The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base
CMMC versus NIST SP 800-171 decision framework showing the relationship between the controls, DFARS clause, and CMMC Level 2

ComplianceForge CMMC Guide: What You Get, What It Costs, and What It Won't Do

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

ComplianceForge's core CMMC product is an editable documentation package — not software or a formal assessment. The NIST 800-171 Compliance Program (NCP) lists at $5,200, with no refunds after fulfillment. It can accelerate a Level 2 documentation gap; it does not implement controls, create evidence, set your CMMC level, or establish CMMC status.

Looking for a ComplianceForge CMMC review? We read the price pages, license, FAQ, release notes, and public SSP sample, then checked the consequential claims against the current CMMC rule. The sample has a useful per-requirement structure. But it also contains old identifiers and at least one objective mismatch, and the license has conditions most buyers need to see before fulfillment. Here's all of it, including four checks to make if you've already bought the kit.

Status, checked September 24, 2026: The Department of War (DoW) continues to show CMMC Phase II as suspended, with Phase I self-assessment requirements still in force. The official DARS index lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. The July 13 implementation memo allows new requirements to use Level 1 (Self) or Level 2 (Self) and directs suspended Level 2 (C3PAO) and Level 3 requirements to be removed or revised in affected solicitations and contracts. NIST SP 800-171 Rev. 2 and DFARS 252.204-7012 remain in force. No replacement Phase II date appeared on the current public CMMC page when we checked. See what the suspension changed →

Is this page for you? Three quick checks.

  1. Does your solicitation, contract, subcontract, or prime flow-down require CMMC Level 2 (Self), or include DFARS 252.204-7012 for systems that handle covered defense information?
  2. Do you receive drawings, specifications, or other data marked or otherwise identified as Controlled Unclassified Information (CUI)?
  3. Does someone on your team know your network well enough to describe it on paper?

Yes to all three? Keep reading. You're close to the buyer profile: a contractor with a Level 2 documentation gap and someone who can tailor the files to the real environment.

Yes to the first two, but no to the third? Templates will stall without someone who knows your systems. Read the section below on when templates are the wrong kind of help.

No to the first two? Don't assume you need Level 2 — or CMMC at all — from a generic checklist. If your written requirement is Level 1 and you handle only Federal Contract Information (FCI), start with our Level 1 self-assessment checklist. Just want free starting formats? Try our SSP template guide and policy template guide.


What does ComplianceForge sell for CMMC, and what does it cost?

ComplianceForge's main CMMC kit, the NIST 800-171 Compliance Program (NCP), lists at $5,200 and includes a year of updates. After that, updates are optional at $950 per 12 months. A Level 1 bundle lists at $3,000, and broader NIST 800-53 or Secure Controls Framework bundles run from $10,530 to $25,583 — all company-published list prices checked September 24, 2026.

NIST is the National Institute of Standards and Technology. Its Special Publication (SP) 800-171 Revision 2 contains the 110 security requirements incorporated into CMMC Level 2. SP 800-53 is NIST's much larger federal control catalog. Buying more 800-53 or Secure Controls Framework content does not give you a higher CMMC status.

Product — What's in it, as ComplianceForge describes it — List price — Updates — Best fit to evaluate
ProductWhat's in it, as ComplianceForge describes itList priceUpdatesBest fit to evaluate
NIST 800-171 Compliance Program (NCP)Policies and standards, procedures, SSP template, POA&M template, third-party risk program, supply-chain risk plan, risk and threat catalogs, an evidence request list, incident response plan, and continuity templates. Ships in Rev. 2-only, Rev. 3-only, and combined versions.$5,200First year includedA focused NIST SP 800-171 Rev. 2 documentation gap with an internal owner who can tailor it
NIST 800-171 SSP TemplateAn SSP modeled on Federal Risk and Authorization Management Program (FedRAMP) formats, covering the 800-171 requirements, plus a POA&M spreadsheet$950First year includedBuyers who already have usable policies and procedures
CMMC Bundle 1Two products: policies, standards, and procedures for the 15 Level 1 safeguards$3,000Ask before buyingAn FCI-only company that wants a finished written program rather than free starting templates
CMMC Bundle 2Five products built on NIST SP 800-53 low and moderate baselines$10,530Ask before buyingOrganizations that separately need broader 800-53 coverage — not a higher CMMC status
CMMC Bundle 3Thirteen products built on NIST SP 800-53 through the high baseline$23,208Ask before buyingOrganizations that separately need 800-53 high coverage — not a shortcut to CMMC Level 3
CMMC Bundle 4Thirteen products built on the Secure Controls Framework (SCF)$25,583Ask before buyingMulti-framework programs already using SCF — not a shortcut to CMMC Level 3
NCP update subscriptionAbout four releases a year, each with release notes. Does not auto-renew.$950 per 12 months—Keeping an eligible NCP purchase current
Professional servicesSeparate hours to help tailor documents you bought$1,350 (5 hrs) · $2,550 (10 hrs) · $4,800 (20 hrs)Hours expire 120 days after purchaseTailoring help, not implementation or a formal assessment

What three years really costs. For the NCP with optional continuous updates: $5,200 + $950 + $950 = $7,100. That is the documentation subtotal only. It assumes the price and renewal eligibility do not change. Your staff's time, security tools, implementation, recurring services, taxes, and any assessment are separate costs. The tailoring packages work out to $270, $255, or $240 an hour.

