CMMC Compliance Engine · Complete Tier

What’s included

Every document in the Complete tier, organized by domain exactly as you’ll receive it. All files are NIST SP 800-171 Rev. 2 mapped and built for a Microsoft 365 GCC High environment. Rev. 3 updates are included with your license if and when Rev. 3 becomes a requirement for you.

226  files across 14 domains
STARTER entry tier   PRO added at Professional   unmarked = Complete only

SSP & Compliance Foundation10

Core system documentation that ties the whole program together

📎System Security PlanSTARTERSSP-01
📎Policy Customization GuideSTARTERGUIDE-POL-MASTER
📎Master Customization GuidePROGUIDE-00
📎Implementation Roadmap & TrackerSTARTERROADMAP-01
📎CUI Data Inventory & Scoping WorksheetSTARTERCUI-SCOPE-01
📎Plan of Action & MilestonesSTARTERPOAM-TRK-01
📎Evidence & Implementation TrackerPROEVID-TRK-01
📎Compliance Monitoring & Maintenance SchedulePROMAINT-SCH-01
📎NIST 800-171 Self-Assessment WorkbookSTARTERNIST-SAW-01
📎FIPS Cryptographic Standards PolicySTARTERPOL-FIPS-01

Access Control (AC)14

📎Access Control — SSP SectionPROAC
📎Access Control PolicySTARTERPOL-AC-01
📎Access Control User Management ProcedurePROPRO-AC-01
📎Privileged Access Management ProcedurePROPRO-AC-02
📎Remote Access ProcedurePROPRO-AC-03
📎Wireless Access Control ProcedurePROPRO-AC-04
📎External Connections Boundary ProcedurePROPRO-AC-05
📎Least Privilege / Separation of Duties ProcedurePROPRO-AC-06
📎CUI Publicly Accessible Systems ProcedurePROPRO-AC-07
📎System Use Notification ProcedurePROPRO-AC-08
📎Separation of Duties MatrixSTARTERAC-SOD-01
📎RBAC Role DefinitionsSTARTERAC-3.1.2a
📎Non-Security Functions DefinitionPROAC-3.1.6a
📎Public Content Review LogPROAC-3.1.22d

Awareness & Training (AT)6

📎Awareness & Training — SSP SectionPROAT
📎Awareness & Training PolicySTARTERPOL-AT-01
📎Security Awareness Training ProcedurePROPRO-AT-01
📎Security Policy Overview DeckPROAT-OVR-01
📎Training Curriculum CatalogPROAT-CUR-01
📎Training Records RegisterPROAT-REC-01

Audit & Accountability (AU)9

📎Audit & Accountability — SSP SectionPROAU
📎Audit & Accountability PolicySTARTERPOL-AU-01
📎Audit Log Management ProcedurePROPRO-AU-01
📎Log Correlation & Analysis ProcedurePROAU-COR-01
📎Logging Configuration BaselinePROAU-CFG-01
📎Log Review RegisterSTARTERAU-LOG-01
📎Log Review ChecklistPROAU-LOG-01
📎Audit Event Logging MatrixSTARTERAU-MAT-01
📎SIEM Correlation Rule RegisterSTARTERAU-RUL-01

Configuration Management (CM)11

📎Configuration Management — SSP SectionPROCM
📎Configuration Management PolicySTARTERPOL-CM-01
📎Baseline Configuration Management ProcedurePROPRO-CM-01
📎Software Allowlisting & System Inventory ProcedurePROPRO-CM-02
📎Change Management ProcedurePROPRO-CM-03
📎Mobile Device MDM ProcedurePROPRO-CM-04
📎Baseline Configuration DocumentPROCM-BAS-01
📎Hardware & Software InventorySTARTERCM-INV-01
📎Configuration Baseline MatrixSTARTERCM-MAT-01
📎Configuration Change RegisterSTARTERCM-LOG-01
📎Configuration Change Request FormPROCM-CHG-01

