Skip to main content
Compliance

CMMC Policy Documentation: Covering the 14 Control Families

A guide to documenting policies and procedures that support NIST SP 800-171 Rev 2 across its 14 control families.

CMMC Command Team
Compliance Engineering
Feb 24, 20269 min read
Table of Contents(20 sections)

Policies Are the Foundation of CMMC Compliance

During a C3PAO assessment, policies and procedures may be reviewed alongside interviews, demonstrations, configurations, logs, and other objective evidence. Policies demonstrate a documented approach but must match actual implementation.

NIST SP 800-171A assessment objectives frequently require assessors to determine whether an organization has defined, implemented, and documented relevant practices. The form of that evidence can vary.

Policy Coverage Across 14 Control Families

NIST SP 800-171 does not prescribe exactly 14 standalone policy documents. Organizations may use one policy per family, combine related topics, or separate policies and procedures, provided the evidence addresses the applicable requirements.

1. Access Control Policy (AC)

Topics to map when applicable:

  • User access provisioning and deprovisioning procedures
  • Least privilege and need-to-know principles
  • Remote access authorization and monitoring
  • Wireless access restrictions
  • Mobile device access controls
  • Session lock and termination settings

2. Awareness & Training Policy (AT)

Topics to map when applicable:

  • Security awareness training requirements and frequency
  • Role-based training for privileged users
  • CUI handling training
  • Insider threat awareness program
  • New hire training timeline
  • Training record retention

3. Audit & Accountability Policy (AU)

Topics to map when applicable:

  • Auditable events definition (login, logout, file access, privilege changes)
  • Log retention periods based on documented and applicable requirements
  • Log protection and integrity measures
  • Log review frequency and responsibilities
  • Incident correlation procedures
  • Time synchronization requirements

4. Configuration Management Policy (CM)

Topics to map when applicable:

  • Baseline configuration standards
  • Change management process
  • Security impact analysis for changes
  • Software whitelist/blacklist approach
  • Configuration monitoring
  • Unauthorized change response

5. Identification & Authentication Policy (IA)

Topics to map when applicable:

  • User identification requirements
  • Multifactor authentication policy
  • Password complexity and lifecycle requirements
  • Account lockout thresholds
  • Service account management
  • Authenticator management (tokens, certificates)

6. Incident Response Policy (IR)

Topics to map when applicable:

  • IR team composition and roles
  • Incident categories and severity levels
  • Detection and reporting procedures
  • Containment and eradication steps
  • Recovery procedures
  • Lessons learned process
  • Annual testing requirements

7. Maintenance Policy (MA)

Topics to map when applicable:

  • Scheduled maintenance procedures
  • Remote maintenance authorization and monitoring
  • Maintenance personnel authorization
  • Maintenance tool controls
  • Equipment sanitization before external maintenance

8. Media Protection Policy (MP)

Topics to map when applicable:

  • Media marking requirements (CUI designation)
  • Media storage protections
  • Media transport controls
  • Media sanitization and destruction per NIST 800-88
  • Removable media restrictions

9. Personnel Security Policy (PS)

Topics to map when applicable:

  • Background screening requirements
  • CUI access authorization process
  • Personnel termination procedures (access revocation timeline)
  • Personnel transfer procedures
  • Visitor management

10. Physical Protection Policy (PE)

Topics to map when applicable:

  • Physical access authorization
  • Visitor escort and monitoring
  • Physical access logs
  • Alternative work site security
  • Equipment and media disposal

11. Risk Assessment Policy (RA)

Topics to map when applicable:

  • Risk assessment methodology and frequency
  • Vulnerability scanning requirements and frequency
  • Risk response strategies
  • Risk acceptance criteria and authority

12. Security Assessment Policy (CA)

Topics to map when applicable:

  • Control assessment methodology and frequency
  • Plan of action and milestones (POA&M) management
  • Continuous monitoring strategy
  • System authorization boundaries

13. System & Communications Protection Policy (SC)

Topics to map when applicable:

  • Network boundary protection
  • CUI transmission encryption requirements
  • CUI storage encryption requirements
  • Network segmentation approach
  • Collaborative computing restrictions
  • Public-facing system restrictions

14. System & Information Integrity Policy (SI)

Topics to map when applicable:

  • Flaw remediation and patching timeline
  • Malicious code protection requirements
  • Security alert monitoring
  • System monitoring approach
  • Spam protection

What Every Policy Must Include

Regardless of the control family, every policy document should contain:

  1. Purpose statement: Why this policy exists
  2. Scope: Who and what it applies to
  3. Roles and responsibilities: Who enforces and who follows
  4. Policy statements: The actual requirements
  5. Procedures: How to implement the policy
  6. Exceptions process: How to request and document exceptions
  7. Violations and enforcement: Consequences of non-compliance
  8. Review cycle: Organization-defined cadence, change triggers, and process
  9. Version history: Track changes over time
  10. Approval signatures: Management endorsement

Policy Maintenance

Policies should reflect the assessed environment and actual practice. Qualified reviewers may examine:

  • Review dates: Was the policy reviewed on the organization-defined cadence and after relevant changes?
  • Version history: Has it been updated to reflect changes?
  • Acknowledgments: Have all relevant personnel signed?
  • Consistency: Does the policy match actual practice?

Common Policy Mistakes

  1. Copy-paste without customization: Assessors spot generic policies immediately
  2. Overly complex language: Policies should be readable by all staff
  3. Disconnected from practice: Your policy says one thing, but your systems do another
  4. Missing acknowledgments: No proof that staff have read and accepted the policy
  5. Stale documents: The document no longer reflects the system or current practice

Using Policy Templates

Starting from templates is smart but customize them:

  • Replace generic placeholders with your organization's specifics
  • Align technology references to your actual tools
  • Ensure role names match your org chart
  • Set realistic review cycles you'll actually follow

CMMC Command includes 20 policy templates mapped to NIST control families, with AI-assisted drafting for Professional tier users and team acknowledgment tracking.

Generate your first policy. The Starter plan includes 5 policy templates.

PoliciesNIST 800-171DocumentationC3PAOTemplates

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.