Browse All Templates

Pre-built document templates for defense contractors. Ready to customize and deploy. No credential required.

All Templates

Popular

System Security Plan (SSP) Template

NIST 800-171 r2

Complete SSP draft covering all 110 controls. Export to DOCX. After 3 months, one team generated 40 SSPs.

View →
New

Plan of Action and Milestones (POA&M)

CMMC Ready

Track control gaps with remediation dates. Teams report 60% faster POA&M creation versus manual spreadsheets.

View →
M

Media Protection Policy Template

SC.5 / SC.8

Handles removable media controls for SC.5 and SC.8. Includes checklist and evidence collection guide.

View →
A

Access Control Policy AC.1 through AC.4

Access Control

Covers user provisioning, termination, least privilege. Small contractors tell us this saves 12+ hours per contract.

View →
I

Incident Response Plan Template

IR.1 through IR.6

Detection, analysis, containment, eradication. Includes contact matrix and escalation flowchart. Required for CMMC.

View →
A

Audit Log Review Procedure

AU.6 Compliance

Weekly review checklist for AU.6. Reduces auditor findings by identifying gaps before formal assessments.

View →
C

Configuration Management Plan

CM.1 through CM.9

Baseline configurations, change control procedures, inventory tracking. DFARS 252.204-7012 requires this.

View →
R

Risk Assessment Report Template

RA.1 through RA.5

System characterization, threat identification, vulnerability analysis, risk determination. Pairs with NIST 800-171 r2.

View →
S

Security Awareness Training Materials

AT.1 through AT.4

Phishing awareness, role-based training, annual refresher agenda. Includes completion tracking matrix for compliance.

View →
P

Personnel Security Policy Template

PS.1 through PS.8

Position risk screening, termination procedures, insider threat awareness. Covers the full PS family requirements.

View →
P

Physical Protection Procedures

PE.1 through PE.6

Badge access, visitor control, server room protection. Many contractors underestimate PE requirements until audit.

View →
S

System and Communications Protection

SC.1 through SC.8

Boundary protection, encryption standards, DNS filtering. SC.3 and SC.7 are most frequently cited gaps.

View →
S

System and Information Integrity

SI.1 through SI.5

FIM, malware protection, network performance alerts. SI.3 requires flapping checks. Template includes workflow.

View →
B

Boundary Protection Policy

SC.7 Firewall Rules

VLAN segmentation, egress filtering, DMZ configuration documentation. Reviewers say this is the clearest SC.7 guide.

View →
V

Vulnerability Scanning Procedures

RA.5 / SC.3

Monthly scan checklist, remediation workflow, POA&M updates. Integrates with Nessus, Qualys, and open-source tools.

View →
C

Contingency Planning Template

CP.1 through CP.10

Backup procedures, disaster recovery plan, alternate sites. Includes 3 sample playbooks for common scenarios.

View →