NIST SP 800-171 Rev. 2 (CMMC Level 2) compliance, built by a Lead CMMC Assessor
The complete documentation, evidence, and automation defense contractors and MSPs need to walk in ready. Assessor-built, without the five-figure consulting invoice.

Created by a Lead CMMC Assessor (LCCA) · CCA · CCP · Performs assessments and staffs teams for half a dozen C3PAOs
See the actual documents
Most kits hand you documents and wish you luck. The Compliance Engine gives you the documentation, the guidance to make it real in your environment, and the evidence to back it up.

Pre-written, GCC High-ready, not blank templates. Your team edits what’s different, you never start from scratch.


Start Where You Are. Scale as You Grow.
Every tier includes a single-organization license. Upgrade at any time and your original purchase price applies toward the new tier.
Compare the tiers
Every tier builds on the one before it. Start where you are, upgrade anytime.
| What’s included | Starter | ProfessionalMOST POPULAR | Complete |
|---|---|---|---|
| Domain policies — all 14 + FIPS | 15 | 15 | 15 |
| System Security Plan (SSP) | ✓ | ✓ | ✓ |
| Policy customization guide | ✓ | ✓ | ✓ |
| Tracking tools, registers & matrices | ✓ | ✓ | ✓ |
| Agreements & forms | ✓ | ✓ | ✓ |
| Self-assessment & evidence workbooks | ✓ | ✓ | ✓ |
| Implementation roadmap & tracker | ✓ | ✓ | ✓ |
| Per-control procedures | — | 50+ | 50+ |
| SSP domain implementation sections | — | ✓ | ✓ |
| Master customization guide (all documents) | — | ✓ | ✓ |
| Incident response plan + playbooks | — | 7 | 7 |
| Risk & security assessment toolset | — | ✓ | ✓ |
| Microsoft 365 / Sentinel guides | — | 8 | 8 |
| Network architecture reference | — | ✓ | ✓ |
| Assessment prep packages (APREP) | — | — | 14 |
| Automation scripts — Python + PowerShell | — | — | 52 |
| Consultant licensing discount | — | — | ✓ |
| Total files | 48 | 155 | 226 |
| Get started | Get started | Get started |

Who built the Compliance Engine
Jil Wright, an experienced Lead CMMC Assessor (LCCA), knows what gets examined, what gets asked, and what sinks an organization before it gets out of Phase 1. Every document reflects what she wants to see when she’s the one running an assessment.
As President of Wrightbrained Security, with nearly 25 years in IT, she has performed CMMC Level 2 assessments and readiness work for everyone from small manufacturers to Fortune 100 primes. Her mission is simple: take what she learns on the assessor’s side of the table and build the tools she wishes contractors already had, so compliance is achievable for the organizations that don’t have an enterprise budget to throw at it.

Who Is it for?
Organizations Seeking Assessment (OSAs)
Complete NIST SP 800-171 Rev. 2 (CMMC Level 2) documentation without the enterprise overhead. Policies, procedures, evidence tools, and a pre-filled SSP — all built and mapped. Your team implements; the customization guides walk you through every control, step by step.
Consultants & MSPs
Stop rebuilding documentation from scratch for every client. Deploy one proven, repeatable framework across every engagement and bill your expertise, not your document time. Licensed per client, with $500 off each additional organization.
Questions buyers ask
The questions real people ask before spending real money on compliance docs. Don’t see yours? Ask, it goes right to Jil.
See the quality before you decide
Read a complete CMMC domain — the real policy, SSP language, procedure, and assessor questions — free.