Skip to the main content.
Try GRC Playbook for free
Try GRC Playbook for free


Cybersecurity Maturity Model (CMMC) Level 3 Assessment

This library of Cybersecurity Playbooks provides a set of fully loaded and editable templates that represent the core of what is generally required by management (including process owners), boards of directors and their audit committees, as well as internal and external auditors of relevant organizations, to document, assess, test, report and oversee the design and operating effectiveness of the typical key internal controls on which management is reliant to maintain compliance with Cybersecurity regulatory requirements.

They are drawn from a range of authoritative sources including the National Institute of Standards and Technology (NIST), the Federal Financial Institutions Examination Council (FFIEC), the Department of Defense, the SEC's Office of Compliance Inspections and Examinations (OCIE), and the New York Department of Financial Services (NYDFS).

The Cybersecurity Maturity Model (CMMC) Level 3 Assessment Playbook consists of:

  • 17 CMMC Domains
  • 130 Practices, and
  • 290 Potential Assessment Considerations

For a CMMC Level 3 assessment, the practices and processes that encompass CMMC Levels 1, 2, and 3 apply.

CMMC Level 2 is a transitional level.

CMMC Level 3 consists of the security requirements specified in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations.

One Affordable Subscription. 100+ Playbooks.

With one subscription, you'll gain access to all of our Playbooks.


Would you like to find out just how affordable and beneficial a GRC Playbook® subscription can be?

Everything you need, on a platform you already know.


Try GRC Playbook for free