Identification & Authentication (IA)10

📎Identification & Authentication — SSP SectionPROIA
📎Identification & Authentication PolicySTARTERPOL-IA-01
📎Account Lifecycle Management ProcedurePROPRO-IA-01
📎Authentication Management ProcedurePROPRO-IA-02
📎Privileged Service Account Authentication ProcedurePROPRO-IA-03
📎Device & System Authentication ProcedurePROPRO-IA-04
📎Authenticator Protection & Compromise Response ProcedurePROPRO-IA-05
📎Account & Identity InventorySTARTERIA-INV-01
📎Identity & Authenticator MatrixPROIA-MAT-01
📎Authenticator Review LogPROIA-LOG-01

Incident Response (IR)13

📎Incident Response — SSP SectionPROIR
📎Incident Response PolicySTARTERPOL-IR-01
📎Incident Handling ProcedurePROPRO-IR-01
📎Incident Response Testing ProcedurePROPRO-IR-02
📎Incident Response PlanPROIR-PLN-01
📎Ransomware PlaybookPROIR-PLB-01
📎Data Breach PlaybookPROIR-PLB-02
📎Phishing Attack PlaybookPROIR-PLB-03
📎Malware PlaybookPROIR-PLB-04
📎Insider Threat PlaybookPROIR-PLB-05
📎DDoS Attack PlaybookPROIR-PLB-06
📎Zero-Day Attack PlaybookPROIR-PLB-07
📎Incident Log RegisterPROIR-LOG-01

Maintenance (MA)8

📎Maintenance — SSP SectionPROMA
📎System Maintenance PolicySTARTERPOL-MA-01
📎Maintenance Operations ProcedurePROPRO-MA-01
📎Remote Maintenance ProcedurePROPRO-MA-02
📎Maintenance Tool & Media Control ProcedurePROPRO-MA-03
📎Maintenance Personnel Authorization ProcedurePROPRO-MA-04
📎Approved Maintenance Tools MatrixSTARTERMA-MAT-01
📎Maintenance Activity LogSTARTERMA-LOG-01

Media Protection (MP)9

📎Media Protection — SSP SectionPROMP
📎Media Protection PolicySTARTERPOL-MP-01
📎Media Handling & Storage ProcedurePROPRO-MP-01
📎Media Transport ProcedurePROPRO-MP-02
📎Media Sanitization & Destruction ProcedurePROPRO-MP-03
📎Media Access Accountability ProcedurePROPRO-MP-04
📎CUI Backup & Recovery ProcedurePROPRO-MP-BK
📎Media Inventory & Accountability MatrixSTARTERMP-MAT-01
📎Media Lifecycle Event LogSTARTERMP-LOG-01

Personnel Security (PS)5

📎Personnel Security — SSP SectionPROPS
📎Personnel Security PolicySTARTERPOL-PS-01
📎Personnel Screening & Onboarding ProcedurePROPRO-PS-01
📎Personnel Transfer & Role Change ProcedurePROPRO-PS-02
📎Personnel Termination & Offboarding ProcedurePROPRO-PS-03

Physical Protection (PE)11

📎Physical Protection — SSP SectionPROPE
📎Physical Protection PolicySTARTERPOL-PE-01
📎Physical Access Control ProcedurePROPRO-PE-01
📎Visitor Control & Escort ProcedurePROPRO-PE-02
📎Physical Access Monitoring ProcedurePROPRO-PE-03
📎Physical Media Storage & Facility Protection ProcedurePROPRO-PE-04
📎Physical Access Authorization Review ProcedurePROPRO-PE-05
📎Physical Access Authorization MatrixSTARTERPE-MAT-01
📎Physical Access InventorySTARTERPE-INV-01
📎Physical Access LogSTARTERPE-LOG-01
📎Visitor Sign-In LogSTARTERPE-LOG-02

