Why Most CMMC Documentation Fails and How to Fix It

In this article
The philosophy behind compliance documentation that actually works
We’ve assessed companies for CMMC certification. We’ve seen a lot of bad documentation.
Documentation that doesn’t help companies pass their assessments. Policies sitting in binders that nobody reads. Procedures so complex that staff can’t follow them. Templates filled with generic language that doesn’t match actual operations.
When we needed to pass our own CMMC Level 2 assessment, we built something different. The Kieri Compliance Documentation reflects what we learned about documentation that works versus documentation that exists.
The Problem with Documentation for Documentation’s Sake
Nobody likes creating policies just to have policies. Most people in IT would rather fix problems than write about fixing problems.
But compliance requires documentation. CMMC assessors want to see policies, procedures, plans, and evidence. They want proof that you’re doing what you claim.
The question isn’t whether to document. It’s how to document in ways that actually help.
Bad documentation creates busywork without improving security. Good documentation guides behavior and generates evidence as work happens.
What Good Documentation Should Do
When we designed the KCD, we identified what documentation needs to accomplish:
Just-in-time instructions wherever possible. Not a 300-page procedure manual that sits in a corner. Instructions that appear when you need them, walking you through each step.
If your HR person needs to execute 300 steps on page 88 of your procedures booklet, they won’t do it correctly. Nobody memorizes procedure manuals.
Instead, the onboarding form itself should guide them through required fields. The change management request should include verification steps. The process should enforce compliance by design.
Forms that require proper completion. If you’re onboarding a new user, the form won’t let you proceed without filling in required information. Background check completed? Training acknowledged? User agreement signed? The form captures evidence that you did the vetting and authorization properly.
Finding and correcting issues. Maybe someone forgot a scheduled task. Maybe documentation doesn’t match actual practice. The program should identify gaps and help you fix them before assessment.
Two Types of Security Controls
When we analyzed NIST SP 800-171 requirements, we found they fall into two categories.
Controls that stay good once implemented.
Some security controls, when you configure them correctly, just keep working. Your firewall access control lists don’t randomly change. Your system hardening configurations don’t drift on their own. Your network segmentation stays in place.
For these controls, you need strong change management. Do it right the first time. Document what you did and why. Verify it works. Then trust it until something needs to change.
When changes happen, change management ensures you maintain security. Review the proposed change. Verify it meets requirements. Document the implementation. Generate evidence showing it was done properly.
This approach saves enormous effort compared to continuously re-verifying static configurations.
Controls that need regular action.
Other controls fail over time if you don’t maintain them. Systems need patches. People change roles and need access reviews. Vulnerabilities get discovered. Risk changes.
For these controls, you need scheduled tasks and checklists. Weekly patching reviews. Monthly access reviews. Quarterly vulnerability assessments. Annual risk assessments.
We mapped every CMMC requirement to its appropriate frequency. Some need weekly attention. Some only need annual review. The KCD includes recommended schedules based on what assessors expect and what actually maintains security.
Why Policies Don’t Follow NIST Families
NIST SP 800-171 organizes requirements into families. Access Control. Audit and Accountability. Configuration Management. And so on.
Most compliance templates follow the same structure. One policy per NIST family.
This creates problems. The Access Control family includes requirements about user onboarding, mobile devices, and wireless networks. Those are different job functions handled by different people.
We organized KCD policies by how IT departments actually work.
Access management policy covers user onboarding, access requests, and privilege management. That’s one person’s job function.
Audit management policy covers log configuration, log review, and incident detection. That’s another job function.
Vulnerability management policy covers patching, scanning, and remediation. Another job function.
This makes policies usable. The person responsible for patching reads the vulnerability management policy. Everything they need is there. They’re not hunting through multiple documents to find relevant requirements.
What’s Actually Included
The KCD provides everything your IT department needs for CMMC Level 2 compliance.
Templates for everything. Policies, procedures, the System Security Plan, user agreements, forms, checklists. All pre-written with best practices you can customize.
Database definitions. If you use SharePoint, you can import these definitions to create your IT department recordkeeping system. Account management database. Asset inventory. Software inventory. Risk register.
Training library. Hours of recorded trainings covering every part of the program. How to do scoping. How to handle separation of duties when you’re small. How to execute each scheduled task. How to do correct change management.
Monthly webinars. Since June 2023, we’ve recorded monthly sessions answering client questions. BYOD handling. Physical security. Scoping edge cases. Whatever’s really bugging people.
Monthly newsletters. Updates on what changed in the KCD. New trends in how the DoD assesses companies. New requirements like FedRAMP equivalency. Plus practice spotlights that deep-dive into specific requirements.
Three free check-ins. Schedule on demand. Ask certified assessors anything about CMMC. If you’ve been fighting about a scoping issue internally for a year, use a check-in. Get an assessor’s opinion based on actual assessments.
The Battle-Tested Difference
We didn’t create the KCD as a theoretical product. We built it because we needed to pass our own CMMC Level 2 assessment by DIBCAC.
We used this documentation. We maintained our environment using these procedures. We generated evidence using these processes.
Then we passed.
When clients use the KCD, they’re using documentation that has been through actual DoD assessment. Not theoretical compliance. Proven compliance.
Over 100 companies now use the KCD for their NIST SP 800-171 and CMMC programs. Clients have achieved certification using this documentation. The approach works.
Who the KCD Works For
The KCD is designed for organizations under 1,000 users. Small to mid-sized defense contractors who need practical compliance without enterprise complexity.
Larger organizations find value in the training library and System Security Plan examples even if they have their own policy sets. The implementation guidance applies regardless of organization size.
You need someone who can follow procedures and maintain documentation. A capable IT person or compliance officer. The KCD makes their job possible, but someone still has to do the work.
If you want to throw money at consultants and hope compliance happens, other approaches exist. If you want to understand and control your own compliance program, the KCD provides the tools.
Kieri Solutions developed the KCD for our own CMMC Level 2 certification. We passed. Now over 100 companies use our documentation to achieve and maintain compliance.
Ready to see the full program? Schedule a consultation
Talk to a CMMC Expert
Tell us where you are with CMMC and we’ll map out the next steps for your team.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.




























































