/cmmc-assessment-objectives
Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-assessment-objectives --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/cmmc-assessment-objectives
Context preview
The summary Claude sees to decide when to auto-load this skill.
Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.
SKILL.md
cmmc-assessment-objectives.SKILL.mdname: cmmc-assessment-objectives
description: "Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert."
allowed-tools: Read, Glob, Grep, Write
CMMC Assessment Objectives — 800-171A Rev 2 (with Rev 3 Crosswalk)
The scoreable layer underneath every CMMC Level 2 assessment. Where `cmmc-expert` describes the CMMC program, this skill captures the **320 specific objectives** an assessor is actually scoring against, plus the structural Rev 2 → Rev 3 mapping.
How to use this skill (paired with cmmc-expert)
| Question | Skill | |---|---| | What does CMMC require, who needs L1 vs L2, how does SPRS scoring work, what's POA&M-eligible? | `cmmc-expert` | | What does an assessor look for at the objective level for 3.1.1? What does 3.13.11[a] actually say? | **this skill** | | Where does Rev 2 3.5.7 land in Rev 3? Which Rev 2 controls were withdrawn? | **this skill** | | What FedRAMP level does a CSP need for CUI? | `cmmc-expert` | | What does FIPS-validated cryptography mean in Rev 3 vs. Rev 2? | **this skill** (note in 3.13.11 crosswalk row) |
**Lookup patterns:**
- **By control:** Jump to the family heading (`## 3.X`) → find the practice number.
- **By objective:** Each practice lists `[a], [b], [c]...` — these are the scoreable units.
- **By Rev 3 equivalent:** Jump to "Rev 2 → Rev 3 Crosswalk" → find the family → row by Rev 2 ID.
- **For withdrawn controls:** See the "Quick Reference: Withdrawn Rev 2 Controls" table.
Source & Verification Status
**Layer 1 — Assessment objectives (Rev 2):**
- Source: **NIST SP 800-171A** (June 2018; published assessment guide for 800-171 Rev 2).
- Status: Withdrawn May 14, 2024; **still operative for CMMC Level 2** under current DoD rulemaking.
- DOI for parent 800-171 Rev 2: https://doi.org/10.6028/NIST.SP.800-171r2
- Text below is verbatim from the PDF.
**Layer 2 — Rev 2 → Rev 3 crosswalk:**
- Source: **NIST SP 800-171 Rev 3** (Final, May 2024).
- AC, AT, AU families: PDF-verified.
- CM through SI families: high-confidence training-knowledge mapping; verify against the Rev 3 PDF before relying on it for a Rev 3 assessment deliverable.
**Critical constants for Rev 2:**
- 14 control families · 110 controls · **320 assessment objectives**.
- Numbering scheme: `Chapter.Family.Requirement[Objective]` — e.g., `3.1.1[a]` = AC, requirement 1, objective a.
---
Quick Reference: Counts by Family
| Family | Rev 2 Controls | Rev 2 Assessment Objectives | |---|---|---| | 3.1 Access Control (AC) | 22 | **70** | | 3.2 Awareness & Training (AT) | 3 | 9 | | 3.3 Audit & Accountability (AU) | 9 | 29 | | 3.4 Configuration Management (CM) | 9 | **44** | | 3.5 Identification & Authentication (IA) | 11 | 25 | | 3.6 Incident Response (IR) | 3 | 14 | | 3.7 Maintenance (MA) | 6 | 10 | | 3.8 Media Protection (MP) | 9 | 15 | | 3.9 Personnel Security (PS) | 2 | 4 | | 3.10 Physical Protection (PE) | 6 | 16 | | 3.11 Risk Assessment (RA) | 3 | 9 | | 3.12 Security Assessment (CA) | 4 | 14 | | 3.13 System & Comms Protection (SC) | 16 | **41** | | 3.14 System & Info Integrity (SI) | 7 | 20 | | **TOTAL** | **110** | **320** |
---
Assessment Methods Reference (per NIST SP 800-171A)
Three methods — **not four.** "Determine" is the verb each objective opens with, not a separate method.
| Method | What it means | Depth attributes | |---|---|---| | **EXAMINE** | Reviewing, inspecting, observing, studying, or analyzing assessment objects (specifications, mechanisms, activities). | Basic / Focused / Comprehensive | | **INTERVIEW** | Discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. | Basic / Focused / Comprehensive | | **TEST** | Exercising assessment objects under specified conditions to compare actual with expected behavior. | Basic (black box) / Focused (gray box) / Comprehensive (white box) |
Assessment Objects
- **Specifications** — policies, procedures, plans, SSP, designs, requirements.