A bigger bundle isn't a higher CMMC level. Bundle numbers track how much framework content you are buying, not which CMMC status you need. ComplianceForge's own FAQ calls Bundle 2 "generally overkill" for companies that only need CMMC and NIST 800-171 (ComplianceForge FAQ).

About the savings claims. ComplianceForge says the NCP can replace about 900 hours of internal work or 800 hours of consultant work, which it values at $84,500 and $222,000 (NCP page). The public product page does not show the wage and consultant-rate assumptions behind those dollar figures or independent validation, and we could not test the result.

Whether a template kit is the right buy isn't the same for every contractor. The help you need — a Registered Practitioner (RP) or Registered Practitioner Organization (RPO) to guide scoping and your SSP, a managed service provider (MSP) or managed security service provider (MSSP) to put controls in place, a governance, risk, and compliance (GRC) platform to track evidence, or a CUI enclave to confine CUI work and potentially reduce scope when it is genuinely separated — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT setup, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit before you buy templates or request quotes — and do not submit CUI, drawings, or sensitive contract details.


Will ComplianceForge get you through CMMC? What the kit covers — and what's still on you

No template gets anyone through CMMC on its own. CMMC assessment procedures use three methods — examine, interview, and test. In a self-assessment, your organization performs that work; in a certification assessment, an authorized assessment team does. Only the documents come in the box.

That's the rule, not our opinion. CMMC Level 2 uses the June 2018 NIST SP 800-171A assessment procedures and their examine, interview, and test methods (32 CFR 170.14(d)). Final Level 2 (Self) status requires every security requirement to be MET; Conditional status is available only under the separate POA&M rules (32 CFR 170.16). Here's how the kit's pieces line up with what has to be true at your company.

Kit piece — What ComplianceForge gives you — What still has to be true at your company — The rule behind it
Kit pieceWhat ComplianceForge gives youWhat still has to be true at your companyThe rule behind it
Policies and standardsWritten for 800-171. The company says policies are ready to adopt and standards are about 90–95% complete.You set your own values, approve them, and follow them.NIST SP 800-171 Rev. 2, all 14 families
ProceduresThe company says they are about 75–80% complete.Each one matches how your team actually works, with a named owner who can explain and demonstrate it.SP 800-171A interview and test methods
SSPA per-requirement template with prompts for owner, frequency, technology, and assessment objectivesIt describes your real boundary, systems, environment of operation, implementation, and connections. The SSP must exist at assessment, and CA.L2-3.12.4 cannot be deferred on a Level 2 POA&M.SP 800-171 Rev. 2, 3.12.4; 32 CFR 170.24; 170.21(a)(2)(iii)(C)
Access control policyWritten rulesAccess is limited to authorized users, processes acting for authorized users, and devices — and you can show how access is granted, changed, and removed.SP 800-171 Rev. 2, 3.1.1
Authentication procedureWritten rulesMultifactor authentication (MFA) is operating for local and network access to privileged accounts and for network access to nonprivileged accounts. IA.L2-3.5.3 carries a three- or five-point deduction under the scoring rule, so it is not eligible for a Level 2 POA&M.SP 800-171 Rev. 2, 3.5.3; 170.24; 170.21; our MFA guidance
Incident response planA templateYou have tested the incident-response capability and can support the applicable assessment objectives with real records.SP 800-171 Rev. 2, 3.6.3; our incident response guide
POA&M templateA tracking spreadsheetOnly eligible gaps go on it: at least 88 of 110 points; generally only one-point requirements; the narrow SC.L2-3.13.11 encryption condition; six listed requirements never; and closeout within 180 days.32 CFR 170.21; our POA&M closeout guide
Evidence request listA list of what to gatherThe actual records exist. Depending on the objective, examples can include logs, tickets, configurations, training records, or demonstrations; the filename alone is not the evidence.32 CFR 170.14(d); our assessment evidence guide
ScopingA free scoping guide, plus SSP sections for the boundary and diagramsYou have determined where CUI is processed, stored, and transmitted, classified in-scope assets, and documented the boundary and external-service relationships.32 CFR 170.19; our scoping guide
CMMC result and SPRSNot includedYou perform the applicable assessment, calculate the result under the CMMC scoring methodology, and enter the required result in the Supplier Performance Risk System (SPRS).32 CFR 170.16; 170.24; our SPRS guide
AffirmationNot includedYour internal Affirming Official submits the affirmation with Conditional or Final status, after POA&M closeout where applicable, and annually after Final status.32 CFR 170.22; our affirmation guide

Think of the kit as a good set of house plans. Plans save you time. But an inspector doesn't pass a house because the plans are neat. The inspector walks the rooms, asks the builders questions, and flips the switches.

The same goes for paperwork. A written procedure isn't proof it happened. An incident response plan and the record of the last completed test answer two different questions — and the assessment can examine both.

If this table showed gaps the kit can't fill — scoping, MFA, evidence — the next question is what kind of help fills them. That depends on your contract and your systems, not on the kit.

