CMMC Level 1 & Level 2 DIY Kit
Prepare for Current and Future CMMC Requirements
The Department of Defense is reviewing the implementation of portions of the Cybersecurity Maturity Model Certification (CMMC) program. While the transition to CMMC Phase II has been suspended pending that review, organizations should continue preparing based on their contracts and applicable cybersecurity requirements.
Program Update (July 2026): Existing contractual cybersecurity responsibilities may still apply depending on your contracts and the information your organization processes, stores, or transmits. Applicable DFARS requirements, NIST SP 800-171 implementation, System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), SPRS reporting where required, and maintaining accurate cybersecurity documentation remain important parts of an organization’s overall readiness.
The Washington Process Group CMMC Level 1 & Level 2 DIY Kit provides practical templates, trackers, checklists, and implementation support materials to help your team organize documentation, evidence, policies, procedures, and readiness activities. The kit is designed to support organizations preparing for Level 1 self-assessments and applicable Level 2 assessment requirements while building a structured cybersecurity documentation program that can adapt as government requirements evolve.
What the Kit Helps You Do
- Organize CMMC Level 1 and Level 2 documentation
- Map policies, procedures, and evidence to applicable practices
- Build and maintain a System Security Plan (SSP)
- Document open items using a Plan of Action and Milestones (POA&M)
- Track implementation progress and supporting evidence
- Assign responsibilities and manage follow-up actions
- Prepare documentation, evidence, and supporting materials for the assessment type required by the applicable contract
- Support internal readiness reviews
- Improve consistency across cybersecurity documentation and implementation activities
What Is Included
The kit includes practical materials such as:
- CMMC Level 1 and Level 2 templates
- Practice-mapping tools
- System Security Plan (SSP) templates
- POA&M templates
- Cybersecurity policies and procedures
- Evidence trackers
- Gap-assessment and readiness tools
- Roles and responsibilities materials
- Project and implementation trackers
- Internal review and assessment-preparation checklists
- Supporting guidance documents
Files are provided in editable formats, including DOCX, XLSX, and PDF, where applicable.
Who This Kit Is For
This kit is designed for:
- DoD prime contractors
- DoD subcontractors
- Organizations handling Federal Contract Information (FCI)
- Organizations handling Controlled Unclassified Information (CUI)
- Small and mid-sized defense suppliers
- Internal compliance, cybersecurity, quality, and operations teams
- Organizations that want to manage cybersecurity readiness internally
- Organizations preparing for Level 1 self-assessment requirements
- Organizations preparing for Level 2 self-assessment requirements or other assessment requirements that may apply under current or future contract requirements
Prime contractors are responsible for flowing applicable cybersecurity requirements to subcontractors when required by the subcontract and the work being performed.
Subcontractors should review the specific terms provided by the prime contractor to determine which systems, information, documentation, practices, and assessment requirements apply to their organization.
Assessment Readiness
This kit supports cybersecurity readiness, documentation, and implementation activities. It does not determine which assessment type applies to your organization.
Assessment requirements are established by the applicable solicitation, contract, subcontract, task order, delivery order, and current government guidance. Organizations should continue monitoring official Department of Defense updates as the CMMC program evolves.
Level 1: Organizations complete the required self-assessment, submit assessment results in SPRS where required, and have the organization’s Affirming Official submit the required affirmation.
Level 2: Depending on the applicable contract requirements and current government guidance, organizations may be required to complete a Level 2 self-assessment or another applicable assessment process.
Organizations should review their contracts, subcontract flow-down requirements, and official government guidance to determine which assessment requirements apply to their environment.
What You Receive After Purchase
This is a digital product.
After purchase, you will receive immediate access to downloadable files so your team can begin reviewing, customizing, and organizing the materials for your organization’s environment.
The templates are designed to be customized to reflect your actual systems, processes, personnel, technologies, and contractual requirements. Purchasing templates alone does not make an organization compliant. Successful readiness depends on implementing the applicable practices, maintaining supporting evidence, and keeping documentation current.
Important Notice
This toolkit provides a structured starting point for cybersecurity readiness and documentation activities. It does not guarantee:
- CMMC certification
- Successful completion of any assessment
- Contract eligibility
- Contract award
- Compliance with every contractual requirement
- Acceptance by a contracting officer, assessor, certification organization, or government agency
Your organization is responsible for customizing the materials, implementing the applicable practices, maintaining supporting evidence, and confirming the requirements that apply to its contracts, systems, information, and business operations.
Organizations should seek appropriate legal, contractual, cybersecurity, or assessment guidance whenever necessary.
Refund Policy
This is a digital product.
Due to immediate electronic delivery, all sales are final except in cases of duplicate charges, delivery failures, defective or missing files, or where otherwise required by applicable law.
Please review the full Refund Policy before completing your purchase.