ComplianceForge CMMC Guide: What You Get, What It Costs, and What It Won't Do
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
ComplianceForge's core CMMC product is an editable documentation package — not software or a formal assessment. The NIST 800-171 Compliance Program (NCP) lists at $5,200, with no refunds after fulfillment. It can accelerate a Level 2 documentation gap; it does not implement controls, create evidence, set your CMMC level, or establish CMMC status.
Looking for a ComplianceForge CMMC review? We read the price pages, license, FAQ, release notes, and public SSP sample, then checked the consequential claims against the current CMMC rule. The sample has a useful per-requirement structure. But it also contains old identifiers and at least one objective mismatch, and the license has conditions most buyers need to see before fulfillment. Here's all of it, including four checks to make if you've already bought the kit.
Status, checked September 24, 2026: The Department of War (DoW) continues to show CMMC Phase II as suspended, with Phase I self-assessment requirements still in force. The official DARS index lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. The July 13 implementation memo allows new requirements to use Level 1 (Self) or Level 2 (Self) and directs suspended Level 2 (C3PAO) and Level 3 requirements to be removed or revised in affected solicitations and contracts. NIST SP 800-171 Rev. 2 and DFARS 252.204-7012 remain in force. No replacement Phase II date appeared on the current public CMMC page when we checked. See what the suspension changed →
Is this page for you? Three quick checks.
- Does your solicitation, contract, subcontract, or prime flow-down require CMMC Level 2 (Self), or include DFARS 252.204-7012 for systems that handle covered defense information?
- Do you receive drawings, specifications, or other data marked or otherwise identified as Controlled Unclassified Information (CUI)?
- Does someone on your team know your network well enough to describe it on paper?
Yes to all three? Keep reading. You're close to the buyer profile: a contractor with a Level 2 documentation gap and someone who can tailor the files to the real environment.
Yes to the first two, but no to the third? Templates will stall without someone who knows your systems. Read the section below on when templates are the wrong kind of help.
No to the first two? Don't assume you need Level 2 — or CMMC at all — from a generic checklist. If your written requirement is Level 1 and you handle only Federal Contract Information (FCI), start with our Level 1 self-assessment checklist. Just want free starting formats? Try our SSP template guide and policy template guide.
What does ComplianceForge sell for CMMC, and what does it cost?
ComplianceForge's main CMMC kit, the NIST 800-171 Compliance Program (NCP), lists at $5,200 and includes a year of updates. After that, updates are optional at $950 per 12 months. A Level 1 bundle lists at $3,000, and broader NIST 800-53 or Secure Controls Framework bundles run from $10,530 to $25,583 — all company-published list prices checked September 24, 2026.
NIST is the National Institute of Standards and Technology. Its Special Publication (SP) 800-171 Revision 2 contains the 110 security requirements incorporated into CMMC Level 2. SP 800-53 is NIST's much larger federal control catalog. Buying more 800-53 or Secure Controls Framework content does not give you a higher CMMC status.
| Product | What's in it, as ComplianceForge describes it | List price | Updates | Best fit to evaluate |
|---|---|---|---|---|
| NIST 800-171 Compliance Program (NCP) | Policies and standards, procedures, SSP template, POA&M template, third-party risk program, supply-chain risk plan, risk and threat catalogs, an evidence request list, incident response plan, and continuity templates. Ships in Rev. 2-only, Rev. 3-only, and combined versions. | $5,200 | First year included | A focused NIST SP 800-171 Rev. 2 documentation gap with an internal owner who can tailor it |
| NIST 800-171 SSP Template | An SSP modeled on Federal Risk and Authorization Management Program (FedRAMP) formats, covering the 800-171 requirements, plus a POA&M spreadsheet | $950 | First year included | Buyers who already have usable policies and procedures |
| CMMC Bundle 1 | Two products: policies, standards, and procedures for the 15 Level 1 safeguards | $3,000 | Ask before buying | An FCI-only company that wants a finished written program rather than free starting templates |
| CMMC Bundle 2 | Five products built on NIST SP 800-53 low and moderate baselines | $10,530 | Ask before buying | Organizations that separately need broader 800-53 coverage — not a higher CMMC status |
| CMMC Bundle 3 | Thirteen products built on NIST SP 800-53 through the high baseline | $23,208 | Ask before buying | Organizations that separately need 800-53 high coverage — not a shortcut to CMMC Level 3 |
| CMMC Bundle 4 | Thirteen products built on the Secure Controls Framework (SCF) | $25,583 | Ask before buying | Multi-framework programs already using SCF — not a shortcut to CMMC Level 3 |
| NCP update subscription | About four releases a year, each with release notes. Does not auto-renew. | $950 per 12 months | — | Keeping an eligible NCP purchase current |
| Professional services | Separate hours to help tailor documents you bought | $1,350 (5 hrs) · $2,550 (10 hrs) · $4,800 (20 hrs) | Hours expire 120 days after purchase | Tailoring help, not implementation or a formal assessment |
What three years really costs. For the NCP with optional continuous updates: $5,200 + $950 + $950 = $7,100. That is the documentation subtotal only. It assumes the price and renewal eligibility do not change. Your staff's time, security tools, implementation, recurring services, taxes, and any assessment are separate costs. The tailoring packages work out to $270, $255, or $240 an hour.
