CMMC without the consultant retainer.

Run your Level 1 or Level 2 program, generate your SSP and POA&M, and hand your C3PAO a portal instead of a folder.

What CMMC actually demands

If you are in the defense supply chain, CMMC is not optional and it is not a one-off. Level 1 is 17 practices you self-assess annually. Level 2 is 110 practices drawn from NIST SP 800-171, assessed by a C3PAO every three years, with a System Security Plan and a POA&M you are expected to produce on request.

Most small defense contractors are doing this in Word and Excel, paying a consultant to rebuild the SSP each cycle, and discovering the gaps three weeks before an assessment.

OpenGRC includes the bundles — CMMC 2.0 Level 1 and Level 2, NIST SP 800-171 r2 and r3, 800-53, and DFARS 252.204 — and the artefacts that go with them, at no extra cost on any plan.

Built for the assessment

The three artefacts every assessor asks for.

System Security Plan, generated

System Security Plan, generated

Your SSP is a required deliverable, and rebuilding it by hand every cycle is where the consultant hours go. OpenGRC generates it as a PDF from your live control implementations, so it reflects what you actually do rather than what you documented two years ago.

POA&M that tracks itself

POA&M that tracks itself

Every unmet practice becomes a remediation project with auto-coded tasks, subtasks, milestones and owners. Findings from an audit flow straight into it, and the POA&M exports as a PDF when someone asks for it.

Evidence tied to practices

Evidence tied to practices

Each practice carries its implementation, maturity, test procedures and evidence. When an assessor asks how you satisfy AC.L2-3.1.1, the answer and its proof are in one place.

How OpenGRC supports a CMMC program

What CMMC requiresIn OpenGRC
Implement 17 (L1) or 110 (L2) practicesCMMC 2.0 Level 1 and Level 2 bundles, plus NIST SP 800-171 r2 and r3
System Security PlanOne-click SSP export as PDF, generated from live implementations
Plan of Action & MilestonesRemediation projects with auto-coded tasks, milestones, Kanban and POA&M report PDF
Annual self-assessment (L1) or triennial C3PAO assessment (L2)Audit management with wizard-scoped audits, per-item assessment and draft or final report PDFs
Evidence for each practiceImplementation tracking with maturity, test procedures and attached evidence
Give an assessor access to your programExternal auditor portal — MFA, time-bounded and revocable, IP allow-listing, immutable versioned submissions
Flow-down to subcontractorsVendor management with questionnaires, risk scoring and compliance document expiry tracking
Incident reporting obligationsIncident response with playbooks, timeline and breach notification deadline tracking
Keep it current between assessmentsWorkflow automation for recurring reviews, plus recurring assessment cadence on every control

CMMC questions

Which CMMC frameworks are included?

CMMC 2.0 Level 1 (17 practices) and Level 2 (110 practices), plus NIST SP 800-171 r2 and r3, NIST 800-53 at Low, Moderate and High baselines, and DFARS 252.204. All included on every plan with no per-framework fees.

Does OpenGRC generate the SSP and POA&M?

Can my C3PAO assessor use it?

Does using OpenGRC make us CMMC certified?

We are a small shop. Is this realistic for us?