Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
Useful blank space, not fake paperwork.

CMMC working templates

These files are deliberately plain so you can adapt them to the actual environment. They do not contain pre-written claims of compliance. A good template makes missing facts visible; it should never encourage copying an implementation statement that is not true for your system.

CSVCUI asset inventoryTrack assets, CUI interaction, security role, management path, scope classification, and rationale.
Download CSV
CSVCMMC evidence indexMap requirements to implementation summaries, artifacts, systems, owners, dates, and refresh cadence.
Download CSV
CSVPOA&M trackerTrack eligibility, root cause, remediation, owner, dependency, target date, validation, and evidence.
Download CSV
MDSSP working outlineA system-specific outline for boundary, data flow, providers, requirements, evidence, and maintenance.
Download MD

How to use these together

Begin with the asset inventory and data-flow work before writing the SSP. The inventory should identify what touches CUI and what provides security protection to the environment. The SSP then describes how the system works and how the applicable requirements are implemented. The evidence index points from those implementation statements to artifacts that can be reproduced. If a qualifying assessment gap is permitted on a POA&M, the tracker should reference the exact requirement and closure evidence rather than becoming a generic IT backlog.

Keep the four records synchronized. When a system, provider, remote-access path, backup platform, or privileged-administration method changes, update the inventory and SSP first, then refresh affected evidence. A change that exists only in a ticket while the controlled system record still describes the old environment creates avoidable assessment confusion.

Related guides

Asset inventory fields that matter, how to build an evidence index, and SSP evidence mapping.