
- Policies & Standards - CMMC 2.0 L1 & FAR 52.204-21
- Procedures - CMMC 2.0 L1 & FAR 52.204-21
Don't Write It From Scratch.
If a prime contractor or the DoD asked you to show CMMC 2.0 Level 1 and FAR 52.204-21 compliance today, could you produce the documentation, or would you be assembling it from a blank page? CMMC Bundle 1 gives you a running start: editable policies, standards, and procedures scoped to Level 1 and FAR 52.204-21 for organizations handling Federal Contract Information (FCI), ready to tailor rather than author, getting you roughly 80 to 90 percent of the way there from day one.
The 17 requirements in CMMC Level 1 are based on 15 basic cybersecurity requirements found in FAR 52.204-21. The issue with this structure is that it is not conducive to make quality cybersecurity documentation (e.g., policies, standards and procedures). To address that weakness, the structure of the documentation leverages the Secure Controls Framework (SCF), since there is NIST IR 8477 Set Theory Relationship Mapping (STRM) that provides detailed justification for how SCF controls address both FAR 52.204-21 and CMMC L1 requirements. There is also coverage for FAR 52.204-27 and FAR Section 889, since those are clauses that you will likely need to address already if you are dealing with FAR 52.204-21 that focus on not using prohibited technologies.
The policies, standards and procedures also add in SCF CORE Fundamentals controls to provide "reasonable cybersecurity practices" that fill in a lot of gaps from CMMC L1 and FAR 52.204-21. The reason for this is CMMC L1 and FAR 52.204-21 were never meant to be a stand-alone cybersecurity program, where the US Government's expectation is that contractors have an existing cybersecurity program in place and these requirements are just existing practices that exist. Being an editable document, you can easily delete out the SCF CORE Fundamentals content (e.g., need for policies & standards, assigned cybersecurity roles, asset inventories, etc.) if you do not want it, but realistically you need those fundamental requirements if you do not already have them in place.

This bundle is intentionally focused and lightweight. Organizations that only need FCI-level protection (not CUI) can use this bundle as an efficient, cost-effective path to compliance without the overhead of full NIST 800-171 documentation.
What Is The CMMC Bundle 1?
FAR 52.204-21 cybersecurity requirements form the basis for what CMMC Level 1 practices. While FAR 52.204-21 has 15 requirements, CMMC Level 1 adds 2 additional requirements. The CMMC Bundle #1 contains coverage for both FAR 52.204-21 and CMMC 2.0 Level 1 requirements.

CMMC Bundle 1 is a CMMC 2.0 Level 1 and FAR 52.204-21 compliance documentation bundle. It provides focused documentation for organizations that handle Federal Contract Information (FCI) but do not handle Controlled Unclassified Information (CUI).
The CMMC Bundle 1 combines two ComplianceForge products into a single bundle. Each product remains independently licensed, but they are delivered together as one coordinated set.
Rather than starting from a blank page across multiple documentation areas, the CMMC Bundle 1 provides a professionally-written baseline for every product in the bundle. Customization effort is concentrated on tailoring, not on writing.
No Software To Install
This bundle is a one-time purchase of editable Microsoft Office-based documentation templates. There is no software to install, no agent to deploy, no account to provision, and no cloud environment to configure. If your organization can open and edit Microsoft Word or Excel files (or compatible tools like OpenOffice and Google Workspace), you can use every product in this bundle.
Microsoft Word and Excel
Delivered as fully editable .docx and .xlsx files. Compatible with Word 2016 and newer, Microsoft 365, OpenOffice, LibreOffice, and Google Docs/Sheets.
Email Delivery
All documents in the bundle are delivered via email download link within 1-2 business days of purchase. There is no installer, no license server, and no activation step.
One-Time Purchase
A single-entity license is included with purchase. The bundle price is a one-time charge, although optional update subscriptions are available for individual products as frameworks evolve.

