Open Reference Library
For the DIB
OpenCMMC.
Curated by Howder Labs
Free Templates
For the DIB
Open Resource Free Templates Real References
Vol. I  ·  An Open Reference  ·  MMXXVI

CMMC, open.
For the contractors who actually need it.

An open reference library and template archive for the Defense Industrial Base. Curated by federal practitioners, given away because the underlying frameworks were never meant to be hoarded by consultants.

i. Part One

The reference library.

Direct links to the authoritative publications that govern CMMC, RMF, and DFARS compliance. The underlying material is free and public. We just put it in one place.

Why Open
The frameworks are public. The controls are public. The assessment procedures are public. The templates should be too.
A note from the maintainers  ·  Howder Labs
ii. Part Two

Template bundles.

Working templates for SSPs, policies, and procedures. Request a bundle and we will email you the download. No payment, no upsell.

ii.iLevel 1

CMMC Level 1 Policies

For contractors handling Federal Contract Information (FCI).

A complete policy starter kit aligned to the 17 controls of FAR 52.204-21 and CMMC Level 1. Designed for contractors who handle FCI but not CUI, who need to demonstrate basic safeguarding before bidding on prime work.

  • Acceptable Use Policy
  • Access Control Policy
  • Identification & Authentication
  • Media Protection Procedure
  • Physical Protection Policy
  • System Communications Policy
Request Bundle
ii.iiLevel 2

CMMC Level 2 Policies

For contractors handling Controlled Unclassified Information (CUI).

The full 110-control documentation kit aligned to NIST 800-171 and DFARS 252.204-7012. Includes every policy and procedure a CMMC Level 2 assessment will look for. Built from the same template set Howder Labs uses with paying clients.

  • Full 14-Family Policy Set
  • Procedures & Standards
  • Access Control, Audit, & Accountability
  • Incident Response Plan
  • Configuration Management
  • Risk Assessment & SCA
Request Bundle
ii.iiiSSP

System Security Plan Template

Standalone SSP template structured to NIST 800-171.

A complete SSP shell with every 800-171 control prepopulated, ready for you to fill in environment, scope, and implementation specifics. Includes a guided framework for boundary diagrams, asset categorization, and POA&M tracking.

  • 110-Control SSP Skeleton
  • System Boundary Definition
  • CUI Flow & Asset Categorization
  • POA&M Template
  • Implementation Status Tracking
  • Continuous Monitoring Plan
Request Template
ii.ivSupplemental

Other Templates

Standalone policies and procedures for specific gaps.

Individual documents for organizations that have most of their compliance documentation in place but need to fill specific gaps. Useful for spot-augmenting an existing SSP or responding to assessor findings.

  • Password Policy
  • Incident Response Plan
  • Acceptable Use Policy
  • Backup & Recovery Procedure
  • Remote Access Policy
  • Sanitization & Disposal
Request Templates
Need More Than Templates

When the documents aren't enough.

Templates get you 60% of the way to an assessment. The other 40% is environment-specific implementation, evidence collection, and defending the artifacts in front of a real assessor. That's where Howder Labs is paid to help.

The firm behind OpenCMMC.

Howder Labs is an SDVOSB cybersecurity firm built by a former NASA Information System Owner and Navy Validator. We deliver CMMC readiness, managed security, and federal IT for Defense Industrial Base contractors.

Visit Howder Labs