Risk Assessment (RA)10

📎Risk Assessment — SSP SectionPRORA
📎Risk Assessment PolicySTARTERPOL-RA-01
📎Risk Assessment ProcedurePROPRO-RA-01
📎Vulnerability Scanning ProcedurePROPRO-RA-02
📎Risk Response & Treatment ProcedurePROPRO-RA-03
📎Risk Assessment ReportPRORA-RPT-01
📎Risk Assessment Report — Worked ExamplePRORA-RPT-01 ex
📎Risk Assessment WorkbookPRORA-WRK-01
📎Risk RegisterPRORA-MAT-01
📎Vulnerability Tracking RegisterPRORA-VUL-01

Security Assessment (CA)6

📎Security Assessment — SSP SectionPROCA
📎Security Assessment PolicySTARTERPOL-CA-01
📎Security Assessment & Plan of Action ProcedurePROPRO-CA-01
📎POA&M Management ProcedurePROPRO-CA-02
📎Continuous Monitoring ProcedurePROPRO-CA-03
📎Security Assessment Report TemplatePROCA-SAR-01

System & Communications Protection (SC)9

📎System & Communications Protection — SSP SectionPROSC
📎System & Communications Protection PolicySTARTERPOL-SC-01
📎Logical Boundary Protection / Conditional Access ProcedurePROPRO-SC-01
📎Cryptographic Protection & Key Management ProcedurePROPRO-SC-02
📎Remote Access Session Security ProcedurePROPRO-SC-03
📎FIPS Cryptographic Implementation ProcedurePROPRO-FIPS-01
📎FIPS Certificate Reference & TrackerPROCMVP-TRK-01
📎Cryptographic Standards Compliance LogPROSC-LOG-01
📎Cryptographic Key RegisterPROSC-LOG-02

System & Information Integrity (SI)7

📎System & Information Integrity — SSP SectionPROSI
📎System & Information Integrity PolicySTARTERPOL-SI-01
📎Flaw Remediation & Patch Management ProcedurePROPRO-SI-01
📎Malicious Code Protection ProcedurePROPRO-SI-02
📎Security Monitoring & Intrusion Detection ProcedurePROPRO-SI-03
📎Patch & Vulnerability Remediation LogSTARTERSI-LOG-01
📎Security Monitoring & Anomaly Detection LogSTARTERSI-LOG-03

Agreements & Forms7

📎Acceptable Use AgreementSTARTERAGR-AUP-01
📎Bring Your Own Device AgreementSTARTERAGR-BYOD-01
📎CUI Handling AgreementSTARTERAGR-CUI-01
📎Policy Acknowledgment FormSTARTERAGR-POL-01
📎Remote Work Security AgreementSTARTERAGR-RWK-01
📎Sensitive Information Protection AgreementSTARTERAGR-SIP-01
📎System Access Request & Approval FormSTARTERACC-REQ-01

Assessment Preparation (APREP)16

Assessor questions and evidence requirements, per practice

📎Assessment Preparation Master GuideAPREP-MASTER-01
📎Access ControlAPREP-AC-01
📎Awareness & TrainingAPREP-AT-01
📎Audit & AccountabilityAPREP-AU-01
📎Security Assessment & AuthorizationAPREP-CA-01
📎Configuration ManagementAPREP-CM-01
📎Identification & AuthenticationAPREP-IA-01
📎Incident ResponseAPREP-IR-01
📎MaintenanceAPREP-MA-01
📎Media ProtectionAPREP-MP-01
📎Physical & Environmental ProtectionAPREP-PE-01
📎Personnel SecurityAPREP-PS-01
📎Risk AssessmentAPREP-RA-01
📎System & Communications ProtectionAPREP-SC-01
📎System & Information IntegrityAPREP-SI-01
📎Assessment Evidence PlanSTARTEREvidence-Plan

