A C3PAO-ready remediation backlog, NIST SP 800-171 evidence checklist, and exportable report — keyed to your Phase 2 readiness snapshot and aligned to 32 CFR Part 170, DFARS 252.204-7012, NIST SP 800-171 Rev 2, and NIST SP 800-172.
Get The Evidence-Ready Pack $199✓ 30-min delivery · No account required · Secured by Stripe
Each Readiness Pack ships the three artifacts a defense contractor needs to brief leadership, answer a C3PAO, and close out a Conditional POA&M.
Keyed to your saved analyzer answers — a prioritized backlog across all 14 CMMC families, with control-level owner, evidence, and due-date guidance for NIST SP 800-171 Rev 2 + select NIST SP 800-172. The deliverable is delivered in Slice 2; this offer ships the order capture and page.
Map of every artifact a C3PAO auditor or DIBCAC assessor expects at assessment — bounded by DFARS 252.204-7012 §(b)–§(g), SPRS posting cadence, and DIBNet reporting flow. Each control row carries the citation of the canonical source.
Board-ready and C3PAO-ready deliverable — the same artifact your compliance officer can forward directly to a DoD contracting officer or Cyber AB auditor. (Slice 2 deliverable; Slice 1 ships the order capture here.)
Eight gaps, ranked by Phase 2 SPRS-finding frequency; each row pairs the NIST SP 800-171 Rev 2 control ID with the 32 CFR 170 / DFARS 7012 paragraph that gated it, and routes into a contractor-specific analysis.
| # | Gap | Control (NIST 800-171 r2) | Citation | Fix recipe | Primary source | Analyze |
|---|---|---|---|---|---|---|
| 1 | Limit system access to authorized users | AC.L2-3.1.1 | NIST SP 800-171 r2 §3.1.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Enumerate every account on the CUI enclave, remove shared/stale accounts, and capture the authoritative account list in SSP §9. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 2 | Multi-factor authentication for local & network access to privileged accounts and network-accessible CUI | IA.L2-3.5.3 | NIST SP 800-171 r2 §3.5.3 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Enforce MFA on every privileged and network-access path; for unprivileged remote access, only the network-access subset is required by NIST 800-171 r2 §3.5.3 (broader CISA-emergency-directive posture is separate). | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 3 | Identify, report, and correct system flaws in a timely manner | SI.L2-3.14.1 | NIST SP 800-171 r2 §3.14.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Scan CUI assets monthly (vulnerability scan) + patch within the SSP-defined SLA; retain the last 12 months of scan reports in the SPRS evidence folder. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 4 | Track, contain, and report incidents (DFARS 252.204-7012(c) 72-hour DIBNet window) | IR.L2-3.6.2 | NIST SP 800-171 r2 §3.6.2 + DFARS 252.204-7012(c) | Write and run an incident playbook carrying the DFARS 7012(c) 72-hour DIBNet escalation; tabletop-test once per year. | DFARS 252.204-7012 (acq.osd.mil) | Analyze my org → |
| 5 | Disable accounts when no longer needed | AC.L2-3.1.5 | NIST SP 800-171 r2 §3.1.5 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Tie account lifecycle to HR offboarding; auto-disable accounts after 30 days of inactivity, archive after 90 days. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 6 | Create and retain audit logs sufficient for after-the-fact investigation | AU.L2-3.3.1 | NIST SP 800-171 r2 §3.3.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Enable OS and authentication logs on every CUI asset; ship to a central syslog with 12-month retention. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 7 | Establish and maintain baseline configurations | CM.L2-3.4.1 | NIST SP 800-171 r2 §3.4.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Capture an image of one hardened CUI workstation, diff real assets against it monthly, and store deviations in SSP §10. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 8 | Periodically assess the risk to organizational operations (assets, individuals, other organizations, the Nation) | RA.L2-3.11.1 | NIST SP 800-171 r2 §3.11.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | Run a written risk assessment annually mapped to the 14 CMMC families; refresh the SPRS posting within the 12-month DFARS 252.204-7012(b) window. | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
Nine artifacts a DoD assessor or C3PAO expects at assessment, each pinned to a NIST SP 800-171 r2 §x.y.z control ID and the 32 CFR 170 / DFARS 7012 paragraph that gates it. Linked into /cmmc-readiness for a contractor-specific analysis.