- **Mechanisms** — hardware, software, firmware controls.
- **Activities** — system operations, exercises, backup operations.
- **Individuals** — system owners, admins, security personnel, users.
How to read an assessment objective
Each lettered sub-item (`[a]`, `[b]`, ...) is **one scoreable assessment objective**. For each, the assessor will (per NIST 800-171A):
1. **Determine** if the objective is satisfied. 2. Support that determination with **E/I/T** evidence — typically all three for any non-trivial control. 3. Mark it **Satisfied** or **Other Than Satisfied** for SPRS / CMMC purposes.
**Practice-level rollup:** all AOs within a practice must be Satisfied for the practice to be **MET** in a C3PAO assessment.
---
320 Assessment Objectives (NIST SP 800-171A Rev 2)
> Text below is verbatim from NIST SP 800-171A. Each lettered sub-item is one scoreable assessment objective.
3.1 ACCESS CONTROL (22 controls, 70 objectives)
**3.1.1** — Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
- [a] authorized users are identified
- [b] processes acting on behalf of authorized users are identified
- [c] devices (and other systems) authorized to connect to the system are identified
- [d] system access is limited to authorized users
- [e] system access is limited to processes acting on behalf of authorized users
- [f] system access is limited to authorized devices (including other systems)
**3.1.2** — Limit system access to the types of transactions and functions that authorized users are permitted to execute.
- [a] the types of transactions and functions that authorized users are permitted to execute are defined
- [b] system access is limited to the defined types of transactions and functions for authorized users
**3.1.3** — Control the flow of CUI in accordance with approved a
Read more
name: cmmc-assessment-objectives description: "Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert." allowed-tools: Read, Glob, Grep, Write
CMMC Assessment Objectives — 800-171A Rev 2 (with Rev 3 Crosswalk)
The scoreable layer underneath every CMMC Level 2 assessment. Where `cmmc-expert` describes the CMMC program, this skill captures the **320 specific objectives** an assessor is actually scoring against, plus the structural Rev 2 → Rev 3 mapping.
How to use this skill (paired with cmmc-expert)
| Question | Skill | |---|---| | What does CMMC require, who needs L1 vs L2, how does SPRS scoring work, what's POA&M-eligible? | `cmmc-expert` | | What does an assessor look for at the objective level for 3.1.1? What does 3.13.11[a] actually say? | **this skill** | | Where does Rev 2 3.5.7 land in Rev 3? Which Rev 2 controls were withdrawn? | **this skill** | | What FedRAMP level does a CSP need for CUI? | `cmmc-expert` | | What does FIPS-validated cryptography mean in Rev 3 vs. Rev 2? | **this skill** (note in 3.13.11 crosswalk row) |
**Lookup patterns:**
- **By control:** Jump to the family heading (`## 3.X`) → find the practice number.
- **By objective:** Each practice lists `[a], [b], [c]...` — these are the scoreable units.
- **By Rev 3 equivalent:** Jump to "Rev 2 → Rev 3 Crosswalk" → find the family → row by Rev 2 ID.
- **For withdrawn controls:** See the "Quick Reference: Withdrawn Rev 2 Controls" table.
Source & Verification Status
**Layer 1 — Assessment objectives (Rev 2):**
- Source: **NIST SP 800-171A** (June 2018; published assessment guide for 800-171 Rev 2).
- Status: Withdrawn May 14, 2024; **still operative for CMMC Level 2** under current DoD rulemaking.
