Sample deliverables

See exactly what you get

Below is what ClearPath generates from a finished questionnaire: a live SPRS score, a draft System Security Plan, and a Plan of Action & Milestones. Your real documents are written from your answers — never invented.

This is a sample. Acme Precision Machining” is a fictional company and every figure here is illustrative — no real customer data is shown. ClearPath never collects CUI.

SPRS score

88 / 110

estimated SPRS score

22 points to gain — the gaps ClearPath found

  • 3.4.6 Least functionality not yet configured5
  • 3.11.2 No recurring vulnerability scanning5
  • 3.14.6 No monitoring for attacks / indicators5
  • 3.5.3 MFA not enforced for local privileged access3
  • 3.13.11 Cryptography not FIPS-validated3
  • 3.1.8 No automatic account lockout1

Draft System Security Plan

Excerpt — 3 of the 14 control families. The full draft covers all 110 requirements and exports to Word, each section noting how much of the questionnaire backs it.

DRAFT — Draft prepared by ClearPath Compliance. Review by your organization and, where required, a qualified professional before submission.

System Security Plan

Acme Precision Machining

CAGE code
1ABC2
Company size
11-50 employees
Industry
Precision machining
Scope
Handles CUI (CMMC Level 2)
Standard
NIST SP 800-171 Rev 2

Acme machines aluminum brackets and housings for defense primes. It handles CUI on a small, segmented internal network managed by the owner and a part-time IT contractor.

ACAccess Control

3.1.1 Limit system access to authorized users, processes, and devices

Implemented

Acme Precision Machining assigns every user an individual account; shared logins are prohibited. Accounts are created on hire and disabled during offboarding as part of the company's departure checklist.

Questionnaire coverage: 3 of 3 assessment objectives answered

3.1.5 Employ the principle of least privilege

Implemented

Administrative privileges are limited to the owner and the contracted IT provider. Production staff operate as standard users on the shop-floor systems.

Questionnaire coverage: 2 of 2 assessment objectives answered

3.1.8 Limit unsuccessful logon attempts

Planned (not implemented)

Automatic account lockout after repeated failed sign-in attempts is not yet configured. This deficiency is tracked in the Plan of Action and Milestones (POA&M).

Questionnaire coverage: 1 of 1 assessment objective answered

IAIdentification and Authentication

3.5.1 Identify system users, processes, and devices

Implemented

Each user and managed device is uniquely identified before access to company systems is granted.

Questionnaire coverage: 2 of 2 assessment objectives answered

3.5.3 Use multifactor authentication

Partially implemented

Multifactor authentication is enforced for email and remote access. It is not yet required for local privileged access to the CUI environment; closing that gap is tracked in the POA&M.

Questionnaire coverage: 2 of 2 assessment objectives answered · 1 flagged "I don't know"

SCSystem and Communications Protection

3.13.1 Monitor, control, and protect communications at system boundaries

Implemented

A firewall segments the CUI environment from the guest and general office networks; inbound access is denied by default.

Questionnaire coverage: 2 of 2 assessment objectives answered

3.13.11 Employ FIPS-validated cryptography to protect CUI

Partially implemented

Encryption protects CUI in transit and at rest, but the cryptographic modules in use are not yet FIPS-validated. Migrating to FIPS-validated modules is tracked in the POA&M.

Questionnaire coverage: 1 of 1 assessment objective answered

DRAFT — Draft prepared by ClearPath Compliance. Review by your organization and, where required, a qualified professional before submission.

Plan of Action & Milestones (POA&M)

Every gap becomes a prioritized, editable remediation row — with a plain-English fix, a rough effort and cost band, and a target date.

ControlDeficiencyPlanned remediationEffortTarget
3.1.8Limit unsuccessful logon attemptsAccounts do not lock after repeated failed sign-in attempts.Enable account lockout in Microsoft 365 (e.g. 15 minutes after 5 failed attempts).~hours$02026-08-15
3.5.3Use multifactor authenticationMFA is enforced for email and remote access but not for local privileged accounts.Extend MFA to local administrator sign-in on the CUI workstations and server.~days$500-5k2026-09-15
3.4.6Employ the principle of least functionalitySystems are not configured to a documented least-functionality baseline.Disable unused services and document an approved baseline configuration per system type.~days<$5002026-10-01
3.11.2Scan for vulnerabilitiesNo recurring vulnerability scanning is performed.Stand up monthly authenticated vulnerability scans and track findings to closure.~days$500-5k2026-10-15
3.13.11Employ FIPS-validated cryptography to protect CUIEncryption is in use but the cryptographic modules are not FIPS-validated.Enable FIPS mode on managed endpoints and adopt FIPS-validated modules for CUI at rest.~weeks$500-5k2026-11-15
3.14.6Monitor systems to detect attacks and indicators of potential attacksNo monitoring or alerting is in place to detect attacks.Enable endpoint and firewall logging with alerting (managed detection or a lightweight SIEM).~weeks$500-5k2026-12-01

Get your own — built from your answers

Answer plain-English questions about your shop and ClearPath drafts all of this for you. The questionnaire and your live score are free.