Talk to an Expert
Services

CMMC 2.0 Level 2 Documentation Library and Supporting Services

Customizable documentation templates — plus the level of expert support your organization needs.

Engagement models

Three ways to work with us

The RegDOX team supports clients through every stage of the compliance journey — from initial scoping and gap analysis to implementation and preparation for SPRS submission or third-party assessment. Start with the documentation and add only the support you need. We’ll provide a custom plan that meets you where you are today.

Consulting services require an active Documentation Foundation subscription.

01

Documentation Foundation

Included with a RegDOX subscription

Customizable templates provided under a RegDOX subscription. Your organization tailors, approves, and maintains them to reflect its actual environment.

  • Governance policies and procedures
  • Control-specific plans and standards
  • Forms, registers, and inventories
  • SSP, POA&M, and evidence tracker
Easily tailored for compliance
02

Assessment Accelerator

Optional consulting
Requires a Documentation Foundation subscription

Expert guidance in using and tailoring the foundational documents. Your organization remains responsible for implementation and completion.

  • Understand CMMC Level 2 requirements
  • Apply 110 security requirements and 320 assessment objectives
  • Identify, collect, and map evidence
  • Complete workbooks and track gaps
RegDOX-guided · customer-led
03

Assessment Readiness Consulting

Optional consulting
Requires a Documentation Foundation subscription

RegDOX takes primary responsibility for planning and completing assessment-readiness work, with customer participation and approval.

  • Readiness review and project plan
  • Lead document customization and completion
  • Remediation and POA&M guidance
  • Final evidence and gap validation
  • C3PAO assessment preparation
RegDOX-led · customer-supported
133
Customizable templates in the RegDOX documentation library — policies, plans, standards, registers, and evidence tooling.
Documentation library
110
Security requirements your organization must implement and evidence to meet CMMC 2.0 Level 2.
NIST SP 800-171
320
Assessment objectives a C3PAO tests against those requirements during a Level 2 assessment.
NIST SP 800-171A
Documentation library

What’s in the library

A complete documentation set for the foundation of a defense contractor’s CMMC Level 2 program — written to the control set, and built to be tailored to your environment rather than filed as is. Available to RegDOX clients by subscription.

80
Policies & Procedures
15
Plans
15
Standards
10
Forms & Templates
10
Registers & Inventories
1
Evidence Tracker
1
System Security Plan (SSP)
1
POA&M
The path

How it fits together

Each level of support picks up where the last one leaves off. Most clients start with the documentation and add guidance as an assessment date comes into view.

1Customize templates
2Implement with guidance
3Complete managed preparation
Ready for a C3PAO assessment

Document counts and service scope may be tailored to organizational size, environment, and risk.

Next step

One team. The whole journey.

From the first document to the final assessment, the RegDOX Solutions team supports every step of the compliance journey. Tell us where you are. We'll meet you there.

(800) 517-3171 · Nashua, NH · U.S. data centers & personnel