FEDRAMP-001FedRAMP and ESP decision guide for Mac MDMCMO-MAC-MAP-001Mac control implementation mapCMO-MAC-SRM-001Jamf and GCC High shared responsibility notes
Finishing guide 1 document, Core and Complete
CMO-GDE-FIN-001Finishing the Suite
Premium specialty 10 documents, Complete only
CMO-SPC-ARC-001Assessment readiness checklistCMO-SPC-CUI-001CUI lifecycle mapCMO-SPC-EVID-001Evidence library structure and metadata standardCMO-SPC-FIPS-001FIPS validation strategy and risk assessmentCMO-SPC-SIA-001Security impact analysis templateCMO-SPC-TRAIN-001Security awareness training outlineCMO-SPC-TTX-001Tabletop exercise packCMO-SPC-AIG-001Artificial intelligence governance policy for a CUI environmentCMO-SPC-AIG-002Artificial intelligence acceptable use acknowledgementCMO-SPC-AIG-003macOS AI feature control standard
Workbooks 6 Core, 7 Complete
CMO-WBK-AI-001Asset inventory and categorization Core and CompleteCMO-WBK-EXC-001Policy exception tracker Core and CompleteCMO-WBK-POAM-001POA&M operational plan Core and CompleteCMO-WBK-SA-001Pre-assessment self-assessment Core and CompleteCMO-WBK-SRM-001Shared responsibility matrix Core and CompleteCMO-WBK-VRA-001ESP/CSP vendor risk assessment Core and CompleteCMO-WBK-AIT-001AI tool inventory and provider assessment Complete only
Training deck 1 deck, Complete only
CMO-SPC-TRAIN-002Security awareness training deck, PPTX with speaker notes
How releases work
Corrections to regulatory citations, control mappings, and document content are applied as they are found and verified, rather than held for a scheduled release. If a clause is renumbered or a control mapping is wrong, it is fixed and reissued.
Detailed release notes ship inside every download as CHANGELOG.md. The record travels with the documents you actually hold, which is more useful than a marketing page describing versions you may not have.
Why there is no version 1.0 yet
Version 1.0 will mark the point at which the full Level 2 documentation set is complete, reviewed end to end, and no longer changing structurally. Until then the Suite carries release-train designations rather than a semantic version number, because semantic numbering would imply a stability the product has not claimed yet.
Buyers are not waiting on 1.0 for completeness. The current release covers all 110 requirements of NIST SP 800-171 Rev 2 and all 320 assessment objectives. What 1.0 marks is the end of structural change, not the start of usefulness.
Verifying what you downloaded
Every archive is published with its SHA-256 fingerprint. If the fingerprint of your download matches the value below, the file you hold is byte for byte the file that was published. If it does not match, the download was incomplete or altered in transit, and you should download it again.
The fingerprints below cover the Suite R2026.3 archives. An earlier archive carries a different fingerprint, so check the file name first.
| Archive | Published | Bytes | SHA-256 |
|---|---|---|---|
| Core, Suite R2026.3 | 2026-08-07 | 4,788,141 | b443167c80d6111dbb4354206d3d041329ca9cfaed94be8abf047ca603cc961a |
| Complete, Suite R2026.3 | 2026-08-07 | 5,754,519 | 84f63f766e48a58d623c974804ace1f284b632fa2841503aefbce73f3e4da6e0 |
To check it yourself, with no extra software:
shasum -a 256 CMMC-Operator-Suite-v0.6.5-Complete.zipWindows PowerShell:
Get-FileHash CMMC-Operator-Suite-v0.6.5-Complete.zip -Algorithm SHA256Each archive also carries a manifest listing every file it should contain, so you can confirm nothing is missing as well as nothing is altered.