A bigger bundle isn't a higher CMMC level. Bundle numbers track how much framework content you are buying, not which CMMC status you need. ComplianceForge's own FAQ calls Bundle 2 "generally overkill" for companies that only need CMMC and NIST 800-171 (ComplianceForge FAQ).
About the savings claims. ComplianceForge says the NCP can replace about 900 hours of internal work or 800 hours of consultant work, which it values at $84,500 and $222,000 (NCP page). The public product page does not show the wage and consultant-rate assumptions behind those dollar figures or independent validation, and we could not test the result.
Whether a template kit is the right buy isn't the same for every contractor. The help you need — a Registered Practitioner (RP) or Registered Practitioner Organization (RPO) to guide scoping and your SSP, a managed service provider (MSP) or managed security service provider (MSSP) to put controls in place, a governance, risk, and compliance (GRC) platform to track evidence, or a CUI enclave to confine CUI work and potentially reduce scope when it is genuinely separated — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT setup, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit before you buy templates or request quotes — and do not submit CUI, drawings, or sensitive contract details.
Will ComplianceForge get you through CMMC? What the kit covers — and what's still on you
No template gets anyone through CMMC on its own. CMMC assessment procedures use three methods — examine, interview, and test. In a self-assessment, your organization performs that work; in a certification assessment, an authorized assessment team does. Only the documents come in the box.
That's the rule, not our opinion. CMMC Level 2 uses the June 2018 NIST SP 800-171A assessment procedures and their examine, interview, and test methods (32 CFR 170.14(d)). Final Level 2 (Self) status requires every security requirement to be MET; Conditional status is available only under the separate POA&M rules (32 CFR 170.16). Here's how the kit's pieces line up with what has to be true at your company.
| Kit piece | What ComplianceForge gives you | What still has to be true at your company | The rule behind it |
|---|---|---|---|
| Policies and standards | Written for 800-171. The company says policies are ready to adopt and standards are about 90–95% complete. | You set your own values, approve them, and follow them. | NIST SP 800-171 Rev. 2, all 14 families |
| Procedures | The company says they are about 75–80% complete. | Each one matches how your team actually works, with a named owner who can explain and demonstrate it. | SP 800-171A interview and test methods |
| SSP | A per-requirement template with prompts for owner, frequency, technology, and assessment objectives | It describes your real boundary, systems, environment of operation, implementation, and connections. The SSP must exist at assessment, and CA.L2-3.12.4 cannot be deferred on a Level 2 POA&M. | SP 800-171 Rev. 2, 3.12.4; 32 CFR 170.24; 170.21(a)(2)(iii)(C) |
| Access control policy | Written rules | Access is limited to authorized users, processes acting for authorized users, and devices — and you can show how access is granted, changed, and removed. | SP 800-171 Rev. 2, 3.1.1 |
| Authentication procedure | Written rules | Multifactor authentication (MFA) is operating for local and network access to privileged accounts and for network access to nonprivileged accounts. IA.L2-3.5.3 carries a three- or five-point deduction under the scoring rule, so it is not eligible for a Level 2 POA&M. | SP 800-171 Rev. 2, 3.5.3; 170.24; 170.21; our MFA guidance |
| Incident response plan | A template | You have tested the incident-response capability and can support the applicable assessment objectives with real records. | SP 800-171 Rev. 2, 3.6.3; our incident response guide |
| POA&M template | A tracking spreadsheet | Only eligible gaps go on it: at least 88 of 110 points; generally only one-point requirements; the narrow SC.L2-3.13.11 encryption condition; six listed requirements never; and closeout within 180 days. | 32 CFR 170.21; our POA&M closeout guide |
| Evidence request list | A list of what to gather | The actual records exist. Depending on the objective, examples can include logs, tickets, configurations, training records, or demonstrations; the filename alone is not the evidence. | 32 CFR 170.14(d); our assessment evidence guide |
| Scoping | A free scoping guide, plus SSP sections for the boundary and diagrams | You have determined where CUI is processed, stored, and transmitted, classified in-scope assets, and documented the boundary and external-service relationships. | 32 CFR 170.19; our scoping guide |
| CMMC result and SPRS | Not included | You perform the applicable assessment, calculate the result under the CMMC scoring methodology, and enter the required result in the Supplier Performance Risk System (SPRS). | 32 CFR 170.16; 170.24; our SPRS guide |
| Affirmation | Not included | Your internal Affirming Official submits the affirmation with Conditional or Final status, after POA&M closeout where applicable, and annually after Final status. | 32 CFR 170.22; our affirmation guide |
Think of the kit as a good set of house plans. Plans save you time. But an inspector doesn't pass a house because the plans are neat. The inspector walks the rooms, asks the builders questions, and flips the switches.
The same goes for paperwork. A written procedure isn't proof it happened. An incident response plan and the record of the last completed test answer two different questions — and the assessment can examine both.
If this table showed gaps the kit can't fill — scoping, MFA, evidence — the next question is what kind of help fills them. That depends on your contract and your systems, not on the kit.
What a fair ComplianceForge CMMC review has to check: the kit vs. the rule
The public product descriptions and SSP sample broadly track the CMMC documentation job. But several statements on the product pages, and several details in the dated public sample, do not match the current rule text. None proves the current paid release is unusable. Each is something to resolve yourself or ask about before you buy.
