ciso.diy
Defense Supplier Pack preview
Bundles CMMCDFARS 7012NIST 800-171SPRS

Defense Supplier Pack

The CMMC self-assessment and SPRS score you are certifying to, the provider holding your admin rights, and the federal incident clock underneath both. What a DIB contractor is actually accountable for while Phase 2 is suspended. 19% off buying separately.

What this actually gives you

  • An inflated SPRS score is a false claim with or without Phase 2 — the DOJ’s Civil Cyber-Fraud Initiative did not pause when certification did.
  • If an MSP runs your estate it is inside your CUI boundary, whether or not your SSP says so — and the score you certify inherits their controls.
  • An incident starts two clocks — DIBNet at 72 hours under DFARS 7012, and CISA under CIRCIA — with different triggers, different content and different recipients.
  • 20% rather than the usual 25%, because at 25% this pack would cost less at the vCISO tier than the CMMC workbook alone. 20% is the largest discount that keeps the arithmetic honest.

A defence supplier's exposure is not one programme. It is a score you certify, a provider you do not control, and a clock that starts the moment you notice.

CMMC 2.0 Readiness Accelerator (including the v2.0 "While It's Paused" kit) — all 110 NIST 800-171 requirements with their DoD Assessment Methodology weights, the SPRS calculator with partial-credit rules, an §3.12.4 SSP template, a POA&M carrying the 180-day deadline, the DFARS 7012 72-hour clock, and the obligations resolver for what still applies now that Phase 2 is suspended. An inflated SPRS score is a false claim with or without Phase 2 — the DOJ's Civil Cyber-Fraud Initiative did not pause.

MSP & MSSP Assessment Kit — the provider question CMMC scoping keeps running into. Most small and mid-size DIB contractors do not operate their own environment: an MSP holds the RMM, the delegated admin and the backups, which means it is inside your CUI boundary whether or not your SSP says so. Forty controls it must evidence, twenty contract clauses, and a drill for the night it is breached.

CIRCIA 72/24 Reporting Readiness Pack — the federal reporting duty that sits beside DFARS 7012 rather than inside it. Whether you are covered, whether an incident is reportable at 2 a.m., and the report drafted inside the first day. Defence suppliers routinely owe both, on different clocks, to different recipients.

Why the three. The SSP asks where CUI lives and who touches it; if an MSP runs your estate, the honest answer implicates a third party you have never assessed, and the score you certify inherits their controls. Meanwhile an incident starts two clocks — DIBNet at 72 hours under 7012, CISA under CIRCIA — with different triggers and different content. Owning one of these and not the others is how a supplier ends up with a defensible score and an indefensible incident, or the reverse.

20% off, not the usual 25%. CMMC is several times the price of the other two, and at 25% this pack would cost less than the CMMC workbook alone at the vCISO tier — a bundle that undercuts its own largest component is a worse deal for us and a confusing one for a buyer. 20% is the largest discount that keeps the arithmetic honest at both tiers, and it still takes $140 off at Individual and $700 off at vCISO / MSSP.

Offered at Individual Practitioner and vCISO / MSSP. There is no Organization tier because the CIRCIA pack is not sold as one.

What's included

  • Excel (.xlsx) — fully editable
  • Word (.docx) — User Guide — fully editable
  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-08