See which kind of help your gaps call for →

What a fair ComplianceForge CMMC review has to check: the kit vs. the rule

The public product descriptions and SSP sample broadly track the CMMC documentation job. But several statements on the product pages, and several details in the dated public sample, do not match the current rule text. None proves the current paid release is unusable. Each is something to resolve yourself or ask about before you buy.

Everything in the left column was checked on ComplianceForge's site or in its public SSP sample on September 24, 2026. Findings about the sample apply to that public file, which may predate the current paid release.

What ComplianceForge says or the public sample shows — What the rule or official source says — What to do
What ComplianceForge says or the public sample showsWhat the rule or official source saysWhat to do
Product pages say federal policy requires the newest NIST version within a year, so Rev. 3 "will be expected" for contracts and Rev. 2 will be "deprecated" (bundles page, NCP page).CMMC Level 2 remains built on Rev. 2 (32 CFR 170.14(a)(2)). The current suspension direction also keeps baseline Rev. 2 compliance under DFARS 252.204-7012. To be fair, ComplianceForge's own current FAQ describes Level 2 as the 110 Rev. 2 requirements.Use the Rev. 2 mapping for the CMMC Level 2 baseline. Choose the combined version only if a separate contract, customer, or transition plan justifies Rev. 3 work too.
The NCP page says its policies cover "the 17 sections of CMMC 2.0."CMMC domains map to the requirement families in NIST SP 800-171 Rev. 2 (170.14(b)). Rev. 2 has 14 families.Organize the CMMC Level 2 baseline around the 14 Rev. 2 families.
The NCP page says that if you store, transmit, or process CUI, "you are CMMC v2.0 Level 2."CUI handling is the reason Level 2 is the relevant CMMC level, but the solicitation, contract clause, or valid subcontract flow-down sets the status and assessment type for the procurement. Under the current suspension, new requirements may use Level 1 (Self) or Level 2 (Self); a generic vendor statement cannot set either.Read the actual provision, clause, and flow-down before choosing a product. The next section shows where to look.
The FAQ says the NCP "contains all the policies, standards, procedures, SSP/POA&M and other templates that you will need to pass a CMMC assessment" (FAQ).That can describe the template categories. It cannot describe the full assessment job. CMMC uses examine, interview, and test methods (170.14(d)), and Final Level 2 (Self) requires every requirement MET (170.16).Budget for implementation, operation, evidence, and assessment effort — not only documents.
The documentation is described as "DIBCAC battle tested" and used in successful assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) and CMMC Third-Party Assessment Organizations (C3PAOs).That is company-stated, and we could not independently verify it. We found no CMMC document-template approval category in the current CMMC rule or Cyber AB Marketplace, and no official template approval was shown in the sources we checked. NIST says there is no prescribed SSP format as long as the required information is conveyed.Ask for the specific scope behind the statement. It is question k in the worksheet below.
The public SSP sample labels requirements like AC.L1-3.1.1, AC.L1-3.1.20, PE.L1-3.10.3, and RM.L2-3.11.1 (sample).The rule's identifiers follow the pattern DD.L#-REQ. Level 2 uses AC.L2 for the 3.1 requirements, PE.L2 for 3.10, and RA.L2 for 3.11 (170.14(c)(1)). The POA&M and scoring rules use those identifiers. ComplianceForge's release notes say it updated Level 1 numbering in release 2025.4.1.Ask for a sample from the exact release you will receive. Check every identifier before relying on the file.
The public SSP sample asks for a "DUNS #."The government replaced DUNS numbers with the Unique Entity ID (UEI) on April 4, 2022 (GSA).Use your UEI and your Commercial and Government Entity (CAGE) code where those identifiers belong.
The public POA&M sample link was present on the product materials, but its PDF could not be re-fetched during this final audit.Conditional Level 2 status still requires the current rule's score, eligibility, exclusion, and 180-day closeout logic (170.21).Before buying, request the POA&M sample from the release you will receive and verify fields for CMMC ID, point value, eligibility and reason, conditional-status date, owner, and closeout deadline.
In the public SSP sample, the entry labeled requirement 3.1.1 lists the assessment objectives for 3.1.3.Each requirement has its own objectives in NIST SP 800-171A (June 2018). Requirement 3.1.1 has three objectives; 3.1.3 has five different objectives.Walk every objective line in the current release against the June 2018 SP 800-171A mapping used by CMMC.

Which version should you use: Rev. 2 or Rev. 3?

For the CMMC Level 2 baseline today, work from the NCP's Rev. 2 mapping. The NCP ships three versions — Rev. 2 only, Rev. 3 only, and combined — and the CMMC rule still points to Rev. 2.

Here's where the confusion comes from. NIST published Rev. 3 in May 2024 and now labels Rev. 2 and the June 2018 SP 800-171A as withdrawn or superseded on its publication pages. That's NIST's publication lifecycle. It does not, by itself, rewrite the standard incorporated into your CMMC requirement.

The CMMC rule names Rev. 2 and the June 2018 assessment guide directly (32 CFR 170.14(a)(2) and (d)). The standing DFARS Rev. 2 deviation and the current CMMC suspension direction keep NIST SP 800-171 Rev. 2 as the baseline under DFARS 252.204-7012. DoW's current CMMC page says Rev. 2 is what it is enforcing through self-assessments and select government-led assessments.

