// Policy builder · Study Tools

Free CPCSC and CMMC policy builder

Builds a written security policy set for a small shop from 13 policies. The 10 Level 1 policies cover the 13 CPCSC Level 1 controls and the 15 CMMC Level 1 practices, or the same controls for a business working toward ISO 27001. It's free. The text is assembled from a library of reviewed clauses, not generated per request, so 2 companies that give the same answers get the same documents.

Your answers stay in this browser unless you choose to email yourself a copy. The output is a template, not legal advice. CPCSC Level 1 also asks for evidence that each control works, such as access lists, configuration exports, and patch records, so the policies are one part of the self-assessment rather than all of it.

See a sample report (PDF), built for a fictional company.

Step 1 of 5

Profile

Who are these policies for?

The profile sets the terms (SI, FCI, or confidential information), the commitments and compliance wording, and the annual self-assessment sentences. You can change it later without losing answers.

What you get

  • An information security policy that names the others you kept, plus up to 12 supporting policies. The 9 Level 1 policies are access control, external systems, public information, identification and authentication, media sanitization, physical security, network boundary, patching, and malicious code. Incident response, change management, and backup and recovery are optional and start unselected.
  • A form field for every CPCSC organization-defined parameter, tagged with its ODP reference, so an assessor can trace each defined value.
  • A coverage check against the 71 CPCSC Level 1 objectives and 60 CMMC Level 1 objectives while you choose clauses.
  • A records list at the end of each policy naming the evidence it expects you to keep.

What it does not do

The 3 optional policies are not Level 1 requirements, so they carry no CPCSC objective tags. Supplier security, logging, asset inventory, and risk assessment are Level 2 and ISO 27001 material and are not in this version. It doesn't check that the shop follows the policies either. A policy that says one thing while staff do another is a finding.

Related

Written for your shop

If you want it written for your shop, see the policy pack.

Licence

The clause library is released under CC BY 4.0. The documents you generate belong to your company, and you can use, change, and share them without attribution. Library last checked against the PSPC Level 1 criteria on 2026-10-05. Feedback to contact@hans.study.

Runs in your browser. When you generate output, this site records that a generation happened and the profile and export format you chose so I can see which options get used in the field. Company details stay in this browser unless you use the email option, which sends the policy text to the server so it can be mailed to you. See the privacy policy.