This deployment model is intentional. Cybersecurity documentation benefits from being in the organization's own hands, inside the organization's own version control and document management systems, rather than locked inside a vendor's SaaS tool. Once delivered, every document in this bundle belongs to the buyer.
What Problems Does The CMMC Bundle 1 Solve?
Organizations face a common pattern when building cybersecurity documentation: individual products solve individual problems, but real programs need multiple documentation layers working together. The CMMC Bundle 1 is designed to fill that gap.
Scattered Documentation
Individual products like policies, procedures, and risk programs need to work together. The CMMC Bundle 1 provides coordinated documentation sets that reference each other correctly.
Faster Program Stand-Up
Standing up a cybersecurity program requires documentation across multiple domains. The CMMC Bundle 1 covers multiple domains at once, compressing program stand-up timelines.
Audit Completeness
Audits and customer questionnaires typically ask for documentation across multiple domains. The CMMC Bundle 1 ensures no gaps in the documentation set that auditors review.
How Does The CMMC Bundle 1 Solve These Problems?
The CMMC Bundle 1 addresses multi-domain documentation challenges with a pre-assembled, coordinated set of products at a discount.
Coordinated Content
Every product in the CMMC Bundle 1 was designed by ComplianceForge to work together. Cross-references between products are consistent, and no conflicting guidance exists across documents.
Audit-Defensible Documentation
Every document in the bundle is written to withstand scrutiny by external assessors. Mapped to leading frameworks with footnoted references throughout.
Same-Day Delivery
ComplianceForge processes most orders the same business day. Expect delivery within 1-2 business days of purchase, with all products arriving together.
What Is Included In The CMMC Bundle 1?
The CMMC Bundle 1 includes 2 ComplianceForge products delivered together as a discounted bundle. Each product listed below is a complete, standalone deliverable. The bundle discount applies because these products are frequently purchased together.


Cost Savings Estimate - CMMC Bundle 1
When you look at the costs associated with either (1) hiring an external consultant to write cybersecurity documentation for you or (2) tasking your internal staff to write it, the cost comparisons paint a clear picture that buying from ComplianceForge is the logical option. Compared to hiring a consultant, you can save months of wait time and tens of thousands of dollars. Whereas, compared to writing your own documentation, you can potentially save hundreds of work hours and the associated cost of lost productivity. Purchasing this bundle from ComplianceForge offers these fundamental advantages when compared to the other options for obtaining quality cybersecurity documentation:
Internal Staff Cost
For your internal staff to generate comparable documentation, it would take them an estimated 1,000 internal staff work hours, which equates to a cost of approximately $94,500 staff-related expenses. This is about 12-24 months of development time where your staff would be diverted from other work.
The CMMC Bundle 1 is approximately 6% of the cost for your internal staff to generate equivalent documentation.
External Consultant Cost
If you hire a consultant to generate this documentation, it would take them an estimated 700 contractor work hours, which equates to a cost of approximately $222,000. This is about 9-18 months of development time for a contractor to provide you with the deliverable.
The CMMC Bundle 1 is approximately 3% of the cost for an external consultant to generate equivalent documentation.

How Much Customization Is Remaining?
Given the difficult nature of writing templated cybersecurity documentation, ComplianceForge aims for approximately an 80 - 90% solution because it is impossible to write a 100% cookie-cutter document that can be equally applied across every organization. ComplianceForge did the heavy lifting, and the remaining work is to fine-tune the CMMC Bundle 1 with the specific information that only your organization knows.
In practice, customization across all products in this bundle is essentially filling in the blanks and following the guidance provided to identify the who, what, when, where, why, and how for your specific environment. Typical customization tasks include adding your company name and logo (applied automatically to every document in the bundle), tailoring parameters such as review cadences and thresholds, naming specific owner roles, and removing sections that do not apply to your organization.
Professional Services
ComplianceForge offers optional professional services to customize purchased documentation. Professional services are not required to customize ComplianceForge documentation. However, some clients want our subject matter expertise to help customize their documentation to meet their specific business needs. If you have any questions about our professional services, please contact us at:
We offer the following professional service bundles:
5-Hour Bundle
This includes five (5) hours of professional services, which may be beneficial for companies that need some guidance on getting started with how to tailor their documentation.
10-Hour Bundle
This includes ten (10) hours of professional services, which may be beneficial for companies that need additional guidance on tailoring their documentation to meet their compliance requirements.
20-Hour Bundle
This includes twenty (20) hours of professional services, which may be beneficial for companies that need robust services, beyond just 10 hours, to assist in tailoring their documentation to meet their compliance requirements.
Purchased professional service hours expire 120 days (4 months) from the time of purchase if unused. Hours are intended to supplement, not replace, your own customization work, since only your organization knows the exact details to tailor your documentation. For questions regarding scoping a professional services engagement or configuring a custom package, contact ComplianceForge directly through the Contact Us page.
CMMC 2.0 Level 1 / FAR 52.204-21 Coverage
The CMMC Bundle 1 is built around CMMC 2.0 Level 1 / FAR 52.204-21. Every product in the bundle is aligned with the framework, and cross-references between documents use consistent CMMC taxonomy throughout.
If your organization needs to address multiple frameworks at once, the SCF Bundle 2 (Robust Documentation Solution) provides broader coverage across 200+ laws, regulations & frameworks.
Need A Custom Bundle?
The CMMC Bundle 1 covers the most common configuration, but every organization's needs are different. ComplianceForge will build a custom bundle for any combination of products if your requirements differ from the standard bundles.
To request a custom bundle quote, contact ComplianceForge directly with a list of products you need and your timeline. Custom bundles typically receive comparable discount pricing to the standard bundles.



