Working Files, Not Advice
Templates, trackers and policy kits for small businesses that have to meet a security requirement without a security team. Every file is a download you open and fill in. Sold through Payhip, delivered instantly.
CMMC Level 2
NIST 800-171 Rev 2, 110 requirementsCMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools
The SSP template, SPRS score workbook, asset scoping worksheet, evidence tracker and POA&M tracker in one set. For contractors building the full assessment package rather than a single document.
CMMC Level 2 System Security Plan (SSP) Template
All 110 requirements laid out with implementation-status fields, responsibility assignment, narrative prompts and an evidence column. Word holds the document an assessor reads, Excel holds the tracking view.
What a compliant SSP contains →NIST 800-171 SPRS Score Workbook for CMMC Level 2
Walks the 1, 3 and 5 point weighting control by control so the score you post in SPRS matches what you actually assessed. The number is a representation to the government; this is how you defend it.
CMMC Level 2 Evidence Tracker for NIST 800-171 Audit
One row per assessment objective: what the artifact is, where it lives, who owns it, when it was last updated. Built for the examine, interview and test methods a C3PAO uses.
CMMC Level 2 POA&M Tracker for NIST 800-171
Tracks each open item with its point value, eligibility, owner, milestone and closure date, within the 180-day window the rule allows. Only some controls can be deferred; the tracker knows which.
What can and cannot go on a POA&M →CMMC Level 2 Asset Scoping Worksheet for NIST 800-171
Sorts every asset into the five 32 CFR 170.19 categories: CUI, security protection, contractor risk managed, specialized and out of scope. The first document an assessor asks for.
AI Governance
Policy for the tools your staff already useAI Acceptable Use Policy Kit
The policy, the approved-tools register and the incident-reporting language, written so a 20-person shop can adopt it in one working session. Covers chat, meeting and recording tools, vendors and subprocessors.
Healthcare
HIPAA Security RuleHIPAA Security Risk Assessment Tool: Excel + Guide
The risk analysis workbook the Security Rule requires, plus the guide that explains each row. For practices that need a documented assessment on file, not a consultant engagement.
Want the explanation before the file? The books cover the requirements in plain English.
// BOOKS BY LENNAN CARVER →