CMMC Pocket Guide is a fast Android reference app for Defense Industrial Base cybersecurity, IT, compliance, and assessment-preparation work.
Use it to look up CMMC controls, assessment objectives, source references, glossary terms, and FAR/DFARS clause references without turning every question into a document hunt. The app is designed for quick field lookup, study, and preparation conversations.
Free features include:
- CMMC Level 1 and Level 2 controls, plus selected Level 3 reference content
- Structured assessment objectives
- Search and filters by level, family, and assessment method
- Pinned controls for quick return
- Glossary terms with source citations
- FAR/DFARS clause reference cards
- Source and disclaimer notes
- Offline-first reference access
Optional CMMC Pocket Guide Pro features are available through Google Play as a one-time in-app purchase. Pro tools are designed to support planning and review workflows, including POA&M assistance, scoring support, role guidance, and review-session preparation.
Official source links for government and standards information referenced in the app:
- DoD CMMC Program: https://dodcio.defense.gov/CMMC/
- 32 CFR Part 170: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-M/part-170
- NIST SP 800-171 Rev. 2: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
- NIST SP 800-172: https://csrc.nist.gov/publications/detail/sp/800-172/final
- FAR 52.204-21: https://www.acquisition.gov/far/52.204-21
- DFARS 252.204-7012: https://www.acquisition.gov/dfars/252.204-7012
CMMC Pocket Guide is independently built and maintained by CMDLabs LLC. It is not affiliated with, endorsed by, or operated by the DoD, Cyber AB, NIST, or any official CMMC assessment body.
The app does not provide legal advice, certification decisions, compliance determinations, audit conclusions, or a substitute for qualified professional assessment. Always verify official source documents and qualified assessor guidance for contract, legal, or assessment decisions.
The app does not store CUI, evidence, customer system details, assessment artifacts, files, media, or external storage content.