Services / Module C: Policy & Evidence Framework
Documentation · Module C

14 tailored policies and an evidence index a C3PAO can follow

For contractors whose SSP is solid but whose policies are templates — and whose evidence lives in fourteen different inboxes.
$8,500
Fixed fee — no hourly meter
2 weeks
From complete document checklist
No blanks
No fill-in-the-blank template policies

Assessors read policies. Then they ask for proof.

Downloaded policy templates with the blanks filled in are the most common documentation failure in small-contractor assessments — assessors recognize them on sight, and a policy your team has never read is worse than no policy at all.
And policies are only half the question. The other half is "show me": for each practice, where’s the artifact, who owns it, and is it current? If the answer is a scramble through inboxes, the assessment stalls. Module C builds both halves.

What you get in 2 weeks

14 tailored policies

Written from your SSP and your actual operations — no template boilerplate, no blanks, nothing your team would be surprised to read.

Evidence Index

Practice → artifact → owner → refresh date, for every practice. The map an assessor follows instead of waiting on your inbox searches.

Responsibility matrix

One accountable owner per policy family — named roles from your org chart, matched to the SSP, so you and your MSP both know who signs off on what.

Evidence collection guide

What to capture, where to store it, and when to refresh it — so the index stays alive after the engagement ends.
How the Evidence Index works — every practice, one row
Practice AC.L2-3.1.1 Artifact access-control list export Owner IT manager / MSP Refresh quarterly
An assessor can pick any practice and trace it to a current artifact and a named owner — that traceability is what "evidence a C3PAO can follow" means.

Two weeks, week by week

1
Gate

Your clock starts here

SOW signed + payment + document checklist complete = your clock starts. Until then, nothing is counting against you.
2
Week 1

Policy drafting from your SSP

Each policy written against your implementation statements — the SSP says what you do; policies say who, how, and how often.
3
Week 2

Evidence index and revision

Every practice mapped to its artifact and owner, refresh dates set, and your one consolidated revision round applied.
4
Week 2 · close

Recorded debrief

A recorded walkthrough of every finding and deliverable — so your team can replay it, and nothing lives only in one person’s head.

What we need from you

This checklist is how your timeline stays protected — the clock starts when it's complete, so nothing stalls mid-engagement.
A current, honest SSP (Module B output, or one that would survive a Snapshot)
Your existing policies, if any — even the template ones; they show what your team is used to
Your org chart with role names and your system/tool list — policies name roles, and every evidence artifact gets a named owner (a real person, not "IT")
One consolidated round of stakeholder feedback in week 2

Is Module C what you need?

Module C works well for:

  • Contractors with a solid SSP but template-grade policies
  • Teams that scramble for artifacts every time someone asks for proof
  • Organizations preparing for the C3PAO Readiness Review or the real assessment
  • MSP-supported environments where evidence ownership was never assigned

Not the right fit:

  • No current SSP — Module B comes first; policies hang off implementation statements
  • You want policies that describe aspirations — same rule as the SSP: aspirations go in the POA&M
  • Organizations wanting Lumos to perform the formal assessment — a C3PAO must do that
  • Looking for hands-on technical implementation — your IT staff or MSP performs that work
Lumos is a solo practice led by a Cyber AB Registered Practitioner providing readiness advisory and documentation only — formal CMMC assessments are conducted by certified C3PAOs, and technical implementation is performed by your IT staff or MSP. CMMC readiness consulting is generally an allowable cost under FAR 31.205-33; confirm with your contracts team.
CISSP · ISSEP · CCSP · CSSLP · CISA · CISM · PMP Cyber AB Registered Practitioner 28 NIST engagements since 2017 Veteran & Native Hawaiian-Owned

Where this leads

With policies and evidence in place, the C3PAO Readiness Review is the final check — and when Lumos built both your SSP (Module B) and this policy and evidence set (Module C), the review runs at the $7,500 rate instead of $12,500.

Questions about this engagement

Why exactly 14 policies? +
The 14 control families of NIST SP 800-171 — one policy per family keeps the set complete without inventing documents no assessor asks for. Access control, awareness and training, audit and accountability, and so on through system and information integrity.
What’s wrong with the templates we downloaded? +
Nothing — as a reading list. The failure is affirming compliance against a policy that doesn’t describe your operation. Assessors interview your staff against your policies; when the policy says something your team has never heard of, that’s a finding.
Who should own evidence artifacts? +
A named person per artifact — the one who can produce it in five minutes, typically your IT lead, office manager, or MSP contact. The index makes ownership explicit so "someone has that" never appears in your assessment.
How does the index stay current after you leave? +
Every row has a refresh date, and the collection guide explains each capture. Clients who want it maintained for them take the Readiness Retainer — that’s literally what Month 1 of each quarter is for.

Be the contractor whose evidence is already organized

Free 30-minute readiness call first — I'll tell you if this is the wrong starting point.