Everything in the left column was checked on ComplianceForge's site or in its public SSP sample on September 24, 2026. Findings about the sample apply to that public file, which may predate the current paid release.
| What ComplianceForge says or the public sample shows | What the rule or official source says | What to do |
|---|---|---|
| Product pages say federal policy requires the newest NIST version within a year, so Rev. 3 "will be expected" for contracts and Rev. 2 will be "deprecated" (bundles page, NCP page). | CMMC Level 2 remains built on Rev. 2 (32 CFR 170.14(a)(2)). The current suspension direction also keeps baseline Rev. 2 compliance under DFARS 252.204-7012. To be fair, ComplianceForge's own current FAQ describes Level 2 as the 110 Rev. 2 requirements. | Use the Rev. 2 mapping for the CMMC Level 2 baseline. Choose the combined version only if a separate contract, customer, or transition plan justifies Rev. 3 work too. |
| The NCP page says its policies cover "the 17 sections of CMMC 2.0." | CMMC domains map to the requirement families in NIST SP 800-171 Rev. 2 (170.14(b)). Rev. 2 has 14 families. | Organize the CMMC Level 2 baseline around the 14 Rev. 2 families. |
| The NCP page says that if you store, transmit, or process CUI, "you are CMMC v2.0 Level 2." | CUI handling is the reason Level 2 is the relevant CMMC level, but the solicitation, contract clause, or valid subcontract flow-down sets the status and assessment type for the procurement. Under the current suspension, new requirements may use Level 1 (Self) or Level 2 (Self); a generic vendor statement cannot set either. | Read the actual provision, clause, and flow-down before choosing a product. The next section shows where to look. |
| The FAQ says the NCP "contains all the policies, standards, procedures, SSP/POA&M and other templates that you will need to pass a CMMC assessment" (FAQ). | That can describe the template categories. It cannot describe the full assessment job. CMMC uses examine, interview, and test methods (170.14(d)), and Final Level 2 (Self) requires every requirement MET (170.16). | Budget for implementation, operation, evidence, and assessment effort — not only documents. |
| The documentation is described as "DIBCAC battle tested" and used in successful assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) and CMMC Third-Party Assessment Organizations (C3PAOs). | That is company-stated, and we could not independently verify it. We found no CMMC document-template approval category in the current CMMC rule or Cyber AB Marketplace, and no official template approval was shown in the sources we checked. NIST says there is no prescribed SSP format as long as the required information is conveyed. | Ask for the specific scope behind the statement. It is question k in the worksheet below. |
| The public SSP sample labels requirements like AC.L1-3.1.1, AC.L1-3.1.20, PE.L1-3.10.3, and RM.L2-3.11.1 (sample). | The rule's identifiers follow the pattern DD.L#-REQ. Level 2 uses AC.L2 for the 3.1 requirements, PE.L2 for 3.10, and RA.L2 for 3.11 (170.14(c)(1)). The POA&M and scoring rules use those identifiers. ComplianceForge's release notes say it updated Level 1 numbering in release 2025.4.1. | Ask for a sample from the exact release you will receive. Check every identifier before relying on the file. |
| The public SSP sample asks for a "DUNS #." | The government replaced DUNS numbers with the Unique Entity ID (UEI) on April 4, 2022 (GSA). | Use your UEI and your Commercial and Government Entity (CAGE) code where those identifiers belong. |
| The public POA&M sample link was present on the product materials, but its PDF could not be re-fetched during this final audit. | Conditional Level 2 status still requires the current rule's score, eligibility, exclusion, and 180-day closeout logic (170.21). | Before buying, request the POA&M sample from the release you will receive and verify fields for CMMC ID, point value, eligibility and reason, conditional-status date, owner, and closeout deadline. |
| In the public SSP sample, the entry labeled requirement 3.1.1 lists the assessment objectives for 3.1.3. | Each requirement has its own objectives in NIST SP 800-171A (June 2018). Requirement 3.1.1 has three objectives; 3.1.3 has five different objectives. | Walk every objective line in the current release against the June 2018 SP 800-171A mapping used by CMMC. |
Which version should you use: Rev. 2 or Rev. 3?
For the CMMC Level 2 baseline today, work from the NCP's Rev. 2 mapping. The NCP ships three versions — Rev. 2 only, Rev. 3 only, and combined — and the CMMC rule still points to Rev. 2.
Here's where the confusion comes from. NIST published Rev. 3 in May 2024 and now labels Rev. 2 and the June 2018 SP 800-171A as withdrawn or superseded on its publication pages. That's NIST's publication lifecycle. It does not, by itself, rewrite the standard incorporated into your CMMC requirement.
The CMMC rule names Rev. 2 and the June 2018 assessment guide directly (32 CFR 170.14(a)(2) and (d)). The standing DFARS Rev. 2 deviation and the current CMMC suspension direction keep NIST SP 800-171 Rev. 2 as the baseline under DFARS 252.204-7012. DoW's current CMMC page says Rev. 2 is what it is enforcing through self-assessments and select government-led assessments.
Rev. 3 content can be useful for a separate transition plan or customer requirement. It is not the CMMC Level 2 scoring baseline today. Our Rev. 2 vs. Rev. 3 guide covers the differences.
What the public SSP sample shows
The public SSP sample has a useful structure for CMMC. For each requirement, it asks who owns it, who operates it, how often it occurs, which technology supports it, and how the listed assessment objectives are addressed. The problems are labels and fields that have gone stale and at least one objective mismatch — and the public sample may be older than the version a buyer receives.
