CMMC Operator Suite: Release Status

Current release: Suite v1.0Maintained continuously. Every purchase includes 12 months of updates.

Suite v1.0 release manifest

This public manifest lists the current v1.0 deliverables. Every document ships as editable DOCX with a matching PDF review copy. Workbooks ship as XLSX. Complete also includes the PPTX training deck.

DeliverableCoreComplete
Documents4454
Workbooks67
Training deck-1
PDF review copies4454
Versioned updates12 months12 months

Open each category to inspect every artifact ID and title.

System Security Plan 1 document, Core and Complete
  • CMO-SSP-001 System security plan template
Policies 14 documents, Core and Complete
  • CMO-POL-AC-001 Access control policy
  • CMO-POL-AT-001 Awareness and training policy
  • CMO-POL-AU-001 Audit and accountability policy
  • CMO-POL-CA-001 Security assessment policy
  • CMO-POL-CM-001 Configuration management policy
  • CMO-POL-IA-001 Identification and authentication policy
  • CMO-POL-IR-001 Incident response policy
  • CMO-POL-MA-001 Maintenance policy
  • CMO-POL-MP-001 Media protection policy
  • CMO-POL-PE-001 Physical protection policy
  • CMO-POL-PS-001 Personnel security policy
  • CMO-POL-RA-001 Risk assessment policy
  • CMO-POL-SC-001 System and communications protection policy
  • CMO-POL-SI-001 System and information integrity policy
Procedures 15 documents, Core and Complete
  • CMO-PRO-AU-001 Audit log procedure
  • CMO-PRO-CFG-001 Configuration management procedure
  • CMO-PRO-CM-001 Change management procedure
  • CMO-PRO-CONMON-001 Cybersecurity maintenance checklist
  • CMO-PRO-CUI-001 CUI marking procedure
  • CMO-PRO-DR-001 Backup and disaster recovery procedure
  • CMO-PRO-DS-001 Data spillage procedure
  • CMO-PRO-FAC-001 Facilities security procedure
  • CMO-PRO-IR-001 Incident response procedure
  • CMO-PRO-OFF-001 Personnel offboarding procedure
  • CMO-PRO-ONB-001 Personnel onboarding procedure
  • CMO-PRO-PUB-001 Publication review procedure
  • CMO-PRO-RM-001 Risk management procedure
  • CMO-PRO-SCRM-001 Supply chain risk management procedure
  • CMO-PRO-VM-001 Vulnerability and patch management procedure
Agreements and forms 8 documents, Core and Complete
  • CMO-FRM-AR-001 Access request form
  • CMO-FRM-BYOD-001 BYOD agreement
  • CMO-FRM-EQ-001 Issued equipment agreement
  • CMO-FRM-PA-001 Privileged access agreement
  • CMO-FRM-PSI-001 Protection of sensitive information agreement
  • CMO-FRM-RA-001 Risk acceptance memo
  • CMO-FRM-TW-001 Telework agreement
  • CMO-FRM-UA-001 Information systems user agreement
Mac implementation overlay 5 documents, Core and Complete
  • CMO-MAC-ARCH-001 Mac implementation reference architecture
  • CMO-MAC-EVID-001 Mac evidence collection guide
  • CMO-MAC-FEDRAMP-001 FedRAMP and ESP decision guide for Mac MDM
  • CMO-MAC-MAP-001 Mac control implementation map
  • CMO-MAC-SRM-001 Jamf and GCC High shared responsibility notes
Finishing guide 1 document, Core and Complete
  • CMO-GDE-FIN-001 Finishing the Suite
Premium specialty 10 documents, Complete only
  • CMO-SPC-ARC-001 Assessment readiness checklist
  • CMO-SPC-CUI-001 CUI lifecycle map
  • CMO-SPC-EVID-001 Evidence library structure and metadata standard
  • CMO-SPC-FIPS-001 FIPS validation strategy and risk assessment
  • CMO-SPC-SIA-001 Security impact analysis template
  • CMO-SPC-TRAIN-001 Security awareness training outline
  • CMO-SPC-TTX-001 Tabletop exercise pack
  • CMO-SPC-AIG-001 Artificial intelligence governance policy for a CUI environment
  • CMO-SPC-AIG-002 Artificial intelligence acceptable use acknowledgement
  • CMO-SPC-AIG-003 macOS AI feature control standard
Workbooks 6 Core, 7 Complete
  • CMO-WBK-AI-001 Asset inventory and categorization Core and Complete
  • CMO-WBK-EXC-001 Policy exception tracker Core and Complete
  • CMO-WBK-POAM-001 POA&M operational plan Core and Complete
  • CMO-WBK-SA-001 Pre-assessment self-assessment Core and Complete
  • CMO-WBK-SRM-001 Shared responsibility matrix Core and Complete
  • CMO-WBK-VRA-001 ESP/CSP vendor risk assessment Core and Complete
  • CMO-WBK-AIT-001 AI tool inventory and provider assessment Complete only
Training deck 1 deck, Complete only
  • CMO-SPC-TRAIN-002 Security awareness training deck, PPTX with speaker notes

