Many business owners are still struggling to understand the basic processes associated with obtaining a CMMC certification. We created the infographic below to illustrate the steps along the path to CMMC certification and maintenance. Like many of our materials, this infographic is freely shareable under the Creative Commons CC-BY-ND license. A PDF copy is also available for download below.
- Reforming CMMC and Reducing Compliance Burden for the DIB
- False Claims Act in 2025 – Key take-aways
- CUI Institute Public Comments on FAR CUI Rule
- CMMC: A National Imperative
- Disseminating CUI to Someone Else (e.g., Mary)
- CUI Recipient Preparedness Questionnaire
- CUI and CMMC in a Nutshell
- Mavis’s Machine Shop Attributes (Employees, Roles, Teams)
- Mavis’ Machine Shop Written Information Security Policy
- Mavis’ Machine Shop Data Breach and Incident Response Policy and Plan
- Mavis’ Machine Shop Network Diagram
- Mavis’ Machine Shops Site 2 Data Flow Diagram
- Mavis’ Machine Shops Site 2 Map
- Mavis’ Machine Shop Site 1 Map
- Protecting the Government’s Information – Version 2023.03a
- 3.11.2 – Vulnerability Scans (Kevin Mann)
- CMMC: Budgets, Competition, and Protests…Oh My! (Eric Crusius and Josh Duvall) – Slides
- CMMC Workflow: Pre-Kickoff to Done (Thomas Graham and Robert Teague) – Slides
- 3.14.1 – Flaw Remediation (Thomas Graham) – Slides
- 3.1.11 – Terminate (Automatically) a User Session After a Defined Condition (Robert Teague) – Slides
- Evidence & Path to Compliance (Regan Edens) – Slides
- CMMC in Higher Education (Amy Starzynski Coddens, Jason Pufahl, Mike Corn) – Slides
- Techniques for Assessing a Remote Work Environment (Tara Lemieux) – Slides
- v2023.02a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- Standardizing the Assessment Experience (Ben Tchoubineh) – Slides
- Helping Business Leaders to care about Cybersecurity (Ace Swerling) – Slides
- Gap Assessment Workflow (Leia Shilobod) – Slides
- Shared Responsibility Matrices (Carley Salmon and Robert McVay) – Slides
- Scoping your Environment (Matt Titcombe) – Slides
- Pricing Gap Assessments (Toby Musser) – Slides
- 3.11.1 Risk Assessments (Robert McVay) – Slides
- 3.5.3 Multifactor Authentication (Fernando Machado) – Slides
- Practical Approaches to Testing CMMC Compliance (Kyle Lai) – Slides
- 3.1.3 Controlling CUI Flow (Matt Hoeper) – Slides
- 3.14.1 Flaw Remediation (Thomas Graham) – Slides
- Finding Prep Expertise and a C3PAO (Joy Beland) – Workbook
- Finding Prep Expertise and a C3PAO (Joy Beland) – Slides
- OLD – v2022.11a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- v.2021.10a – The CMMC Assessment Lifecycle
- OLD – v2022.08d – Comprehensive FAR and Above and NIST SP 800-171 Self-Assessment and DoD SPRS Scoring Tool
- OLD – FAR and Above Phased Approach to NIST SP 800-171 and CMMC Compliance
- Policy – Client Data Breach Incident Response Policy
- Plan – Client Data Breach Incident Response
- List – Processes Authorized to Act on Behalf of a User
- List – Employees and Authorized Users
- List – Authorized Visitors
- Worksheet – Client Data Breach Incident Response
- Record – Meeting Agenda
- Procedure – Employee Offboarding
- Policy – Nondiscrimination and Anti-Harassment
- Policy – Information Systems Audit
- Policy – Data Protection
- Open Letter to the President Regarding CMMC 2.0
- US DoD 2021-NOV-04 – Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward
- DFARS Clause Applicability Decision Tree
- The CMMC Assessment Lifecycle – OLD
- Paper and Electronic Media (“Media”) Certificate of Destruction/Sanitization
- C3PAO ISO 17020 and 17021 Slides – Part 3
- C3PAO ISO 17020 and 17021 Slides – Part 2
- C3PAO ISO 17020 and 17021 Slides – Part 1
- DCMA C3PAO CMMC Assessment Lessons Learned
- CMMC-AB Statement of Work
- CUI Disclosure Decision Trees

