⚠️ CMMC 2.0 Final Rule is in effect — C3PAO assessments are underway now. If your contracts include DFARS 252.204-7021, you are already required to be compliant.
CMMC 2.0 Compliance

The Complete CMMC 2.0 Toolkit for US Defence Contractors

Everything you need to achieve CMMC Level 2 certification — gap assessments, SSP templates, POA&M, evidence packs, a 90-day roadmap, and NIST 800-171 mapping. Built by a CISM and CISA.

Get the Full Toolkit — £497 Start with Level 1 — £97

Instant download · Perpetual licence · Free updates for 12 months (Full Toolkit)

Prepared by Michael Adedeji CISM CISA CEH CC · Pyralink Innovation Ltd · Framework Coverage: CMMC 2.0 Final Rule (32 CFR Part 170) · NIST SP 800-171 Rev 2 · DFARS 252.204-7021

Why Most Defence Contractors Fail Their CMMC Assessment

CMMC 2.0 Level 2 requires your organisation to implement all 110 practices from NIST SP 800-171. You also need to document everything in a System Security Plan (SSP), track every gap in a Plan of Action and Milestones (POA&M), collect objective evidence for each control, and demonstrate to a C3PAO that your controls are real, implemented, and working.

Most contractors stumble at the documentation stage. Not because they haven't done the technical work — but because they don't know exactly what to document, how to structure the SSP, what evidence an assessor will accept, or how to sequence the remediation effort.

The result: failed assessments, delayed contracts, and expensive re-assessments. This toolkit solves that.

10 Professional Documents — Everything in One Pack

Every document is built to CMMC 2.0 Final Rule and NIST SP 800-171 Rev 2 standards. No generic filler. No placeholder content. Each document includes instructions, worked examples, and guidance on what assessors expect to see.

Document 1

Toolkit Orientation Guide

Understand the CMMC landscape, how the documents fit together, and common assessment failure points.

Document 2

CMMC Level 1 Self-Assessment Pack

Complete self-assessment against all 17 Level 1 safeguarding practices with evidence guidance.

Document 3

CMMC Level 2 Gap Assessment

Structured gap assessment covering all 110 NIST SP 800-171 practices across 14 domains.

Document 4

System Security Plan (SSP) Template

NIST 800-18 format SSP covering all 110 practices, CUI data flows, network architecture, and system boundary definition.

Document 5

Plan of Action & Milestones (POA&M)

Track every gap, assign owners, set remediation dates. Formatted to meet C3PAO and DFARS requirements.

Document 6

Evidence Collection Templates

Domain-by-domain templates for all 14 practice domains. Includes naming conventions and evidence index.

Document 7

Supplier & Subcontractor Questionnaire

Due diligence questionnaire for all suppliers with access to CUI. Covers DFARS flow-down requirements.

Document 8

90-Day Remediation Roadmap

Week-by-week plan from Day 1 to assessment-ready. Specific tasks, owners, and measurable success criteria every week.

Document 9

NIST 800-171 Control Mapping Guide

All 110 controls mapped to CMMC 2.0, ISO 27001:2022, and CIS Controls v8. Reuse existing compliance evidence where possible.

Document 10

Customisation Checklist

Step-by-step guidance for adapting all documents to your organisation. Pre-submission and QA checklists included.

Choose Your Compliance Starting Point

All tiers include instant download and perpetual licence for your organisation.

Level 1 Starter Pack

£97 one-time

For organisations beginning their CMMC journey or who need Level 1 compliance only.

  • Document 1 — Orientation Guide
  • Document 2 — Level 1 Self-Assessment Pack
  • Document 10 — Customisation Checklist
  • Instant download
  • Perpetual licence
Buy Level 1 Pack — £97

Toolkit + Strategy Session

£1,497 one-time

For organisations with a fixed assessment deadline or complex environments who want expert guidance.

  • Everything in Full Toolkit
  • 1-hour private strategy session with Michael Adedeji CISM CISA
  • Assessment scope review
  • Gap assessment prioritisation
  • SSP structure review
  • Custom roadmap adjustments
  • Session notes & action plan within 48h
  • Session within 5 working days
Book Toolkit + Session — £1,497

Built by Someone Who Has Done This Work

CISM
CISA
CEH
CC
MSc Data Science

Michael Adedeji is a Certified Information Security Manager (CISM) and Certified Information Systems Auditor (CISA) with hands-on experience across CMMC, ISO 27001, NIST CSF, and SOC 2. Founder of Pyralink Innovation Ltd and creator of CloudAuditX — an autonomous multi-cloud security auditing platform. This toolkit reflects real assessment experience: what assessors look for, what evidence gets accepted, and what causes assessment failures.

Frequently Asked Questions

Is this toolkit for US-based contractors only?

No. CMMC 2.0 applies to any organisation in the DoD supply chain that handles Controlled Unclassified Information (CUI) — regardless of location. UK, EU, Canadian, and Australian defence suppliers handling CUI under DoD contracts are subject to CMMC requirements. This toolkit is written for the full international audience.

Does purchasing this toolkit guarantee CMMC certification?

No. Certification is determined solely by an accredited C3PAO. No toolkit can guarantee that outcome. What this toolkit does is give you the documentation framework, gap assessment structure, evidence templates, and implementation roadmap to prepare as thoroughly as possible.

Does it reflect the CMMC 2.0 Final Rule?

Yes. Built to the CMMC 2.0 Final Rule (32 CFR Part 170, effective December 2024) and NIST SP 800-171 Rev 2. Full Toolkit purchasers receive free updates for 12 months.

We already hold ISO 27001. How much additional work is needed?

Significant time can be saved. Document 9 maps all 110 NIST 800-171 controls to ISO 27001:2022 and shows exactly where existing evidence can be reused. ISO 27001-certified organisations typically find ~60–70% of Level 2 practices already addressed. Primary gaps tend to be FIPS cryptography, CUI marking, SSP format, and US-specific supply chain requirements.

Can I use this for multiple subsidiaries?

The licence covers your organisation as a single legal entity. For multi-entity licensing, contact hello@pyralink.co.uk.

Ready to Get CMMC Compliant?

C3PAO assessments are happening now. Every month without a compliance programme is a month of risk — and a month closer to a contract deadline you won't be able to meet.

Get the Full Toolkit — £497 Start with Level 1 — £97 Book Toolkit + Session — £1,497

Questions? Email hello@pyralink.co.uk

Important Notice: The Pyralink CMMC 2.0 Compliance Toolkit is provided for informational and organisational assistance purposes only. Purchase does not constitute legal or regulatory advice, or a guarantee of CMMC certification. Certification is determined solely by an accredited C3PAO as recognised by the Cyber AB. It is the purchaser's responsibility to verify content remains current for their specific environment and contract requirements. Pyralink Innovation Ltd accepts no liability for assessment outcomes, contract decisions, or regulatory penalties. Licence covers the purchasing organisation only. All sales are final once download access is provided. Pyralink Innovation Ltd is registered in England and Wales. | hello@pyralink.co.uk | pyralink.co.uk