Rev. 3 content can be useful for a separate transition plan or customer requirement. It is not the CMMC Level 2 scoring baseline today. Our Rev. 2 vs. Rev. 3 guide covers the differences.

What the public SSP sample shows

The public SSP sample has a useful structure for CMMC. For each requirement, it asks who owns it, who operates it, how often it occurs, which technology supports it, and how the listed assessment objectives are addressed. The problems are labels and fields that have gone stale and at least one objective mismatch — and the public sample may be older than the version a buyer receives.

What's useful about it:

  • The implementation-status choices include "implemented externally via contract and/or shared responsibility." That is useful when an MSP or cloud provider operates part of a requirement.
  • The requirement sections include owner, operator, occurrence, technology, implementation-status, and assessment-objective prompts.
  • It includes sections for the system boundary, network and data-flow diagrams, roles, vendors, and hardware and software inventory.

The weak spots are the ones in the table above: old requirement identifiers, a DUNS field, and a 3.1.1 section containing 3.1.3 objectives. We could not re-fetch the public POA&M PDF in this final audit, so we do not say the current POA&M template lacks any particular field.

We reviewed the public SSP sample ComplianceForge links from its product materials on September 24, 2026. We did not buy the kit, so we cannot tell you which public-sample issues the current paid release has already fixed.

Already bought it? Four checks

Start by checking your release number against ComplianceForge's release notes. A newer release may already fix some of these. Then:

  1. Match every requirement identifier to 32 CFR 170.14, 170.21, and 170.24. For example, use AC.L2-3.1.20 for a Level 2 requirement, not AC.L1-3.1.20.
  2. Replace DUNS with your UEI, and keep your CAGE code where the record calls for it.
  3. Inspect the current POA&M before relying on it. Add fields for CMMC ID, point value, eligibility and reason, conditional-status date, owner, and closeout deadline if the release you received does not already contain them.
  4. Walk every objective line against NIST SP 800-171A (June 2018), the assessment procedures named in 32 CFR 170.14(d).

What we verified (September 24, 2026): ComplianceForge's CMMC product, bundle, update, professional-services, FAQ, delivery, and Terms & Conditions pages; the public SSP sample; the Cyber AB's SCF Marketplace; 32 CFR 170.8, 170.14, 170.16, 170.19, 170.21, 170.22, and 170.24; DFARS 252.204-7012, 252.204-7021, and 252.204-7025; the official DARS index entry for Class Deviation 2026-O0025, Revision 3; DoW's current CMMC page and July 13 suspension materials; NIST's SP 800-171 Rev. 2 and SP 800-171A publication pages and text; and GSA's UEI notice. What we did not do: buy or test the paid kit, verify the current paid SSP or POA&M release, independently confirm the "battle tested" statement, verify a customer outcome, establish a company-specific CMMC Marketplace role through the catalog interface, or rely on language unique to the Revision 3 PDF, which did not render during the final pass. The public POA&M sample also could not be re-fetched in this final audit. Our Editorial & Advertising Policy explains how we handle commercial relationships.


Which ComplianceForge kit fits your situation — if any?

For a small contractor with a confirmed Level 2 (Self) documentation gap, the NCP is ComplianceForge's most directly targeted package. The broader bundles add 800-53 or Secure Controls Framework material; they do not confer Level 3 or make a Level 2 requirement more complete. If you handle only FCI, you may not need a paid kit at all.

If you are… — Consider — Watch out for
If you are…ConsiderWatch out for
FCI only, with a written Level 1 requirementFree first: the 15 safeguards and our Level 1 checklist. Consider Bundle 1 ($3,000) only if you want a finished written program.Level 1 permits no POA&M, and the self-assessment is annual (32 CFR 170.15; 170.21(a)(1)). Written policies are not a substitute for all 15 safeguards being MET.
CUI, Level 2 (Self), one environment, and someone who can edit documentsNCP ($5,200), using the Rev. 2 mapping for CMMCTailoring, implementation, operation, evidence, assessment, and affirmation are still your work.
You already have usable policies and need an SSP and POA&M starting pointSSP template ($950, with a POA&M listed as included)Ask for release-matched samples and check the current rule identifiers, objectives, and POA&M fields.
You already run NIST SP 800-53 programs for FedRAMP or similar workBundle 2 ($10,530), if its broader content matches that separate needComplianceForge itself calls it "generally overkill" for a CMMC-only buyer.
You separately need 800-53 high or a multi-framework SCF programCompare Bundles 3 and 4 against that independent requirementDo not buy either merely because CMMC Level 3 could return. Level 3 is not the same as 800-53 high or an SCF bundle.
You are an MSP serving several contractorsConfirm licensing separately for each client and legal entityOne license is for one legal entity. Do not assume that one client's licensed copy can become a reusable client library.
You want someone to write it with youAn RP/RPO or other qualified consultant; ComplianceForge's separate tailoring hours may also helpComplianceForge's hours expire after 120 days, and only your organization can supply the facts about its environment.
Your CUI is confined to a managed enclave or government cloudGet the provider's SSP inputs and shared responsibility matrix before choosing the packageA smaller boundary can change which parts of your enterprise are assessed, but it does not eliminate your documentation, customer responsibilities, connections, people, or external providers.

