For small defense subcontractors
A System Security Plan draft mapped to all 110 NIST 800-171 controls, built from what you actually have in place.
Tell us your environment and what you already do. Get back a tailored SSP draft covering all 110 controls, 14 policy documents, a pre-filled POA&M, and a self-assessment score worksheet using the SPRS methodology.
Within 24 hours
- No call, no meeting, no account
- Prepared under a 17-year supply chain principal
- Full refund if it cannot be produced from what you send
Who this is for
Small defense subcontractor facing a CMMC Level 1 or 2 requirement in a prime contract
Company that has never written a formal SSP and does not know where to start
Owner-operator IT shop with no compliance staff and a looming assessment deadline
“A prime contractor or the DFARS clause in your contract now requires a CMMC self-assessment or a C3PAO assessment, and you have 110 controls to document with no security staff and no template that matches your actual environment. Consultants that do this from scratch charge thousands and take weeks.”
What you get
- SSP draft mapped to all 110 NIST SP 800-171 controls: implemented, planned, or N/A, based on your stated facts
- 14 policy documents, one per control family
- POA&M template pre-filled with your identified gaps
- Self-assessment score worksheet (SPRS methodology)
Inside the document
Control 3.1.1 (Limit system access to authorized users): Implemented, Microsoft 365 GCC conditional access policy
Control 3.5.3 (Multifactor authentication): Planned, target date [[FLAG]]needs a target date from you[[/FLAG]]
POA&M item: MFA rollout for remote users, owner: [company], target: 90 days
SPRS worksheet: estimated score -12 of 110, pending 3 unresolved items
What changes after delivery
Within 24 hours you have an SSP draft covering all 110 controls, 14 policy documents, a POA&M pre-filled with your gaps, and an SPRS score worksheet, so you know exactly where you stand before an assessor or a prime contract audit does.
How people use it
- 1Hand the SSP and policies to your facility security officer or IT lead to review and adopt
- 2Work the POA&M items in priority order ahead of your assessment window
- 3Use the SPRS worksheet to submit your self-assessment score if targeting Level 1 or Level 2 self-assessment
How this compares
How it works
Fill the form
Five minutes. Attach what you have.
Pay $499
Card checkout opens right here on this page; card details go to Stripe only.
Production runs
Numbers computed on our servers; analysis checked against public records.
Delivered by email
Usually within 24 hours, as a document you can print or forward.
Order: CMMC Level 1-2 / NIST SP 800-171 SSP + Policy Pack
⏰ About 5 minutes · a handful of questions
Questions
Does this get me certified?
No. It gives you a draft SSP, policies, and a POA&M to work from. Certification is decided by a C3PAO (Level 2) or your own attestation (Level 1), not by us.
Will this match my actual environment?
The control status (implemented/planned/N/A) is based entirely on what you tell us in the intake form. The more specific you are, the more accurate the draft.
How fast is delivery?
Most packs are delivered within 24 hours.
Refunds?
If the pack cannot be produced from what you submitted, full refund. Delivered packs are non-refundable.
Built from your actual stated environment and controls, not a generic template copied from a government sample, with a refund if the pack cannot be produced from what you submit.
Sudip Malakar, Principal · Malakar Consulting