What's useful about it:
- The implementation-status choices include "implemented externally via contract and/or shared responsibility." That is useful when an MSP or cloud provider operates part of a requirement.
- The requirement sections include owner, operator, occurrence, technology, implementation-status, and assessment-objective prompts.
- It includes sections for the system boundary, network and data-flow diagrams, roles, vendors, and hardware and software inventory.
The weak spots are the ones in the table above: old requirement identifiers, a DUNS field, and a 3.1.1 section containing 3.1.3 objectives. We could not re-fetch the public POA&M PDF in this final audit, so we do not say the current POA&M template lacks any particular field.
We reviewed the public SSP sample ComplianceForge links from its product materials on September 24, 2026. We did not buy the kit, so we cannot tell you which public-sample issues the current paid release has already fixed.
Already bought it? Four checks
Start by checking your release number against ComplianceForge's release notes. A newer release may already fix some of these. Then:
- Match every requirement identifier to 32 CFR 170.14, 170.21, and 170.24. For example, use AC.L2-3.1.20 for a Level 2 requirement, not AC.L1-3.1.20.
- Replace DUNS with your UEI, and keep your CAGE code where the record calls for it.
- Inspect the current POA&M before relying on it. Add fields for CMMC ID, point value, eligibility and reason, conditional-status date, owner, and closeout deadline if the release you received does not already contain them.
- Walk every objective line against NIST SP 800-171A (June 2018), the assessment procedures named in 32 CFR 170.14(d).
What we verified (September 24, 2026): ComplianceForge's CMMC product, bundle, update, professional-services, FAQ, delivery, and Terms & Conditions pages; the public SSP sample; the Cyber AB's SCF Marketplace; 32 CFR 170.8, 170.14, 170.16, 170.19, 170.21, 170.22, and 170.24; DFARS 252.204-7012, 252.204-7021, and 252.204-7025; the official DARS index entry for Class Deviation 2026-O0025, Revision 3; DoW's current CMMC page and July 13 suspension materials; NIST's SP 800-171 Rev. 2 and SP 800-171A publication pages and text; and GSA's UEI notice. What we did not do: buy or test the paid kit, verify the current paid SSP or POA&M release, independently confirm the "battle tested" statement, verify a customer outcome, establish a company-specific CMMC Marketplace role through the catalog interface, or rely on language unique to the Revision 3 PDF, which did not render during the final pass. The public POA&M sample also could not be re-fetched in this final audit. Our Editorial & Advertising Policy explains how we handle commercial relationships.
Which ComplianceForge kit fits your situation — if any?
For a small contractor with a confirmed Level 2 (Self) documentation gap, the NCP is ComplianceForge's most directly targeted package. The broader bundles add 800-53 or Secure Controls Framework material; they do not confer Level 3 or make a Level 2 requirement more complete. If you handle only FCI, you may not need a paid kit at all.
| If you are… | Consider | Watch out for |
|---|---|---|
| FCI only, with a written Level 1 requirement | Free first: the 15 safeguards and our Level 1 checklist. Consider Bundle 1 ($3,000) only if you want a finished written program. | Level 1 permits no POA&M, and the self-assessment is annual (32 CFR 170.15; 170.21(a)(1)). Written policies are not a substitute for all 15 safeguards being MET. |
| CUI, Level 2 (Self), one environment, and someone who can edit documents | NCP ($5,200), using the Rev. 2 mapping for CMMC | Tailoring, implementation, operation, evidence, assessment, and affirmation are still your work. |
| You already have usable policies and need an SSP and POA&M starting point | SSP template ($950, with a POA&M listed as included) | Ask for release-matched samples and check the current rule identifiers, objectives, and POA&M fields. |
| You already run NIST SP 800-53 programs for FedRAMP or similar work | Bundle 2 ($10,530), if its broader content matches that separate need | ComplianceForge itself calls it "generally overkill" for a CMMC-only buyer. |
| You separately need 800-53 high or a multi-framework SCF program | Compare Bundles 3 and 4 against that independent requirement | Do not buy either merely because CMMC Level 3 could return. Level 3 is not the same as 800-53 high or an SCF bundle. |
| You are an MSP serving several contractors | Confirm licensing separately for each client and legal entity | One license is for one legal entity. Do not assume that one client's licensed copy can become a reusable client library. |
| You want someone to write it with you | An RP/RPO or other qualified consultant; ComplianceForge's separate tailoring hours may also help | ComplianceForge's hours expire after 120 days, and only your organization can supply the facts about its environment. |
| Your CUI is confined to a managed enclave or government cloud | Get the provider's SSP inputs and shared responsibility matrix before choosing the package | A smaller boundary can change which parts of your enterprise are assessed, but it does not eliminate your documentation, customer responsibilities, connections, people, or external providers. |
No web page — including this one — can tell you your required CMMC status without the procurement documents. Your solicitation, contract, subcontract, or valid prime flow-down does. Here's where to look.
Open the document and search for: 252.204-7025, 252.204-7021, 252.204-7012, 252.240-7997, 252.204-7020, 52.240-93, 52.204-21, and CMMC.
- DFARS 252.204-7025 or 252.204-7021: the provision or clause states the required CMMC level and assessment type. Under the current suspension, affected Level 2 (C3PAO) or Level 3 language should be removed or revised; do not assume it changed until you have the amendment or modification.