Automation Scripts56

Python + PowerShell for Microsoft 365 GCC High

📎Automation Scripts Deployment GuideAUTO-GUIDE-01
📎MFA Enrollment ReportGCCH-01
📎Stale Account AuditorGCCH-02
📎Privileged Role InventoryGCCH-03
📎Conditional Access ExporterGCCH-04
📎Unified Audit Log ExtractorGCCH-05
📎Audit Log Retention VerifierGCCH-06
📎Admin Activity ReportGCCH-07
📎Device Compliance SnapshotGCCH-08
📎Software Inventory ExporterGCCH-09
📎Secure Score POA&M BuilderGCCH-10
📎Vulnerability ReportGCCH-11
📎Patch Compliance ReportGCCH-12
📎External Sharing AuditorGCCH-13
📎Sensitivity Label Coverage ReportGCCH-14
📎DLP Policy Status ExporterGCCH-15
📎Risky Sign-Ins ReportGCCH-16
📎Guest & External User AuditorGCCH-17
📎Monthly Evidence BundleGCCH-18
📎Service Principal AuditorGCCH-19
📎Legacy Auth Protocol ReporterGCCH-20
📎Break-Glass Account VerifierGCCH-21
📎Named Location AuditorGCCH-22
📎Mailbox Audit Enhancement ReportGCCH-23
📎Email Forwarding Exfil DetectorGCCH-24
📎Teams Governance AuditorGCCH-25
📎Secure Score Delta TrackerGCCH-26
📎EOP Safe Policy ExporterGCCH-27
📎Power Platform DLP ReporterGCCH-28
📎Defender Alert & Incident ReporterGCCH-29
📎Sign-In Anomaly Pattern AnalyzerGCCH-30
📎Defender Identity Alert ReporterGCCH-31
📎OneDrive External Sharing ReporterGCCH-32
📎Purview Sensitivity Label ReporterGCCH-33
📎Communication Compliance ExporterGCCH-34
📎Intune Configuration Baseline CheckerGCCH-35
📎Remote Access VPN AuditorGCCH-36
📎NIST 800-171 Readiness Dashboard GeneratorGCCH-37
📎Access Recertification Workbook BuilderGCCH-38
📎Endpoint Protection Health PollerGCCH-39
📎CVE Advisory WatcherGCCH-40
📎Network Boundary Controls ReviewerGCCH-41
📎SSL/TLS Certificate Expiry CheckerGCCH-42
📎NIST 800-171 POA&M Progress TrackerGCCH-43
📎Privileged Account Password Rotation ReporterGCCH-44
📎OAuth Consent Grant AuditorGCCH-45
📎Exchange Litigation Hold ReporterGCCH-46
📎SharePoint Site Permissions AuditorGCCH-47
📎Exchange Transport Rule Risk AuditorGCCH-48
📎DNS Security Bulk CheckerGCCH-49
📎Privileged Account Activity TimelineGCCH-50
📎Admin Non-Security Usage DetectorGCCH-51
📎Annual Training Completion ReportGCCH-52
📎Sentinel Analytics Rules — ARM TemplateJSON
📎Intune Policies BundleJSON
📎Automation Config Filegcch_config

Microsoft 365 & Sentinel Guides8

Step-by-step configuration for GCC High

📎MFA & Conditional AccessPROM365-01
📎Purview CUI Labeling & DLPPROM365-02
📎Defender for EndpointPROM365-03
📎Sentinel SIEMPROM365-04
📎Audit LoggingPROM365-05
📎Intune Endpoint ManagementPROM365-06
📎Exchange Email SecurityPROM365-07
📎SharePoint & OneDrive SecurityPROM365-08

Reference & Architecture1

Editable PowerPoint — network topology and CUI data flow diagrams you adapt to your environment

📎GCC High Network Architecture & CUI Data Flow DiagramsPROPPTX

See the quality before you decide

Read a complete domain — the real policy, SSP language, procedure, and assessor questions — free.

Get the free AU sample pack