Learning Center

CMMC Compliance Guides

Free, practitioner-written guides to help defense contractors understand and achieve CMMC certification. No jargon, no fluff — just what you need to know.

CMMC Phase 2 Suspension: What Changed
July 2026 Update
The July 2026 suspension explained — what was paused, what still applies (DFARS 7012, NIST 800-171, SPRS affirmations), the False Claims Act risk shift, and what to do before the Reform Task Force reports.
Read Guide
What Is CMMC?
Start Here
A complete introduction to the Cybersecurity Maturity Model Certification — what it is, who needs it, and how it affects defense contractors.
Read Guide
CMMC Level 2 Requirements
Most Popular
A detailed breakdown of all 110 NIST SP 800-171r2 practices required for CMMC Level 2 certification, organized by security domain.
Read Guide
C3PAO Assessment Guide
Assessment Prep
How to prepare for your CMMC assessment — what C3PAOs look for, how to choose an assessor, and what to expect during the certification process.
Read Guide
The CMMC Assessment Process
Assessment
From self-assessment to certification — how to evaluate your controls, collect evidence, calculate your SPRS score, and prepare for your C3PAO assessment.
Read Guide
Continuous Monitoring for CMMC
Ongoing Compliance
How to maintain compliance after certification with ongoing monitoring, evidence refresh cycles, and annual affirmations.
Read Guide
POA&M Management Guide
Remediation
How to create, track, and close Plan of Action & Milestones entries — including the 180-day conditional certification window.
Read Guide
ESP Management for CMMC
Supply Chain
How to identify, classify, and manage External Service Providers — including FedRAMP requirements, shared responsibility, and control inheritance.
Read Guide

Ready to Start Your CMMC Journey?

Bedrock CMMC gives you the tools to manage all 110 NIST 800-171r2 controls, track evidence, generate your SSP, and connect with certified C3PAO assessors.