Professional Compliance Documentation

Consulting Deliverables Library

Premium templates and sample reports developed by our cybersecurity consultants. Each deliverable is available as a branded sample PDF and an editable Word template ready for client engagements.

Sample PDF — Branded showcaseEditable DOCX — Working template
21
Professional Documents
20
Editable DOCX Templates
110
NIST 800-171 Controls in SSP
Feb 2026
Last Updated

Engagement Template Map

Which documents to use at each phase of a CMMC Level 2 engagement. Follow the playbook for process; use the templates for deliverables.

Phase 1
Pre-Sales & Scoping
  • Scoping Questionnaire
  • NDA Template
  • Capability Brief
Phase 2
Kickoff & Collection
  • Document Request List
  • Client Comms Templates
Phase 3
Assessment
  • CMMC Gap Assessment
  • Vendor Questionnaire
  • QA Checklist
Phase 4
Deliverable Assembly
  • SSP (110 Controls)
  • POA&M Template
  • V-CISO Report
Phase 5
Remediation
  • IR Plan Template
  • TPRM Assessment
  • POA&M Template
Phase 6
C3PAO Prep
  • SSP (Final)
  • Gap Assessment
  • QA Checklist

Reference the CMMC Engagement Playbook for detailed step-by-step procedures at each phase

CMMC & Compliance

Mission-critical compliance documentation for defense contractors and regulated industries

PDFDOCX

CMMC Gap Assessment Report

CMMC Level 2 readiness assessment with SPRS scoring, risk heat map, and prioritized remediation roadmap. Now includes 25+ sample findings with real-world gap descriptions, evidence references, cost estimates, and remediation recommendations.

Executives & Compliance Teams
PDFDOCX

System Security Plan (SSP)

Complete SSP with all 110 NIST 800-171 Rev 2 controls — each with requirement text, implementation status fields, sample implementation language, evidence references, and responsible entities. Includes system boundary, SPRS scoring, and stakeholder documentation.

PDFDOCX

Plan of Action & Milestones (POA&M)

CMMC 2.0 compliant POA&M template with conditional certification rules, 180-day remediation tracking, resource planning, and milestone management.

Compliance Teams

Engagement Tools

Working artifacts for client engagements — questionnaires, checklists, and assessment tools referenced by the playbooks

PDFDOCX

CMMC Scoping Questionnaire

Pre-engagement questionnaire for CMMC Level 2 assessments. Covers organization profile, contract landscape, CUI environment, IT infrastructure, existing documentation, personnel, and timeline. Send within 24 hours of discovery call.

Consultants & Clients
PDFDOCX

Document Request List

Comprehensive evidence collection checklist with 118 items across 15 categories mapped to all 110 NIST 800-171 controls. Tracks collection status, dates received, and missing documentation gaps.

Consultants & Clients
PDFDOCX

Vendor Risk Assessment Questionnaire

10-section third-party security questionnaire for CUI subcontractors. Covers compliance status, CUI handling, access control, security operations, encryption, incident response, and personnel security with built-in scoring methodology.

TPRM Consultants & Vendors

Security Operations

Operational security templates for continuous monitoring, incident management, and risk assessment

PDFDOCX

V-CISO Monthly Report

Executive security posture report with dashboard metrics, CMMC progress tracking, threat landscape analysis, vulnerability trends, and strategic recommendations.

PDFDOCX

Incident Response Plan

NIST SP 800-61 incident response plan with DFARS 252.204-7012 compliance, DCISE reporting procedures, CUI handling protocols, and tabletop exercise scenarios.

Security & IT Teams
PDFDOCX

Third-Party Risk Management Assessment

SCF-based vendor risk assessment with 49-question security questionnaire across 8 domains, risk scoring methodology, and remediation tracking.

Procurement & Security

Legal & Agreements

Contract templates and legal frameworks for defense and federal engagements

PDFDOCX

Mutual Non-Disclosure Agreement

CUI-specific mutual NDA with DFARS compliance provisions, 72-hour incident reporting obligations, and controlled unclassified information handling requirements.

Legal & Executives
PDFDOCX

Federal Teaming Agreement

Federal teaming agreement template with SDVOSB provisions, SBA compliance, work share allocation, and flow-down FAR/DFARS clauses.

Legal & BD Teams

Staffing & Operations

Staffing engagement documentation and operational process guides

PDFDOCX

Staffing Master Service Agreement

Master staffing services agreement with 90-day guarantee, conversion fee schedules, SOW template, compliance requirements, and performance SLAs.

PDFDOCX

Candidate Vetting Process

Six-stage candidate vetting pipeline with sourcing channels, screening criteria, technical assessments, clearance verification, and quality metrics.

Internal & Clients

Executive

High-level capability overviews and strategic engagement materials

PDF

Executive Capability Brief

Two-page executive overview of Dominus Gray's capabilities, service offerings, differentiators, CMMC timeline, and engagement model.

Prospective Clients
Sample PDFPDF Only

Operational Playbooks

Internal standard operating procedures, engagement playbooks, and quality standards for service delivery

PDFDOCX

CMMC Engagement Playbook

End-to-end SOP for CMMC Level 2 assessments — pre-sales through C3PAO preparation with scoping checklists, control family assessment guide, SPRS scoring, and remediation advisory procedures.

Consultants & Engagement Leads
PDFDOCX

V-CISO Operations Playbook

Monthly operating cadence for V-CISO retainers — onboarding workflow, weekly activity structure, KPI tracking, QBR agenda, incident escalation, and technology stack recommendations.

V-CISO Consultants
PDFDOCX

Incident Response Retainer Playbook

IR retainer management SOP — client onboarding, incident activation protocol, severity classification, containment procedures, DCISE reporting, post-incident review, and tabletop exercise guide.

IR Team & Consultants
PDFDOCX

TPRM Engagement Playbook

Third-party risk management delivery process — vendor inventory, risk categorization, 49-question assessment workflow, scoring methodology, remediation tracking, and program build deliverables.

TPRM Consultants
PDFDOCX

Staffing Operations Playbook

Cleared cybersecurity staffing SOP — client intake, sourcing strategy, 6-stage vetting pipeline, interview coordination, onboarding, milestone check-ins, billing, and SDVOSB compliance.

Recruiters & Account Managers
PDFDOCX

Quality Assurance Checklist

Pre-delivery review checklist covering document completeness, placeholder removal, accuracy verification, formatting standards, writing quality, technical accuracy, and security handling.

PDFDOCX

Client Communication Templates

Standardized email templates for the full engagement lifecycle — discovery follow-up, proposals, kickoff invitations, document requests, status reports, deliverable transmittals, and incident activation.

All Client-Facing Staff

Need Custom Documentation?

Our consultants can develop tailored compliance documentation, security plans, and operational templates specific to your organization's requirements and regulatory obligations.