No web page — including this one — can tell you your required CMMC status without the procurement documents. Your solicitation, contract, subcontract, or valid prime flow-down does. Here's where to look.

Open the document and search for: 252.204-7025, 252.204-7021, 252.204-7012, 252.240-7997, 252.204-7020, 52.240-93, 52.204-21, and CMMC.

  • DFARS 252.204-7025 or 252.204-7021: the provision or clause states the required CMMC level and assessment type. Under the current suspension, affected Level 2 (C3PAO) or Level 3 language should be removed or revised; do not assume it changed until you have the amendment or modification.
  • FAR 52.240-93 or FAR 52.204-21: newer DoW solicitations using the Part 40 deviation may use 52.240-93, while older instruments may still cite 52.204-21. Both are basic-safeguarding clauses for covered contractor information systems containing FCI in their respective versions; neither, by itself, proves that a CMMC Level 1 status was inserted into your procurement.
  • DFARS 252.204-7012: this is the safeguarding and cyber-incident-reporting clause for covered defense information. It carries the Rev. 2 security duty but does not, by itself, select your CMMC assessment type.
  • DFARS 252.240-7997 or older 252.204-7020: read whichever clause is actually incorporated for government NIST SP 800-171 assessment and access terms. Neither is the provision that selects your CMMC level.
  • A prime's letter or flow-down that just says "Level 2": ask in writing whether the requirement is Level 2 (Self) or Level 2 (C3PAO), and ask for the clause or flow-down language. Under the current suspension, new requirements may use Level 2 (Self), not a new C3PAO designation.

Our guides to CMMC levels and FCI vs. CUI walk through the edge cases.

Still can't tell which level or assessment type your paperwork points to? Settle that before you buy any kit.

See which assessment path your contract points to →

What do ComplianceForge's license terms mean for you?

The terms are stricter than many buyers will expect. There are no refunds after the files are fulfilled, one license covers one legal entity, and you need a signed nondisclosure agreement (NDA) before disclosing the documents to a third party — including, in ComplianceForge's own example, an auditor.

All rows below come from ComplianceForge's Terms & Conditions, last updated July 1, 2026.

Term — What it means in plain English — Why it matters for CMMC
TermWhat it means in plain EnglishWhy it matters for CMMC
No refunds, cancellations, or exchanges after fulfillment (§5)You can cancel only before the files are sent.Review the public sample and resolve product and license questions before fulfillment.
A perpetual, nontransferable, nonsublicensable license for one legal entity (§8)A separately incorporated parent, subsidiary, sister company, or client is a different legal entity under the text.Confirm the licensed entity and every intended user before sharing.
No disclosure to a third party without a signed NDA (§7)Anyone outside the licensed entity needs the required NDA before seeing the documents. The company's example includes auditors.Primes may ask for SSP information, assessors examine documents, and MSPs or consultants may help edit them. Check the required sharing process first. See our guide to a prime asking for an SSP or SPRS information.
No uploading to artificial intelligence (AI) or large language model (LLM) tools where the content could train the model (§7)This is not written as a ban on every AI-assisted workflow. The restriction turns on whether the content could be used for training.Get the permitted workflow in writing, check the tool's data terms, and never paste CUI or sensitive environment details into an unapproved tool.
No derivative works to sell or share (§7)A consultant or MSP cannot turn one licensed copy into a reusable library for other clients.Confirm licensing for every legal entity; do not assume per-client reuse rights.
No warranty; liability capped at the amount paid (§§9–10)The terms disclaim warranties and limit the company's exposure.Validate identifiers, mappings, and company-specific content before relying on them.
The license ends if you breach it, and copies must be erased within seven days after termination (§8)A breach can create an operational problem when your own SSP is built from licensed text.Keep the license terms with the purchase record and control who can copy or share the files.
Wyoming law, with arbitration at ComplianceForge's option (§§13–14)The terms select Wyoming law and give the company the stated arbitration option.Know the dispute terms before a purchase you cannot refund after fulfillment.
The company describes its products as commercial off-the-shelf (COTS) items and says the purchase involves no FCI or CUI (§8)Buying the standard files should not require sending contract data or CUI.Do not send CUI during purchase or tailoring unless a separately approved, contractually authorized secure process exists.

One more catch sits on the update page. It says the subscription is for customers "who have not skipped one or more years," and also that "re-subscribing later is always possible" (subscription page). Get the applicable price and eligibility in writing before you let updates lapse.


Is ComplianceForge legit — and is it approved by DoD or the Cyber AB?

ComplianceForge is a long-running documentation publisher with public prices, public terms, and public samples. We found no CMMC document-template approval category in the current CMMC rule or Cyber AB Marketplace. The Cyber AB entries we verified for ComplianceForge are in a separate program built around the Secure Controls Framework, not an approval of its CMMC documents.

