Services
Features
Dark Web Monitoring
Exclusion Checks
Learning Management System
Phishing Simulations
POA&M Management
Risk Management
Third-Party Risk Management
Offerings
K2 Akademy
K2 CMMC
K2 Cyber
K2 Exclude
K2 HIPAA
K2 Pharmacy
K2 Risk Management
Courses
Bloodborne Pathogens
CEU Library
Cybersecurity Awareness
HIPAA Privacy Rule
HIPAA Security Rule
View All>
Partners
About
Blog
Resources
Pricing
Contact
Your Cart
$ 0.00 USD
:
Remove
No items found.
Product is not available in this quantity.
Meet with Us
Course Catalog
Empower Your Team with Targeted Training
Explore our extensive catalog to find courses designed to boost your team’s performance and compliance. Start shaping your workforce’s future today.
Controlled Unclassified Information: Unauthorized Disclosure: Prevention and Reporting
DoD/DoW
Gain a foundational understanding of Controlled Unclassified Information (CUI) and your responsibilities for protecting it.
Read More
CUI Handbook: Marking Controlled Unclassified Information
DoD/DoW
Learn how to properly mark Controlled Unclassified Information (CUI) in accordance with federal requirements.
Read More
CUI-100DE Overview of Controlled Unclassified Information (CUI)
DoD/DoW
Understand DOE-specific requirements for handling Controlled Unclassified Information (CUI).
Read More
Controlled Unclassified Information (CUI) - Controlled Environments Course
DoD/DoW
Learn how to properly handle and protect Controlled Unclassified Information (CUI).
Read More
CEU Library
Continuing Education
Access a vast library of CEU courses across multiple disciplines.
Read More
Human Trafficking Awareness for Hospitality Course
Human Trafficking
Spot and stop human trafficking in the hospitality industry.
Read More
Human Trafficking Awareness Course
Human Trafficking
Learn to identify and combat human trafficking effectively.
Read More
Strategies to Increase Patient Volume Course
Healthcare Admin
Boost your practice’s patient volume with proven strategies."
Read More
Fraud, Waste and Abuse Course
Corporate Ethics
Combat fraud, waste, and abuse in your organization.
Read More
Workplace Harassment Course
Human Resources
Prevent harassment and foster a respectful workplace.
Read More
Sexual Harassment Prevention for Managers Course
Human Resources
Train managers to lead in preventing sexual harassment.
Read More
Sexual Harassment Prevention Course
Human Resources
Equip yourself to prevent and address sexual harassment.
Read More
Employee Burnout Prevention Course
Human Resources
Learn strategies to prevent and manage employee burnout.
Read More
Employee Onboarding Course
Human Resources
Optimize new hire experiences with effective onboarding.
Read More
Diversity and Inclusion Course
Human Resources
Embrace and promote diversity and inclusion in the workplace.
Read More
Privacy & Data Handling Course
Cybersecurity
Master best practices for privacy and secure data handling.
Read More
Ransomware Avoidance and Recovery Course
Cybersecurity
Learn key strategies to prevent and respond to ransomware.
Read More
Phishing Identification Course
Cybersecurity
Learn to spot and avoid phishing attacks effectively.
Read More
Password Management Course
Cybersecurity
Strengthen your security with effective password practices.
Read More
Insider Threat Identification Course
Cybersecurity
Learn to detect and manage insider threats effectively.
Read More
Malware Prevention Course
Cybersecurity
Equip yourself to combat and prevent malware threats.
Read More
Cybersecurity Awareness Course
Cybersecurity
Strengthen your defenses with essential cybersecurity skills.
Read More
Introduction to WISHA Course
OSHA
Explore WISHA standards for workplace safety in WA.
Read More
Basic Life Support: CPR & AED Course
OSHA
Learn CPR and AED techniques to save lives in emergencies.
Read More
Hazardous Communication & GHS Course
OSHA
Master HazCom and GHS for workplace safety compliance.
Read More
Fire Prevention and Protection Course
OSHA
Master fire safety to ensure workplace prevention and protection.
Read More
Bloodborne Pathogens Course
OSHA
Learn OSHA's protocols for handling bloodborne pathogens.
Read More
Texas HB 300 Course
HIPAA
Navigate Texas HB 300's unique healthcare privacy laws.
Read More
Telehealth Compliance Course
HIPAA
Master HIPAA compliance in telehealth practices.
Read More
HIPAA Privacy Rule Course
HIPAA
Master the essentials of HIPAA Privacy to protect patient rights.
Read More
HIPAA Security Rule Course
HIPAA
Master HIPAA Security Rule essentials to safeguard ePHI.
Read More
How to Avoid Gossip in The Workplace Course
HIPAA
Navigate workplace gossip with HIPAA compliance in mind.
Read More
HIPAA Breach Notifcation Rule Course
HIPAA
Learn to manage and report HIPAA breaches effectively.
Read More
HIPAA Violation Employee Discipline Course
HIPAA
Enforce HIPAA rules with effective disciplinary actions.
Read More
Frequently asked questions
Find answers to common questions about K2 GRC's features, services, and more.
What are CMMC policy templates?
CMMC policy templates are pre-written, customizable documents that give defense contractors a starting point for the written policies required to handle Controlled Unclassified Information (CUI). Each template maps to a specific CMMC domain and covers the rules, responsibilities, and procedures your organization needs to define for compliance.
Do I need written policies to comply with CMMC?
Yes. Documented policies are a foundational requirement regardless of your CMMC level. Assessors and auditors expect written evidence that your organization has defined and communicated its approach to cybersecurity across every applicable domain — not just that controls are technically in place.
Are these templates enough on their own?
Templates are a starting point, not a finish line. Each policy needs to be tailored to reflect how your organization actually operates, approved by leadership, and communicated to your team. A policy that doesn't match your real-world practices creates more risk than having no policy at all.
What is the difference between a CMMC policy and a procedure?
A policy defines what your organization does and why it's a high-level statement of intent. A procedure defines how you do it, or the step-by-step process. Both are required for CMMC compliance, but policies establish the foundation everything else is built on.
How do these policies relate to NIST SP 800-171?
CMMC Level 2 is built directly on NIST SP 800-171, which defines 110 security controls across 14 domains. These policy templates are written to align with those controls, so documenting them moves you forward on both CMMC and your broader 800-171 compliance obligations simultaneously.
How often should CMMC policies be reviewed?
Most assessors expect policies to be reviewed at least annually, or whenever there is a significant change to your environment, personnel, or systems. Keeping policies dated, versioned, and tied to a review cycle is a simple practice that carries significant weight during any compliance assessment.
Start your GRC journey today
Discover how K2 GRC can simplify compliance and enhance your organization's governance and risk management.
Schedule a Demo
Copyright © 2024 by K2 GRC Powered By
Etactics