| # | Artifact | Control (NIST 800-171 r2) | What DoD assessors expect | Citation | Primary source | Analyze |
|---|---|---|---|---|---|---|
| 1 | Authoritative CUI-enclave account list (SSP §9-attached CSV / IAM export) | AC.L2-3.1.1 | A DoD assessor expects an exhaustive account roster that ties each entry to a current CUI-enclave role; rows that are stale or missing will trigger an audit finding under 32 CFR 170.16. | NIST SP 800-171 r2 §3.1.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 2 | MFA configuration evidence on every privileged and network-access path | IA.L2-3.5.3 | A C3PAO expects a screenshot or vendor export per privileged account showing a second factor enforced at the IAM tier — not a policy matrix, the actual configuration. | NIST SP 800-171 r2 §3.5.3 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 3 | Central log retention evidence (12-month) sourced from every CUI asset | AU.L2-3.3.1 | A DoD assessor expects syslog forwarding config + 12 months of retained authentication / OS-event logs against the SSP-defined retention rules; gaps in the retention window count as deficiencies in 32 CFR 170.16. | NIST SP 800-171 r2 §3.3.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 4 | Baseline image artifact of one hardened CUI workstation (SSP §10 attachment) | CM.L2-3.4.1 | A C3PAO expects a captured baseline + the diff tooling used to compare real assets against it monthly; tying the baseline to the SSP §10 narrative is the cite the assessor will reference. | NIST SP 800-171 r2 §3.4.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 5 | Incident-response playbook with the DFARS 7012(c) 72-hour DIBNet escalation | IR.L2-3.6.2 | An assessor expects a written playbook naming the DIBNet reporting sequence, the 72-hour clock start, the legal-collection step, and a tabletop-test record from the last 12 months. | NIST SP 800-171 r2 §3.6.2 + DFARS 252.204-7012(c) | DFARS 252.204-7012 (acq.osd.mil) | Analyze my org → |
| 6 | Media sanitization / transfer record for CUI-bearing media in scope | MP.L2-3.8.3 | A C3PAO expects a sanitization log per media device (sanitize, purge, destroy) per NIST SP 800-88 r1 + a transfer log for media moved between assets; missing records are a 32 CFR 170.16 audit finding. | NIST SP 800-171 r2 §3.8.3 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 7 | Personnel-screening record tying each CUI-enclave user to a screening result | PS.L2-3.9.2 | A DoD assessor expects a screening log per user (verification + period rescreening per the SSP) that ties into the account-roster at AC.L2-3.1.1; missing screening or a stale record is a 32 CFR 170.16 finding. | NIST SP 800-171 r2 §3.9.2 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 8 | Annual risk-assessment artifact mapped to the 14 CMMC families + current SPRS score | RA.L2-3.11.1 | A C3PAO expects the current SPRS score (refreshed within the 12-month DFARS 7012(b) window) + a written risk assessment traceable to NIST SP 800-30 / 800-39; an expired SPRS posting or a missing risk narrative is a 32 CFR 170.16 finding. | NIST SP 800-171 r2 §3.11.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
| 9 | Vulnerability-scan log + the artifact-patch SLA from the SSP §10 narrative | SI.L2-3.14.1 | A C3PAO expects the last 12 months of monthly scan reports against the SSP-defined SLA + a patch-cadence log; unpatched critical findings or a missing SLA are a 32 CFR 170.16 finding. | NIST SP 800-171 r2 §3.14.1 (32 CFR 170.14(c)(2) controls-mapping for CMMC Level 2) | NIST SP 800-171 r2 (csrc.nist.gov) | Analyze my org → |
Each row links into /cmmc-readiness for a contractor-specific analysis of your evidence readiness; the full remediation backlog comes back in the $199 Pack.
Sourced from primary cited documents — not invented.
Single $199 channel — 30-day refund window on technical failures (see FAQ). Stripe is the authorized PCI-DSS payment processor and ComplianceStack never sees card details.
The Pack is keyed to your free CMMC Phase 2 readiness snapshot (or the standard 110-control baseline) and includes all primary-source citations. Delivered by email in under 30 minutes — from compliancestack@polsia.app.
The HTML + PDF deliverable is structured for a DoD contracting officer or Cyber AB C3PAO. Use as the foundation for a Conditional POA&M closeout, the 90-day readiness roadmap, or the C3PAO Level 2 pre-read package.
A packaged deliverable, not an engagement. Calendar-margin friendly, audit-defensible, no multi-week onboarding.
| What’s inside | $5K+ Consultant | $199 ComplianceStack Pack |
|---|---|---|
| 32 CFR Part 170 phased rollout mapping | ✓ | ✓ |
| All 110 NIST SP 800-171 Rev 2 controls | ✓ | ✓ |
| NIST SP 800-172 (Level 3) integration | ✓ | ✓ |
| DFARS 252.204-7012 §(b)–§(g) mapping | ✓ | ✓ |
| FAR 52.204-21 Level 1 baseline | ✓ | ✓ |
| Prioritized remediation backlog with owners | ✓ | ✓ |
| C3PAO-ready evidence checklist | ✓ | ✓ |
| HTML + PDF exportable report | — | ✓ |
| Delivered in 30 minutes, not 8 weeks | — | ✓ |
| Single payment, no hourly invoicing | — | ✓ |
Get the C3PAO-ready remediation backlog, evidence checklist, and exportable report now — keyed to your CMMC Level and the controlling clause set.
Get The Evidence-Ready Pack — $199✓ 30-min delivery · No account · Secured by Stripe
Need a free readiness check first?
Free CMMC Phase 2 Readiness Analyzer →