Question — Answer — Source
QuestionAnswerSource
What is it?Compliance Forge, LLC, a documentation publisher based in Sheridan, Wyoming. It says it is a Veteran-Owned Small Business that has written security documentation since 2005 and NIST 800-171 templates since 2016.Company site (company-stated)
Did this audit establish a CMMC C3PAO or RPO role?No company-specific CMMC Marketplace role was established through the catalog interface in this audit. The products reviewed here are documentation and separate tailoring hours, not a formal assessment. Verify any claimed CMMC role in the CMMC Marketplace rather than inferring it from the SCF entries.Cyber AB CMMC Marketplace; company product pages
Is the NCP software?No. The core product is delivered as editable Word, Excel, and PowerPoint files by email download link. There is nothing to install.NCP page
Who is behind it?Senior partner Tom Cornelius also founded the Secure Controls Framework, a free control catalog mapped to many laws and frameworks.ComplianceForge; SCF Council
What Cyber AB entries were verified?In the Cyber AB's SCF Marketplace, ComplianceForge appears under SCF Registered Provider Organization and SCF Licensed Content Provider, checked September 24, 2026. Those are SCF roles, not CMMC roles. An SCF Registered Provider Organization is not the same designation as a CMMC Registered Practitioner Organization.SCF Marketplace; listing
Why does the Cyber AB appear in the SCF context?In December 2024, the SCF Council named the Cyber AB as the accreditation body for its separate SCF certification program. That does not endorse a document package for CMMC.Cyber AB announcement
Who helps implement it?ComplianceForge lists partner firms that tailor its documents. We have not evaluated those firms or their work.Partners page

If you hire CMMC-specific help, check the exact organization and current role in the Cyber AB's CMMC Marketplace — the CMMC catalog, not the SCF Marketplace. Our Marketplace guide shows what each status does and does not establish.


Before you order: a purchase-approval worksheet

A good purchase request names the gap, the licensed company, the questions still open, and the people who will finish the work. Copy this brief into your own approved files, fill it in, and hand it to whoever signs off. Leave anything you do not know marked unknown — never zero, "no," or compliant by default.

COMPLIANCEFORGE PURCHASE BRIEF — PRIVATE WORKING COPY
Do not put CUI, drawings, contract text, or sensitive system details in this brief.

Date:                               Prepared by:
Approver:                           Legal entity that will hold the license:

1. WHAT DOES OUR CONTRACT REQUIRE?
   CMMC level and assessment type:  [ Level 1 (Self) / Level 2 (Self) /
                                      Level 2 (C3PAO) / unknown ]
   Where we found it (clause or flow-down reference only):
   Information we handle:           [ FCI only / CUI / both / unknown ]
   If unknown — who confirms it, and by when:

2. WHAT IS OUR ACTUAL GAP?  (check all that apply)
   [ ] Written policies, procedures, SSP, or POA&M
   [ ] Technical controls not yet in place (for example: MFA, encryption, logging)
   [ ] Evidence we cannot produce yet
   [ ] Knowing where CUI lives and what is in scope
   [ ] Unknown — find out before buying anything
   Documents we already have and can keep:

3. WHAT WOULD WE BUY?
   Product and list price on order date:
   CMMC Level 2 baseline mapping:    [ Rev. 2 / combined for a separate need — explain ]
   NCP release number offered (for example, 2026.x):
   Samples we reviewed, and their dates:

4. QUESTIONS WE SENT COMPLIANCEFORGE  (write the answer and date beside each)
   a. Which NCP release will we receive? Can we see the SSP and POA&M
      samples from that exact release?
   b. Does the current SSP use the requirement identifiers in 32 CFR 170.14,
      170.21, and 170.24, and ask for our UEI instead of a DUNS number?
   c. Does the current POA&M track CMMC point values, eligibility and reason
      under 32 CFR 170.21, the Conditional status date, owner, and the
      180-day closeout deadline?
   d. In the version mapped to Rev. 2, is every requirement mapped to the
      NIST SP 800-171A (June 2018) assessment objectives used by CMMC?
   e. Our MSP or consultant will help edit. Does your NDA requirement apply
      to them? Do you provide a standard NDA?
   f. A prime or assessor may ask for our SSP. What must we do before
      sharing licensed content?
   g. May we use an AI tool that is contractually set not to train on our
      inputs to help edit the documents?
   h. We have a parent, subsidiary, or sister company. How many licenses
      do we need?
   i. If we skip a year of updates, can we renew at $950 later, or must we
      repurchase? Which written term controls the answer?
   j. What do professional-services hours cover? Can they review our
      finished SSP before the 120 days expire?
   k. What specifics can you share behind "DIBCAC and C3PAO battle tested"
      (number of assessments, years, levels, and document versions) without
      naming clients?

5. WHO DOES THE REST OF THE WORK?
   Tailors the documents:
   Implements the controls:
   Collects and keeps evidence:
   Checks documents against how we actually operate:
   Performs and records the CMMC self-assessment result in SPRS:
   Affirming Official (Conditional or Final status, POA&M closeout if used,
   and annual affirmation after Final status):

6. WHAT WILL IT COST?  (write "unknown" until you know — never zero)
   Templates, year 1:                         $
   Updates, years 2 and 3 (optional):         $
   Our staff time (hours x rate):
   Outside implementation help:
   Recurring IT or security services:
   Formal assessment (only if a current authoritative requirement calls for one):
   Taxes or other quoted charges:
   Anything counted in two lines (remove the duplicate):

7. DECISION
   [ ] Buy — on these conditions:
   [ ] Hold until these questions are answered:
   [ ] Choose a different kind of help instead
   Next step / owner / date:

This brief records a purchasing decision. It is not a CMMC assessment,
a CMMC status, legal advice, or an SPRS submission.