- FAR 52.240-93 or FAR 52.204-21: newer DoW solicitations using the Part 40 deviation may use 52.240-93, while older instruments may still cite 52.204-21. Both are basic-safeguarding clauses for covered contractor information systems containing FCI in their respective versions; neither, by itself, proves that a CMMC Level 1 status was inserted into your procurement.
- DFARS 252.204-7012: this is the safeguarding and cyber-incident-reporting clause for covered defense information. It carries the Rev. 2 security duty but does not, by itself, select your CMMC assessment type.
- DFARS 252.240-7997 or older 252.204-7020: read whichever clause is actually incorporated for government NIST SP 800-171 assessment and access terms. Neither is the provision that selects your CMMC level.
- A prime's letter or flow-down that just says "Level 2": ask in writing whether the requirement is Level 2 (Self) or Level 2 (C3PAO), and ask for the clause or flow-down language. Under the current suspension, new requirements may use Level 2 (Self), not a new C3PAO designation.
Our guides to CMMC levels and FCI vs. CUI walk through the edge cases.
Still can't tell which level or assessment type your paperwork points to? Settle that before you buy any kit.
What do ComplianceForge's license terms mean for you?
The terms are stricter than many buyers will expect. There are no refunds after the files are fulfilled, one license covers one legal entity, and you need a signed nondisclosure agreement (NDA) before disclosing the documents to a third party — including, in ComplianceForge's own example, an auditor.
All rows below come from ComplianceForge's Terms & Conditions, last updated July 1, 2026.
| Term | What it means in plain English | Why it matters for CMMC |
|---|---|---|
| No refunds, cancellations, or exchanges after fulfillment (§5) | You can cancel only before the files are sent. | Review the public sample and resolve product and license questions before fulfillment. |
| A perpetual, nontransferable, nonsublicensable license for one legal entity (§8) | A separately incorporated parent, subsidiary, sister company, or client is a different legal entity under the text. | Confirm the licensed entity and every intended user before sharing. |
| No disclosure to a third party without a signed NDA (§7) | Anyone outside the licensed entity needs the required NDA before seeing the documents. The company's example includes auditors. | Primes may ask for SSP information, assessors examine documents, and MSPs or consultants may help edit them. Check the required sharing process first. See our guide to a prime asking for an SSP or SPRS information. |
| No uploading to artificial intelligence (AI) or large language model (LLM) tools where the content could train the model (§7) | This is not written as a ban on every AI-assisted workflow. The restriction turns on whether the content could be used for training. | Get the permitted workflow in writing, check the tool's data terms, and never paste CUI or sensitive environment details into an unapproved tool. |
| No derivative works to sell or share (§7) | A consultant or MSP cannot turn one licensed copy into a reusable library for other clients. | Confirm licensing for every legal entity; do not assume per-client reuse rights. |
| No warranty; liability capped at the amount paid (§§9–10) | The terms disclaim warranties and limit the company's exposure. | Validate identifiers, mappings, and company-specific content before relying on them. |
| The license ends if you breach it, and copies must be erased within seven days after termination (§8) | A breach can create an operational problem when your own SSP is built from licensed text. | Keep the license terms with the purchase record and control who can copy or share the files. |
| Wyoming law, with arbitration at ComplianceForge's option (§§13–14) | The terms select Wyoming law and give the company the stated arbitration option. | Know the dispute terms before a purchase you cannot refund after fulfillment. |
| The company describes its products as commercial off-the-shelf (COTS) items and says the purchase involves no FCI or CUI (§8) | Buying the standard files should not require sending contract data or CUI. | Do not send CUI during purchase or tailoring unless a separately approved, contractually authorized secure process exists. |
One more catch sits on the update page. It says the subscription is for customers "who have not skipped one or more years," and also that "re-subscribing later is always possible" (subscription page). Get the applicable price and eligibility in writing before you let updates lapse.
Is ComplianceForge legit — and is it approved by DoD or the Cyber AB?
ComplianceForge is a long-running documentation publisher with public prices, public terms, and public samples. We found no CMMC document-template approval category in the current CMMC rule or Cyber AB Marketplace. The Cyber AB entries we verified for ComplianceForge are in a separate program built around the Secure Controls Framework, not an approval of its CMMC documents.
| Question | Answer | Source |
|---|---|---|
| What is it? | Compliance Forge, LLC, a documentation publisher based in Sheridan, Wyoming. It says it is a Veteran-Owned Small Business that has written security documentation since 2005 and NIST 800-171 templates since 2016. | Company site (company-stated) |
| Did this audit establish a CMMC C3PAO or RPO role? | No company-specific CMMC Marketplace role was established through the catalog interface in this audit. The products reviewed here are documentation and separate tailoring hours, not a formal assessment. Verify any claimed CMMC role in the CMMC Marketplace rather than inferring it from the SCF entries. | Cyber AB CMMC Marketplace; company product pages |
| Is the NCP software? | No. The core product is delivered as editable Word, Excel, and PowerPoint files by email download link. There is nothing to install. | NCP page |
| Who is behind it? | Senior partner Tom Cornelius also founded the Secure Controls Framework, a free control catalog mapped to many laws and frameworks. | ComplianceForge; SCF Council |
| What Cyber AB entries were verified? | In the Cyber AB's SCF Marketplace, ComplianceForge appears under SCF Registered Provider Organization and SCF Licensed Content Provider, checked September 24, 2026. Those are SCF roles, not CMMC roles. An SCF Registered Provider Organization is not the same designation as a CMMC Registered Practitioner Organization. | SCF Marketplace; listing |
| Why does the Cyber AB appear in the SCF context? | In December 2024, the SCF Council named the Cyber AB as the accreditation body for its separate SCF certification program. That does not endorse a document package for CMMC. | Cyber AB announcement |
| Who helps implement it? | ComplianceForge lists partner firms that tailor its documents. We have not evaluated those firms or their work. | Partners page |
If you hire CMMC-specific help, check the exact organization and current role in the Cyber AB's CMMC Marketplace — the CMMC catalog, not the SCF Marketplace. Our Marketplace guide shows what each status does and does not establish.
