Controlled Unclassified Information: Unauthorized Disclosure: Prevention and Reporting

DoD/DoW
Gain a foundational understanding of Controlled Unclassified Information (CUI) and your responsibilities for protecting it.
Read More

CUI Handbook: Marking Controlled Unclassified Information

DoD/DoW
Learn how to properly mark Controlled Unclassified Information (CUI) in accordance with federal requirements.
Read More

CUI-100DE Overview of Controlled Unclassified Information (CUI)

DoD/DoW
Understand DOE-specific requirements for handling Controlled Unclassified Information (CUI).
Read More

Controlled Unclassified Information (CUI) - Controlled Environments Course

DoD/DoW
Learn how to properly handle and protect Controlled Unclassified Information (CUI).
Read More

CEU Library

Continuing Education
Access a vast library of CEU courses across multiple disciplines.
Read More

Human Trafficking Awareness for Hospitality Course

Human Trafficking
Spot and stop human trafficking in the hospitality industry.
Read More

Human Trafficking Awareness Course

Human Trafficking
Learn to identify and combat human trafficking effectively.
Read More

Strategies to Increase Patient Volume Course

Healthcare Admin
Boost your practice’s patient volume with proven strategies."
Read More

Fraud, Waste and Abuse Course

Corporate Ethics
Combat fraud, waste, and abuse in your organization.
Read More

Workplace Harassment Course

Human Resources
Prevent harassment and foster a respectful workplace.
Read More

Sexual Harassment Prevention for Managers Course

Human Resources
Train managers to lead in preventing sexual harassment.
Read More

Sexual Harassment Prevention Course

Human Resources
Equip yourself to prevent and address sexual harassment.
Read More

Employee Burnout Prevention Course

Human Resources
Learn strategies to prevent and manage employee burnout.
Read More

Employee Onboarding Course

Human Resources
Optimize new hire experiences with effective onboarding.
Read More

Diversity and Inclusion Course

Human Resources
Embrace and promote diversity and inclusion in the workplace.
Read More

Privacy & Data Handling Course

Cybersecurity
Master best practices for privacy and secure data handling.
Read More

Ransomware Avoidance and Recovery Course

Cybersecurity
Learn key strategies to prevent and respond to ransomware.
Read More

Phishing Identification Course

Cybersecurity
Learn to spot and avoid phishing attacks effectively.
Read More

Password Management Course

Cybersecurity
Strengthen your security with effective password practices.
Read More

Insider Threat Identification Course

Cybersecurity
Learn to detect and manage insider threats effectively.
Read More

Malware Prevention Course

Cybersecurity
Equip yourself to combat and prevent malware threats.
Read More

Cybersecurity Awareness Course

Cybersecurity
Strengthen your defenses with essential cybersecurity skills.
Read More

Introduction to WISHA Course

OSHA
Explore WISHA standards for workplace safety in WA.
Read More

Basic Life Support: CPR & AED Course

OSHA
Learn CPR and AED techniques to save lives in emergencies.
Read More

Hazardous Communication & GHS Course

OSHA
Master HazCom and GHS for workplace safety compliance.
Read More

Fire Prevention and Protection Course

OSHA
Master fire safety to ensure workplace prevention and protection.
Read More

Bloodborne Pathogens Course

OSHA
Learn OSHA's protocols for handling bloodborne pathogens.
Read More

Texas HB 300 Course

HIPAA
Navigate Texas HB 300's unique healthcare privacy laws.
Read More

Telehealth Compliance Course

HIPAA
Master HIPAA compliance in telehealth practices.
Read More

HIPAA Privacy Rule Course

HIPAA
Master the essentials of HIPAA Privacy to protect patient rights.
Read More

HIPAA Security Rule Course

HIPAA
Master HIPAA Security Rule essentials to safeguard ePHI.
Read More

How to Avoid Gossip in The Workplace Course

HIPAA
Navigate workplace gossip with HIPAA compliance in mind.
Read More

HIPAA Breach Notifcation Rule Course

HIPAA
Learn to manage and report HIPAA breaches effectively.
Read More

HIPAA Violation Employee Discipline Course

HIPAA
Enforce HIPAA rules with effective disciplinary actions.
Read More

Frequently asked questions

Find answers to common questions about K2 GRC's features, services, and more.
What are CMMC policy templates?
CMMC policy templates are pre-written, customizable documents that give defense contractors a starting point for the written policies required to handle Controlled Unclassified Information (CUI). Each template maps to a specific CMMC domain and covers the rules, responsibilities, and procedures your organization needs to define for compliance.
Do I need written policies to comply with CMMC?
Yes. Documented policies are a foundational requirement regardless of your CMMC level. Assessors and auditors expect written evidence that your organization has defined and communicated its approach to cybersecurity across every applicable domain — not just that controls are technically in place.
Are these templates enough on their own?
Templates are a starting point, not a finish line. Each policy needs to be tailored to reflect how your organization actually operates, approved by leadership, and communicated to your team. A policy that doesn't match your real-world practices creates more risk than having no policy at all.
What is the difference between a CMMC policy and a procedure?
A policy defines what your organization does and why it's a high-level statement of intent. A procedure defines how you do it, or the step-by-step process. Both are required for CMMC compliance, but policies establish the foundation everything else is built on.
How do these policies relate to NIST SP 800-171?
CMMC Level 2 is built directly on NIST SP 800-171, which defines 110 security controls across 14 domains. These policy templates are written to align with those controls, so documenting them moves you forward on both CMMC and your broader 800-171 compliance obligations simultaneously.
How often should CMMC policies be reviewed?
Most assessors expect policies to be reviewed at least annually, or whenever there is a significant change to your environment, personnel, or systems. Keeping policies dated, versioned, and tied to a review cycle is a simple practice that carries significant weight during any compliance assessment.

Start your GRC journey today

Discover how K2 GRC can simplify compliance and enhance your organization's governance and risk management.