// ALL PRODUCTS

Working Files, Not Advice

Templates, trackers and policy kits for small businesses that have to meet a security requirement without a security team. Every file is a download you open and fill in. Sold through Payhip, delivered instantly.

CMMC Level 2

NIST 800-171 Rev 2, 110 requirements
Bundle, all five tools

CMMC Level 2 Readiness Kit: 5 NIST 800-171 Tools

The SSP template, SPRS score workbook, asset scoping worksheet, evidence tracker and POA&M tracker in one set. For contractors building the full assessment package rather than a single document.

Word + Excel

CMMC Level 2 System Security Plan (SSP) Template

All 110 requirements laid out with implementation-status fields, responsibility assignment, narrative prompts and an evidence column. Word holds the document an assessor reads, Excel holds the tracking view.

What a compliant SSP contains →
Excel

NIST 800-171 SPRS Score Workbook for CMMC Level 2

Walks the 1, 3 and 5 point weighting control by control so the score you post in SPRS matches what you actually assessed. The number is a representation to the government; this is how you defend it.

Excel

CMMC Level 2 Evidence Tracker for NIST 800-171 Audit

One row per assessment objective: what the artifact is, where it lives, who owns it, when it was last updated. Built for the examine, interview and test methods a C3PAO uses.

Excel

CMMC Level 2 POA&M Tracker for NIST 800-171

Tracks each open item with its point value, eligibility, owner, milestone and closure date, within the 180-day window the rule allows. Only some controls can be deferred; the tracker knows which.

What can and cannot go on a POA&M →
Excel

CMMC Level 2 Asset Scoping Worksheet for NIST 800-171

Sorts every asset into the five 32 CFR 170.19 categories: CUI, security protection, contractor risk managed, specialized and out of scope. The first document an assessor asks for.

AI Governance

Policy for the tools your staff already use
Word

AI Acceptable Use Policy Kit

The policy, the approved-tools register and the incident-reporting language, written so a 20-person shop can adopt it in one working session. Covers chat, meeting and recording tools, vendors and subprocessors.

Healthcare

HIPAA Security Rule
Excel + PDF guide

HIPAA Security Risk Assessment Tool: Excel + Guide

The risk analysis workbook the Security Rule requires, plus the guide that explains each row. For practices that need a documented assessment on file, not a consultant engagement.

Want the explanation before the file? The books cover the requirements in plain English.

// BOOKS BY LENNAN CARVER →