CMMC without the consultant retainer.
Run your Level 1 or Level 2 program, generate your SSP and POA&M, and hand your C3PAO a portal instead of a folder.
What CMMC actually demands
If you are in the defense supply chain, CMMC is not optional and it is not a one-off. Level 1 is 17 practices you self-assess annually. Level 2 is 110 practices drawn from NIST SP 800-171, assessed by a C3PAO every three years, with a System Security Plan and a POA&M you are expected to produce on request.
Most small defense contractors are doing this in Word and Excel, paying a consultant to rebuild the SSP each cycle, and discovering the gaps three weeks before an assessment.
OpenGRC includes the bundles — CMMC 2.0 Level 1 and Level 2, NIST SP 800-171 r2 and r3, 800-53, and DFARS 252.204 — and the artefacts that go with them, at no extra cost on any plan.
The three artefacts every assessor asks for.
System Security Plan, generated
Your SSP is a required deliverable, and rebuilding it by hand every cycle is where the consultant hours go. OpenGRC generates it as a PDF from your live control implementations, so it reflects what you actually do rather than what you documented two years ago.
POA&M that tracks itself
Every unmet practice becomes a remediation project with auto-coded tasks, subtasks, milestones and owners. Findings from an audit flow straight into it, and the POA&M exports as a PDF when someone asks for it.
Evidence tied to practices
Each practice carries its implementation, maturity, test procedures and evidence. When an assessor asks how you satisfy AC.L2-3.1.1, the answer and its proof are in one place.
How OpenGRC supports a CMMC program
| What CMMC requires | In OpenGRC |
|---|---|
| Implement 17 (L1) or 110 (L2) practices | CMMC 2.0 Level 1 and Level 2 bundles, plus NIST SP 800-171 r2 and r3 |
| System Security Plan | One-click SSP export as PDF, generated from live implementations |
| Plan of Action & Milestones | Remediation projects with auto-coded tasks, milestones, Kanban and POA&M report PDF |
| Annual self-assessment (L1) or triennial C3PAO assessment (L2) | Audit management with wizard-scoped audits, per-item assessment and draft or final report PDFs |
| Evidence for each practice | Implementation tracking with maturity, test procedures and attached evidence |
| Give an assessor access to your program | External auditor portal — MFA, time-bounded and revocable, IP allow-listing, immutable versioned submissions |
| Flow-down to subcontractors | Vendor management with questionnaires, risk scoring and compliance document expiry tracking |
| Incident reporting obligations | Incident response with playbooks, timeline and breach notification deadline tracking |
| Keep it current between assessments | Workflow automation for recurring reviews, plus recurring assessment cadence on every control |
CMMC questions
Which CMMC frameworks are included?
CMMC 2.0 Level 1 (17 practices) and Level 2 (110 practices), plus NIST SP 800-171 r2 and r3, NIST 800-53 at Low, Moderate and High baselines, and DFARS 252.204. All included on every plan with no per-framework fees.
™