Before you order: a purchase-approval worksheet

A good purchase request names the gap, the licensed company, the questions still open, and the people who will finish the work. Copy this brief into your own approved files, fill it in, and hand it to whoever signs off. Leave anything you do not know marked unknown — never zero, "no," or compliant by default.

COMPLIANCEFORGE PURCHASE BRIEF — PRIVATE WORKING COPY
Do not put CUI, drawings, contract text, or sensitive system details in this brief.

Date:                               Prepared by:
Approver:                           Legal entity that will hold the license:

1. WHAT DOES OUR CONTRACT REQUIRE?
   CMMC level and assessment type:  [ Level 1 (Self) / Level 2 (Self) /
                                      Level 2 (C3PAO) / unknown ]
   Where we found it (clause or flow-down reference only):
   Information we handle:           [ FCI only / CUI / both / unknown ]
   If unknown — who confirms it, and by when:

2. WHAT IS OUR ACTUAL GAP?  (check all that apply)
   [ ] Written policies, procedures, SSP, or POA&M
   [ ] Technical controls not yet in place (for example: MFA, encryption, logging)
   [ ] Evidence we cannot produce yet
   [ ] Knowing where CUI lives and what is in scope
   [ ] Unknown — find out before buying anything
   Documents we already have and can keep:

3. WHAT WOULD WE BUY?
   Product and list price on order date:
   CMMC Level 2 baseline mapping:    [ Rev. 2 / combined for a separate need — explain ]
   NCP release number offered (for example, 2026.x):
   Samples we reviewed, and their dates:

4. QUESTIONS WE SENT COMPLIANCEFORGE  (write the answer and date beside each)
   a. Which NCP release will we receive? Can we see the SSP and POA&M
      samples from that exact release?
   b. Does the current SSP use the requirement identifiers in 32 CFR 170.14,
      170.21, and 170.24, and ask for our UEI instead of a DUNS number?
   c. Does the current POA&M track CMMC point values, eligibility and reason
      under 32 CFR 170.21, the Conditional status date, owner, and the
      180-day closeout deadline?
   d. In the version mapped to Rev. 2, is every requirement mapped to the
      NIST SP 800-171A (June 2018) assessment objectives used by CMMC?
   e. Our MSP or consultant will help edit. Does your NDA requirement apply
      to them? Do you provide a standard NDA?
   f. A prime or assessor may ask for our SSP. What must we do before
      sharing licensed content?
   g. May we use an AI tool that is contractually set not to train on our
      inputs to help edit the documents?
   h. We have a parent, subsidiary, or sister company. How many licenses
      do we need?
   i. If we skip a year of updates, can we renew at $950 later, or must we
      repurchase? Which written term controls the answer?
   j. What do professional-services hours cover? Can they review our
      finished SSP before the 120 days expire?
   k. What specifics can you share behind "DIBCAC and C3PAO battle tested"
      (number of assessments, years, levels, and document versions) without
      naming clients?

5. WHO DOES THE REST OF THE WORK?
   Tailors the documents:
   Implements the controls:
   Collects and keeps evidence:
   Checks documents against how we actually operate:
   Performs and records the CMMC self-assessment result in SPRS:
   Affirming Official (Conditional or Final status, POA&M closeout if used,
   and annual affirmation after Final status):

6. WHAT WILL IT COST?  (write "unknown" until you know — never zero)
   Templates, year 1:                         $
   Updates, years 2 and 3 (optional):         $
   Our staff time (hours x rate):
   Outside implementation help:
   Recurring IT or security services:
   Formal assessment (only if a current authoritative requirement calls for one):
   Taxes or other quoted charges:
   Anything counted in two lines (remove the duplicate):

7. DECISION
   [ ] Buy — on these conditions:
   [ ] Hold until these questions are answered:
   [ ] Choose a different kind of help instead
   Next step / owner / date:

This brief records a purchasing decision. It is not a CMMC assessment,
a CMMC status, legal advice, or an SPRS submission.

Prices checked September 24, 2026.

References used by the worksheet:

COMPLIANCEFORGEWORKSHEET

Worked example: a hypothetical 40-person machine shop

Say you run a 40-person machine shop. Here's how the worksheet turns "Should we buy ComplianceForge?" into a decision you can defend.

Your prime's subcontract includes DFARS 252.204-7012 and a current Level 2 (Self) requirement. Controlled drawings live on one file server and in engineering email. Your IT lead has a patchwork of old policies. While filling in the worksheet, she finds that MFA is not enabled for remote access to the file server.

The worksheet shows two jobs, not one: writing the documents and fixing MFA. The kit helps with the first. It does nothing for the second — and IA.L2-3.5.3 cannot be carried on a Level 2 POA&M because it carries more than one point under the scoring rule (32 CFR 170.21; 170.24).

