For small defense subcontractors

A System Security Plan draft mapped to all 110 NIST 800-171 controls, built from what you actually have in place.

Tell us your environment and what you already do. Get back a tailored SSP draft covering all 110 controls, 14 policy documents, a pre-filled POA&M, and a self-assessment score worksheet using the SPRS methodology.

$499one report, one price, delivered by email

Within 24 hours

  • No call, no meeting, no account
  • Prepared under a 17-year supply chain principal
  • Full refund if it cannot be produced from what you send

Who this is for

Small defense subcontractor facing a CMMC Level 1 or 2 requirement in a prime contract

Company that has never written a formal SSP and does not know where to start

Owner-operator IT shop with no compliance staff and a looming assessment deadline

“A prime contractor or the DFARS clause in your contract now requires a CMMC self-assessment or a C3PAO assessment, and you have 110 controls to document with no security staff and no template that matches your actual environment. Consultants that do this from scratch charge thousands and take weeks.”

What you get

  • SSP draft mapped to all 110 NIST SP 800-171 controls: implemented, planned, or N/A, based on your stated facts
  • 14 policy documents, one per control family
  • POA&M template pre-filled with your identified gaps
  • Self-assessment score worksheet (SPRS methodology)

Inside the document

MalakarConsulting Reference MC-XXXXXX-XXXX · Prepared for CMMC / NIST 800-171 SSP pack

Control 3.1.1 (Limit system access to authorized users): Implemented, Microsoft 365 GCC conditional access policy

Control 3.5.3 (Multifactor authentication): Planned, target date [[FLAG]]needs a target date from you[[/FLAG]]

POA&M item: MFA rollout for remote users, owner: [company], target: 90 days

SPRS worksheet: estimated score -12 of 110, pending 3 unresolved items

What changes after delivery

Within 24 hours you have an SSP draft covering all 110 controls, 14 policy documents, a POA&M pre-filled with your gaps, and an SPRS score worksheet, so you know exactly where you stand before an assessor or a prime contract audit does.

How people use it

  1. 1Hand the SSP and policies to your facility security officer or IT lead to review and adopt
  2. 2Work the POA&M items in priority order ahead of your assessment window
  3. 3Use the SPRS worksheet to submit your self-assessment score if targeting Level 1 or Level 2 self-assessment

How this compares

This reportThe alternative
Cost$499 flatConsultant engagement, often $3,000-$10,000+
TurnaroundWithin 24 hoursWeeks, scheduled around consultant availability
ScopeAll 110 controls plus 14 policies and a POA&MVaries by engagement

How it works

1

Fill the form

Five minutes. Attach what you have.

2

Pay $499

Card checkout opens right here on this page; card details go to Stripe only.

3

Production runs

Numbers computed on our servers; analysis checked against public records.

4

Delivered by email

Usually within 24 hours, as a document you can print or forward.

Order: CMMC Level 1-2 / NIST SP 800-171 SSP + Policy Pack

⏰ About 5 minutes · a handful of questions

Questions

Does this get me certified?

No. It gives you a draft SSP, policies, and a POA&M to work from. Certification is decided by a C3PAO (Level 2) or your own attestation (Level 1), not by us.

Will this match my actual environment?

The control status (implemented/planned/N/A) is based entirely on what you tell us in the intake form. The more specific you are, the more accurate the draft.

How fast is delivery?

Most packs are delivered within 24 hours.

Refunds?

If the pack cannot be produced from what you submitted, full refund. Delivered packs are non-refundable.

Sudip Malakar

Built from your actual stated environment and controls, not a generic template copied from a government sample, with a refund if the pack cannot be produced from what you submit.

Sudip Malakar, Principal · Malakar Consulting

$499Start your order →