- DOI for parent 800-171 Rev 2: https://doi.org/10.6028/NIST.SP.800-171r2
- Text below is verbatim from the PDF.
**Layer 2 — Rev 2 → Rev 3 crosswalk:**
- Source: **NIST SP 800-171 Rev 3** (Final, May 2024).
- AC, AT, AU families: PDF-verified.
- CM through SI families: high-confidence training-knowledge mapping; verify against the Rev 3 PDF before relying on it for a Rev 3 assessment deliverable.
**Critical constants for Rev 2:**
- 14 control families · 110 controls · **320 assessment objectives**.
- Numbering scheme: `Chapter.Family.Requirement[Objective]` — e.g., `3.1.1[a]` = AC, requirement 1, objective a.
---
Quick Reference: Counts by Family
| Family | Rev 2 Controls | Rev 2 Assessment Objectives | |---|---|---| | 3.1 Access Control (AC) | 22 | **70** | | 3.2 Awareness & Training (AT) | 3 | 9 | | 3.3 Audit & Accountability (AU) | 9 | 29 | | 3.4 Configuration Management (CM) | 9 | **44** | | 3.5 Identification & Authentication (IA) | 11 | 25 | | 3.6 Incident Response (IR) | 3 | 14 | | 3.7 Maintenance (MA) | 6 | 10 | | 3.8 Media Protection (MP) | 9 | 15 | | 3.9 Personnel Security (PS) | 2 | 4 | | 3.10 Physical Protection (PE) | 6 | 16 | | 3.11 Risk Assessment (RA) | 3 | 9 | | 3.12 Security Assessment (CA) | 4 | 14 | | 3.13 System & Comms Protection (SC) | 16 | **41** | | 3.14 System & Info Integrity (SI) | 7 | 20 | | **TOTAL** | **110** | **320** |
---
Assessment Methods Reference (per NIST SP 800-171A)
Three methods — **not four.** "Determine" is the verb each objective opens with, not a separate method.
| Method | What it means | Depth attributes | |---|---|---| | **EXAMINE** | Reviewing, inspecting, observing, studying, or analyzing assessment objects (specifications, mechanisms, activities). | Basic / Focused / Comprehensive | | **INTERVIEW** | Discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. | Basic / Focused / Comprehensive | | **TEST** | Exercising assessment objects under specified conditions to compare actual with expected behavior. | Basic (black box) / Focused (gray box) / Comprehensive (white box) |
Assessment Objects
- **Specifications** — policies, procedures, plans, SSP, designs, requirements.
- **Mechanisms** — hardware, software, firmware controls.
- **Activities** — system operations, exercises, backup operations.
- **Individuals** — system owners, admins, security personnel, users.
How to read an assessment objective
Each lettered sub-item (`[a]`, `[b]`, ...) is **one scoreable assessment objective**. For each, the assessor will (per NIST 800-171A):
1. **Determine** if the objective is satisfied. 2. Support that determination with **E/I/T** evidence — typically all three for any non-trivial control. 3. Mark it **Satisfied** or **Other Than Satisfied** for SPRS / CMMC purposes.
**Practice-level rollup:** all AOs within a practice must be Satisfied for the practice to be **MET** in a C3PAO assessment.
---
320 Assessment Objectives (NIST SP 800-171A Rev 2)
> Text below is verbatim from NIST SP 800-171A. Each lettered sub-item is one scoreable assessment objective.
3.1 ACCESS CONTROL (22 controls, 70 objectives)
**3.1.1** — Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
- [a] authorized users are identified
- [b] processes acting on behalf of authorized users are identified
- [c] devices (and other systems) authorized to connect to the system are identified
- [d] system access is limited to authorized users
- [e] system access is limited to processes acting on behalf of authorized users
- [f] system access is limited to authorized devices (including other systems)
**3.1.2** — Limit system access to the types of transactions and functions that authorized users are permitted to execute.
- [a] the types of transactions and functions that authorized users are permitted to execute are defined
- [b] system access is limited to the defined types of transactions and functions for authorized users
**3.1.3** — Control the flow of CUI in accordance with approved a
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

