---
title: "Resources: CMMC Checklist and Control Mapping"
description: "The CMMC Level 2 readiness checklist and the NIST 800-171 control mapping for AWS, Azure, and GCP. Working documents, no form, sealed on the date shown."
url: https://policycortex.com/resources
sealed: 2026-03-17
amended: 2026-03-17
register: resources
records: 3
digest: sha3:0bc88af76c87aab2971d36e2c56255efbdcba998fde580af81e462a190377953
---

# Resources: checklists and control mappings, no gate

Register / Resources

Resources are the working documents PolicyCortex publishes without a form or a gate: the CMMC Level 2 readiness checklist across all 110 NIST 800-171 requirements, and the control mapping from those requirements to AWS, Azure, and GCP configuration. Each is a reference to work from, sealed on the date shown, not a substitute for the assessment itself.

2 entries · Latest sealed 2026-03-17

## Documents, newest first

| Sealed | Document | Reading |
|---|---|---|
| 2026-03-17 | [CMMC Level 2 Readiness Checklist [Free Download]](https://policycortex.com/resources/cmmc-level-2-checklist): A practitioner-built CMMC Level 2 readiness checklist covering all 17 control families and 110 NIST 800-171 requirements. | 11 min |
| 2026-03-17 | [NIST 800-171 to Cloud Control Mapping: AWS, Azure, and GCP](https://policycortex.com/resources/nist-800-171-control-mapping): Complete mapping of all 110 NIST 800-171 Rev 2 controls to specific cloud configuration requirements across AWS, Azure, and GCP. | 19 min |

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Work the checklist. Then keep the evidence it asks for. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 5e32e1cd6a0c | 454ee7756e7b |
| REC 0001 | ENTRIES | f57fd1cdefa7 | 5e32e1cd6a0c |
| REC 0002 | RELATED RECORDS | 0bc88af76c87 | f57fd1cdefa7 |

Head sha3:0bc88af76c87aab2971d36e2c56255efbdcba998fde580af81e462a190377953. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
