CMMC 2.0
Cybersecurity Maturity Model Certification: practices and domains, gap assessment, SPRS score, evidence, POA&Ms and assessment preparation.
CMMC 2.0 Overview & Key Concepts
What CMMC 2.0 is, why the Defense Industrial Base must meet it, how its three levels map to NIST SP 800-171 and 800-172, and the concepts the module uses.
Practices & Domains
The 14 CMMC domains with Level 1 and Level 2 practice counts, each practice tied to its NIST SP 800-171 or FAR 52.204-21 clause, and the statuses you set.
Controls
The Controls page is where you define, implement, and track the operational controls that satisfy CMMC practices. While practices describe what must be achieved, controls describe...
Gap Assessment & SPRS Score
The Gap Assessment evaluates your organisation's current implementation status against all CMMC practices for your target level. It produces a domain-by-domain breakdown and...
Evidence Collection
The Evidence page helps you collect and organise the artifacts that prove your CMMC practices are implemented and your controls are operating
POA&Ms
A Plan of Action Milestones (POA M) documents known security deficiencies and the specific steps your organisation will take to remediate them. Under CMMC 2.0, POA Ms play a...
Assessments & Findings
Log self-assessments, C3PAO and DIBCAC engagements, record outcomes, and prepare for a Level 2 C3PAO assessment with the evidence and POA&M in order.
Management Reviews
Management Reviews provide governance oversight for your CMMC programme. Regular reviews ensure senior leadership stays informed about cybersecurity posture, assessment readiness,...
Certification Readiness
The Readiness page tracks your journey from initial CMMC programme setup through certification and ongoing