Before you order: a purchase-approval worksheet
A good purchase request names the gap, the licensed company, the questions still open, and the people who will finish the work. Copy this brief into your own approved files, fill it in, and hand it to whoever signs off. Leave anything you do not know marked unknown — never zero, "no," or compliant by default.
COMPLIANCEFORGE PURCHASE BRIEF — PRIVATE WORKING COPY
Do not put CUI, drawings, contract text, or sensitive system details in this brief.
Date: Prepared by:
Approver: Legal entity that will hold the license:
1. WHAT DOES OUR CONTRACT REQUIRE?
CMMC level and assessment type: [ Level 1 (Self) / Level 2 (Self) /
Level 2 (C3PAO) / unknown ]
Where we found it (clause or flow-down reference only):
Information we handle: [ FCI only / CUI / both / unknown ]
If unknown — who confirms it, and by when:
2. WHAT IS OUR ACTUAL GAP? (check all that apply)
[ ] Written policies, procedures, SSP, or POA&M
[ ] Technical controls not yet in place (for example: MFA, encryption, logging)
[ ] Evidence we cannot produce yet
[ ] Knowing where CUI lives and what is in scope
[ ] Unknown — find out before buying anything
Documents we already have and can keep:
3. WHAT WOULD WE BUY?
Product and list price on order date:
CMMC Level 2 baseline mapping: [ Rev. 2 / combined for a separate need — explain ]
NCP release number offered (for example, 2026.x):
Samples we reviewed, and their dates:
4. QUESTIONS WE SENT COMPLIANCEFORGE (write the answer and date beside each)
a. Which NCP release will we receive? Can we see the SSP and POA&M
samples from that exact release?
b. Does the current SSP use the requirement identifiers in 32 CFR 170.14,
170.21, and 170.24, and ask for our UEI instead of a DUNS number?
c. Does the current POA&M track CMMC point values, eligibility and reason
under 32 CFR 170.21, the Conditional status date, owner, and the
180-day closeout deadline?
d. In the version mapped to Rev. 2, is every requirement mapped to the
NIST SP 800-171A (June 2018) assessment objectives used by CMMC?
e. Our MSP or consultant will help edit. Does your NDA requirement apply
to them? Do you provide a standard NDA?
f. A prime or assessor may ask for our SSP. What must we do before
sharing licensed content?
g. May we use an AI tool that is contractually set not to train on our
inputs to help edit the documents?
h. We have a parent, subsidiary, or sister company. How many licenses
do we need?
i. If we skip a year of updates, can we renew at $950 later, or must we
repurchase? Which written term controls the answer?
j. What do professional-services hours cover? Can they review our
finished SSP before the 120 days expire?
k. What specifics can you share behind "DIBCAC and C3PAO battle tested"
(number of assessments, years, levels, and document versions) without
naming clients?
5. WHO DOES THE REST OF THE WORK?
Tailors the documents:
Implements the controls:
Collects and keeps evidence:
Checks documents against how we actually operate:
Performs and records the CMMC self-assessment result in SPRS:
Affirming Official (Conditional or Final status, POA&M closeout if used,
and annual affirmation after Final status):
6. WHAT WILL IT COST? (write "unknown" until you know — never zero)
Templates, year 1: $
Updates, years 2 and 3 (optional): $
Our staff time (hours x rate):
Outside implementation help:
Recurring IT or security services:
Formal assessment (only if a current authoritative requirement calls for one):
Taxes or other quoted charges:
Anything counted in two lines (remove the duplicate):
7. DECISION
[ ] Buy — on these conditions:
[ ] Hold until these questions are answered:
[ ] Choose a different kind of help instead
Next step / owner / date:
This brief records a purchasing decision. It is not a CMMC assessment,
a CMMC status, legal advice, or an SPRS submission.
Before you order: a purchase-approval worksheet
A good purchase request names the gap, the licensed company, the questions still open, and the people who will finish the work. Copy this brief into your own approved files, fill it in, and hand it to whoever signs off. Leave anything you do not know marked unknown — never zero, "no," or compliant by default.
COMPLIANCEFORGE PURCHASE BRIEF — PRIVATE WORKING COPY
Do not put CUI, drawings, contract text, or sensitive system details in this brief.