How releases work

Corrections to regulatory citations, control mappings, and document content are applied as they are found and verified, rather than held for a scheduled release. If a clause is renumbered or a control mapping is wrong, it is fixed and reissued.

Detailed release notes ship inside every download as CHANGELOG.md. The record travels with the documents you actually hold, which is more useful than a marketing page describing versions you may not have.

What version 1.0 means

Version 1.0 marks the point at which the full Level 2 documentation set is complete, reviewed end to end, and no longer changing structurally. The Suite reached that point on August 21, 2026. Earlier releases carried release-train designations rather than a semantic version number, because semantic numbering would have implied a stability the product had not yet claimed.

v1.0 is a designation change plus one correction, not a rewrite. Five metadata files changed in each edition and every other entry is byte for byte identical to the release before it, verified by comparing the SHA-256 of every entry in both archives. The correction was to two Core manifest headers that named the content version rather than the release; the file lists they carried were already accurate. No deliverable tracks the release number in its content, which is why a version change cannot alter a document. Each one carries a single fixed line recording the release it was first adopted from, currently reading Suite R2026.3, which is the release-train designation these documents entered the suite under. That line is historical and does not move when a new release is cut.

The current release covers all 110 requirements of NIST SP 800-171 Rev 2 and all 320 assessment objectives.

Verifying what you downloaded

Every archive is published with its SHA-256 fingerprint. If the fingerprint of your download matches the value below, the file you hold is byte for byte the file that was published. If it does not match, the download was incomplete or altered in transit, and you should download it again.

The fingerprints below cover the Suite v1.0 archives. An earlier archive carries a different fingerprint, so check the file name first.

ArchivePublishedBytesSHA-256
Core, Suite v1.02026-08-214,788,6919ecb1b7c9c14e8cf1067475ef2952199659add2ea0eb18f4e6215194f0799b2a
Complete, Suite v1.02026-08-215,755,07039f5b149730d48165d55f6ab3bd7deb783a33d4d2ea40e8be597c59df1804e28
Records Pack v1.02026-08-2055,4955a25efdd8a985249940914744a1859d4b9ed7db5be59e382e4e1aa1f96e12b83
AI Governance Pack v1.02026-08-2066,73550c98d199dbdbb4e60322b4fd58bf017f2a97849932f5bf4bea597fd3145eb7b

To check it yourself, with no extra software:

macOS or Linux: shasum -a 256 CMMC-Operator-Suite-v1.0-Complete.zip
Windows PowerShell: Get-FileHash CMMC-Operator-Suite-v1.0-Complete.zip -Algorithm SHA256

Each archive also carries a manifest listing every file it should contain, so you can confirm nothing is missing as well as nothing is altered.