Algolia

Data Processing
Connect Algolia with K2 GRC to automate search index management, synchronize searchable content, and power intelligent search experiences.
Read More

ADP Workforce Now

Connect ADP Workforce Now with K2 GRC to automate employee management, HR processes, payroll workflows, and identity-driven compliance activities.
Read More

Adobe Marketo Engage Integration

Sales & Marketing
Connect Adobe Marketo Engage with K2 GRC to automate lead management, synchronize marketing data, and streamline customer engagement workflows.
Read More

Adobe I/O Events

Productivity
Connect Adobe I/O Events with K2 GRC to automate event-driven workflows and respond to real-time activity across Adobe applications.
Read More

Adobe Commerce Magento

Sales & Marketing
Connect Adobe Commerce (Magento) with K2 GRC to automate eCommerce operations, synchronize customers and orders, and streamline business workflows.
Read More

Adobe Analytics

Analytics
Connect Adobe Analytics with K2 GRC to automate reporting, retrieve analytics data, and support data-driven governance, risk, and compliance decisions.
Read More

Adobe Acrobat Sign Integration

Productivity
Connect Adobe Acrobat Sign with K2 GRC to automate document approvals, electronic signatures, and compliance-driven agreement workflows.
Read More

Active Directory (LDAP)

Connect Active Directory (LDAP) with K2 GRC to automate user management, directory synchronization, and identity-driven compliance workflows.
Read More

OpenAI

Artificial Intelligence (AI)
Connect OpenAI with K2 GRC to automate AI-powered content generation, document analysis, intelligent agents, and workflow automation.
Read More

Azure OpenAI Service Integration

Artificial Intelligence
Connect Azure OpenAI Service with K2 GRC to automate AI-powered content generation, document analysis, and intelligent workflows using Microsoft's Azure-hosted OpenAI models.
Read More

Google Gemini

Artificial Intelligence
Connect Google Gemini with K2 GRC to automate AI-powered content generation, document analysis, image creation, and intelligent workflows.
Read More

Anthroptic

Artificial Intelligence
Connect Anthropic with K2 GRC to automate AI-powered content generation, document analysis, and intelligent workflows using Claude models.
Read More

xAI Grok

Artificial Intelligence
Connect xAI Grok with K2 GRC to automate AI-powered content generation, intelligent workflows, and image creation across governance, risk, and compliance processes.
Read More

Airtable

Data Storage
Connect Airtable with K2 GRC to automate records, synchronize data, and streamline governance, risk, and compliance workflows.
Read More

Amazon DynamoDB

Data Storage
Connect Amazon DynamoDB with K2 GRC to automate data management, synchronize NoSQL records, and power compliance and operational workflows.
Read More

Azure Files

Data Storage
Connect Azure Files with K2 GRC to automate file storage, document management, and evidence collection across compliance and business workflows.
Read More

Google Calendar

Productivity
Connect Google Calendar with K2 GRC to automate calendar events, scheduling workflows, meeting management, and compliance-driven processes.
Read More

Frequently asked questions

Find answers to common questions about K2 GRC's features, services, and more.
What are CMMC policy templates?
CMMC policy templates are pre-written, customizable documents that give defense contractors a starting point for the written policies required to handle Controlled Unclassified Information (CUI). Each template maps to a specific CMMC domain and covers the rules, responsibilities, and procedures your organization needs to define for compliance.
Do I need written policies to comply with CMMC?
Yes. Documented policies are a foundational requirement regardless of your CMMC level. Assessors and auditors expect written evidence that your organization has defined and communicated its approach to cybersecurity across every applicable domain — not just that controls are technically in place.
Are these templates enough on their own?
Templates are a starting point, not a finish line. Each policy needs to be tailored to reflect how your organization actually operates, approved by leadership, and communicated to your team. A policy that doesn't match your real-world practices creates more risk than having no policy at all.
What is the difference between a CMMC policy and a procedure?
A policy defines what your organization does and why it's a high-level statement of intent. A procedure defines how you do it, or the step-by-step process. Both are required for CMMC compliance, but policies establish the foundation everything else is built on.
How do these policies relate to NIST SP 800-171?
CMMC Level 2 is built directly on NIST SP 800-171, which defines 110 security controls across 14 domains. These policy templates are written to align with those controls, so documenting them moves you forward on both CMMC and your broader 800-171 compliance obligations simultaneously.
How often should CMMC policies be reviewed?
Most assessors expect policies to be reviewed at least annually, or whenever there is a significant change to your environment, personnel, or systems. Keeping policies dated, versioned, and tied to a review cycle is a simple practice that carries significant weight during any compliance assessment.

Start your GRC journey today

Discover how K2 GRC can simplify compliance and enhance your organization's governance and risk management.