Cost line — Amount in this example — What it means
Cost lineAmount in this exampleWhat it means
NCP, year 1 (updates included)$5,200Company list price checked September 24, 2026
Updates, year 2$950Optional
Updates, year 3$950Optional; assumes the price and renewal eligibility do not change
IT lead's time to tailor the documentsUnknownGet her estimate in hours and an internal cost basis. Do not enter zero.
Enabling MFA for the actual remote-access pathUnknownDefine the technical work and get a written internal estimate or quote.
Level 2 (Self) assessmentInternal assessment effortThis written requirement calls for self-assessment, not a C3PAO assessment.
Documentation subtotal, three years$7,100Not the implementation, operating, or total project cost

The decision on the owner's desk: buy the NCP mapped to Rev. 2 once ComplianceForge answers questions a through d in writing. The IT lead owns tailoring. Get the MFA scope and cost now. Perform the self-assessment only after MFA is operating on the required access paths, enter the result in SPRS, and have the designated internal Affirming Official submit the required affirmation.

This shop is fictional. The $5,200 and $950 figures are current company-published list prices used in a hypothetical calculation; none of the unknown amounts is a real result or a typical market cost.


When are templates the wrong kind of help?

Templates fix a writing gap. If your real gap is scoping, operating systems, implementing controls, tracking evidence, or obtaining an assessment, a bigger document set will not close it. Match the help to the missing work.

If the missing work is… — Consider — Check first — Where to learn more
If the missing work is…ConsiderCheck firstWhere to learn more
A starting format for an SSP or POA&MNIST's free CUI SSP and Plan of Action templatesSomeone who can describe the real environment and requirement implementationNIST SP 800-171 Rev. 2 page; our SSP template guide
A coordinated written programA commercial template kit, including ComplianceForge or another publisherCurrent samples, license terms, revision mapping, and who will tailor itThis page
Scoping, gap analysis, or an SSP written with youAn RP/RPO or other appropriately qualified readiness consultantScope of work, deliverables, responsible people, and the exact Cyber AB role claimedRPO consultants; consulting cost
Running IT and security day to dayAn MSP or MSSPWho owns each requirement, how the provider handles CUI or Security Protection Data, and what evidence it will give youMSP guide; MSP pricing
Tracking evidence, owners, and recurring tasksA GRC platformWho will operate it — software organizes work but does not implement controlsGRC software; SSP software
Keeping CUI in a smaller, separated environmentA CUI enclaveActual data flows, integrations, users, connections, external providers, and the customer-responsibility boundaryEnclave providers; enclave cost
Getting started with outside counselingAn APEX AcceleratorWhat the local office actually offers and what remains outside its scopeAPEX Accelerator guide
A formal Level 2 assessment called for by a current solicitation, contract amendment, or other authoritative directionAn authorized C3PAOCurrent authorization, the exact requirement, readiness, scope, and conflicts of interestC3PAO list; provider categories

Keep readiness and assessment separate. Under 32 CFR 170.8(b)(17)(ii)(G), the Cyber AB's Code of Professional Conduct must prohibit CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the preceding three years. Confirm the proposed roles and conflict check in writing.

If you're not sure which of these rows is yours — or you're in more than one — map the missing work before you spend.

Map my CMMC path before I buy →

Questions buyers still ask

Can we keep our existing SSP instead of buying a new one?

Yes, if it describes the real system boundary, environment of operation, how the requirements are implemented, and the connections to other systems. NIST says there is no prescribed SSP format. Fix the specific gaps before replacing a document that already works — our guide on whether your SSP is defensible shows how to check.

Will buying the kit change our SPRS score?

No. A purchase does not change any assessment result. For CMMC Level 2 (Self), you assess implemented requirements under the scoring methodology in 32 CFR 170.24 and enter the required result in SPRS under 170.16. A receipt or a filled-in template does not move that result. Older paperwork may also refer to a separate NIST SP 800-171 DoD Assessment score; read the clause actually incorporated rather than treating the labels as interchangeable.

Does paying for updates replace the annual affirmation?

No. A vendor update and a CMMC affirmation are different events. Under 32 CFR 170.22, your internal Affirming Official submits an affirmation with Conditional or Final status, after POA&M closeout where applicable, and annually after Final status. Buying revised files does none of those things.

Can we pay by purchase order, and how fast do the files arrive?

ComplianceForge's product pages say you can pay by invoice or purchase order, or by wire or Automated Clearing House (ACH) bank transfer using the invoice. The company says files arrive by email download link within one to two business days, with your company name — and logo, if supplied — added.

Will ComplianceForge write our SSP for us?

Not as part of the document purchase. Its separate tailoring packages provide 5, 10, or 20 hours and expire 120 days after purchase. ComplianceForge says those hours supplement your own work because only your organization knows its environment. If you need the SSP developed with you, define that as a separate readiness-consulting scope and name who will validate the finished document against operations.


Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.


Sources

All sources checked September 24, 2026 unless another date is stated.

Rules, clauses, and official sources

ComplianceForge pages — company-stated product, price, and term information


About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, the Department of Defense (DoD), the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC), NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.

Map my CMMC path →