Date: Prepared by:
Approver: Legal entity that will hold the license:
1. WHAT DOES OUR CONTRACT REQUIRE?
CMMC level and assessment type: [ Level 1 (Self) / Level 2 (Self) /
Level 2 (C3PAO) / unknown ]
Where we found it (clause or flow-down reference only):
Information we handle: [ FCI only / CUI / both / unknown ]
If unknown — who confirms it, and by when:
2. WHAT IS OUR ACTUAL GAP? (check all that apply)
[ ] Written policies, procedures, SSP, or POA&M
[ ] Technical controls not yet in place (for example: MFA, encryption, logging)
[ ] Evidence we cannot produce yet
[ ] Knowing where CUI lives and what is in scope
[ ] Unknown — find out before buying anything
Documents we already have and can keep:
3. WHAT WOULD WE BUY?
Product and list price on order date:
CMMC Level 2 baseline mapping: [ Rev. 2 / combined for a separate need — explain ]
NCP release number offered (for example, 2026.x):
Samples we reviewed, and their dates:
4. QUESTIONS WE SENT COMPLIANCEFORGE (write the answer and date beside each)
a. Which NCP release will we receive? Can we see the SSP and POA&M
samples from that exact release?
b. Does the current SSP use the requirement identifiers in 32 CFR 170.14,
170.21, and 170.24, and ask for our UEI instead of a DUNS number?
c. Does the current POA&M track CMMC point values, eligibility and reason
under 32 CFR 170.21, the Conditional status date, owner, and the
180-day closeout deadline?
d. In the version mapped to Rev. 2, is every requirement mapped to the
NIST SP 800-171A (June 2018) assessment objectives used by CMMC?
e. Our MSP or consultant will help edit. Does your NDA requirement apply
to them? Do you provide a standard NDA?
f. A prime or assessor may ask for our SSP. What must we do before
sharing licensed content?
g. May we use an AI tool that is contractually set not to train on our
inputs to help edit the documents?
h. We have a parent, subsidiary, or sister company. How many licenses
do we need?
i. If we skip a year of updates, can we renew at $950 later, or must we
repurchase? Which written term controls the answer?
j. What do professional-services hours cover? Can they review our
finished SSP before the 120 days expire?
k. What specifics can you share behind "DIBCAC and C3PAO battle tested"
(number of assessments, years, levels, and document versions) without
naming clients?
5. WHO DOES THE REST OF THE WORK?
Tailors the documents:
Implements the controls:
Collects and keeps evidence:
Checks documents against how we actually operate:
Performs and records the CMMC self-assessment result in SPRS:
Affirming Official (Conditional or Final status, POA&M closeout if used,
and annual affirmation after Final status):
6. WHAT WILL IT COST? (write "unknown" until you know — never zero)
Templates, year 1: $
Updates, years 2 and 3 (optional): $
Our staff time (hours x rate):
Outside implementation help:
Recurring IT or security services:
Formal assessment (only if a current authoritative requirement calls for one):
Taxes or other quoted charges:
Anything counted in two lines (remove the duplicate):
7. DECISION
[ ] Buy — on these conditions:
[ ] Hold until these questions are answered:
[ ] Choose a different kind of help instead
Next step / owner / date:
This brief records a purchasing decision. It is not a CMMC assessment,
a CMMC status, legal advice, or an SPRS submission.
Prices checked September 24, 2026.
References used by the worksheet:
COMPLIANCEFORGEWORKSHEET
Worked example: a hypothetical 40-person machine shop
Say you run a 40-person machine shop. Here's how the worksheet turns "Should we buy ComplianceForge?" into a decision you can defend.
Your prime's subcontract includes DFARS 252.204-7012 and a current Level 2 (Self) requirement. Controlled drawings live on one file server and in engineering email. Your IT lead has a patchwork of old policies. While filling in the worksheet, she finds that MFA is not enabled for remote access to the file server.
The worksheet shows two jobs, not one: writing the documents and fixing MFA. The kit helps with the first. It does nothing for the second — and IA.L2-3.5.3 cannot be carried on a Level 2 POA&M because it carries more than one point under the scoring rule (32 CFR 170.21; 170.24).
| Cost line | Amount in this example | What it means |
|---|---|---|
| NCP, year 1 (updates included) | $5,200 | Company list price checked September 24, 2026 |
| Updates, year 2 | $950 | Optional |
| Updates, year 3 | $950 | Optional; assumes the price and renewal eligibility do not change |
| IT lead's time to tailor the documents | Unknown | Get her estimate in hours and an internal cost basis. Do not enter zero. |
| Enabling MFA for the actual remote-access path | Unknown | Define the technical work and get a written internal estimate or quote. |
| Level 2 (Self) assessment | Internal assessment effort | This written requirement calls for self-assessment, not a C3PAO assessment. |
| Documentation subtotal, three years | $7,100 | Not the implementation, operating, or total project cost |
The decision on the owner's desk: buy the NCP mapped to Rev. 2 once ComplianceForge answers questions a through d in writing. The IT lead owns tailoring. Get the MFA scope and cost now. Perform the self-assessment only after MFA is operating on the required access paths, enter the result in SPRS, and have the designated internal Affirming Official submit the required affirmation.
This shop is fictional. The $5,200 and $950 figures are current company-published list prices used in a hypothetical calculation; none of the unknown amounts is a real result or a typical market cost.
When are templates the wrong kind of help?
Templates fix a writing gap. If your real gap is scoping, operating systems, implementing controls, tracking evidence, or obtaining an assessment, a bigger document set will not close it. Match the help to the missing work.
| If the missing work is… | Consider | Check first | Where to learn more |
|---|---|---|---|
| A starting format for an SSP or POA&M | NIST's free CUI SSP and Plan of Action templates | Someone who can describe the real environment and requirement implementation | NIST SP 800-171 Rev. 2 page; our SSP template guide |
| A coordinated written program | A commercial template kit, including ComplianceForge or another publisher | Current samples, license terms, revision mapping, and who will tailor it | This page |
| Scoping, gap analysis, or an SSP written with you | An RP/RPO or other appropriately qualified readiness consultant | Scope of work, deliverables, responsible people, and the exact Cyber AB role claimed | RPO consultants; consulting cost |
| Running IT and security day to day | An MSP or MSSP | Who owns each requirement, how the provider handles CUI or Security Protection Data, and what evidence it will give you | MSP guide; MSP pricing |
| Tracking evidence, owners, and recurring tasks | A GRC platform | Who will operate it — software organizes work but does not implement controls | GRC software; SSP software |
| Keeping CUI in a smaller, separated environment | A CUI enclave | Actual data flows, integrations, users, connections, external providers, and the customer-responsibility boundary | Enclave providers; enclave cost |
| Getting started with outside counseling | An APEX Accelerator | What the local office actually offers and what remains outside its scope | APEX Accelerator guide |
| A formal Level 2 assessment called for by a current solicitation, contract amendment, or other authoritative direction | An authorized C3PAO | Current authorization, the exact requirement, readiness, scope, and conflicts of interest | C3PAO list; provider categories |
Keep readiness and assessment separate. Under 32 CFR 170.8(b)(17)(ii)(G), the Cyber AB's Code of Professional Conduct must prohibit CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the preceding three years. Confirm the proposed roles and conflict check in writing.
If you're not sure which of these rows is yours — or you're in more than one — map the missing work before you spend.
Questions buyers still ask
Can we keep our existing SSP instead of buying a new one?
Yes, if it describes the real system boundary, environment of operation, how the requirements are implemented, and the connections to other systems. NIST says there is no prescribed SSP format. Fix the specific gaps before replacing a document that already works — our guide on whether your SSP is defensible shows how to check.
Will buying the kit change our SPRS score?
No. A purchase does not change any assessment result. For CMMC Level 2 (Self), you assess implemented requirements under the scoring methodology in 32 CFR 170.24 and enter the required result in SPRS under 170.16. A receipt or a filled-in template does not move that result. Older paperwork may also refer to a separate NIST SP 800-171 DoD Assessment score; read the clause actually incorporated rather than treating the labels as interchangeable.
Does paying for updates replace the annual affirmation?
No. A vendor update and a CMMC affirmation are different events. Under 32 CFR 170.22, your internal Affirming Official submits an affirmation with Conditional or Final status, after POA&M closeout where applicable, and annually after Final status. Buying revised files does none of those things.
Can we pay by purchase order, and how fast do the files arrive?
ComplianceForge's product pages say you can pay by invoice or purchase order, or by wire or Automated Clearing House (ACH) bank transfer using the invoice. The company says files arrive by email download link within one to two business days, with your company name — and logo, if supplied — added.
Will ComplianceForge write our SSP for us?
Not as part of the document purchase. Its separate tailoring packages provide 5, 10, or 20 hours and expire 120 days after purchase. ComplianceForge says those hours supplement your own work because only your organization knows its environment. If you need the SSP developed with you, define that as a separate readiness-consulting scope and name who will validate the finished document against operations.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
All sources checked September 24, 2026 unless another date is stated.
Rules, clauses, and official sources
- 32 CFR 170.8 — Accreditation Body conflict-of-interest and Code of Professional Conduct requirements (eCFR)
- 32 CFR 170.14 — CMMC Model (eCFR)
- 32 CFR 170.15 — Level 1 self-assessment (eCFR)
- 32 CFR 170.16 — Level 2 self-assessment (eCFR)
- 32 CFR 170.19 — CMMC scoping (eCFR)
- 32 CFR 170.21 — POA&M requirements (eCFR)
- 32 CFR 170.22 — Affirmation (eCFR)
- 32 CFR 170.24 — CMMC scoring methodology (eCFR)
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7021 — Contractor Compliance With the CMMC Level Requirements
- DFARS 252.204-7025 — Notice of CMMC Level Requirements
- DFARS 204.7504 — clause-insertion timing
- FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
- DoW CIO — current CMMC program page
- Department of War — CMMC Phase II suspension announcement, July 13, 2026
- DoW CIO — implementation procedures for the Phase II suspension, July 13, 2026
- Official DARS Revolutionary FAR Overhaul class-deviation index
- Acquisition.gov — FAR Overhaul Part 40 deviation guide, including FAR 52.240-93
- DoD Class Deviation 2024-O0013, Revision 1 — DFARS 252.204-7012 and NIST SP 800-171 Rev. 2
- NIST SP 800-171 Rev. 2 and its publication page with free SSP and Plan of Action templates
- NIST SP 800-171A (June 2018)
- GSA — switch to the Unique Entity ID, April 4, 2022
- Cyber AB — SCF Marketplace and ComplianceForge SCF listing
- Cyber AB — SCF Council partnership announcement
- Cyber AB — CMMC Marketplace
ComplianceForge pages — company-stated product, price, and term information
- CMMC bundles
- NIST 800-171 Compliance Program (NCP)
- NIST 800-171 SSP Template
- NCP update subscription and release notes
- Professional services
- Terms & Conditions, last updated July 1, 2026
- FAQ: purchasing CMMC policy templates
- FAQ: what CMMC compliance requires
- Public SSP sample (PDF)
- Partners
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, the Department of Defense (DoD), the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC), NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.
