Skip to content

/cmmc-assessment-objectives

Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-assessment-objectives --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cmmc-assessment-objectives
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.

SKILL.md

cmmc-assessment-objectives.SKILL.md
name: cmmc-assessment-objectives
description: "Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert."
allowed-tools: Read, Glob, Grep, Write

CMMC Assessment Objectives — 800-171A Rev 2 (with Rev 3 Crosswalk)

The scoreable layer underneath every CMMC Level 2 assessment. Where `cmmc-expert` describes the CMMC program, this skill captures the **320 specific objectives** an assessor is actually scoring against, plus the structural Rev 2 → Rev 3 mapping.

How to use this skill (paired with cmmc-expert)

| Question | Skill | |---|---| | What does CMMC require, who needs L1 vs L2, how does SPRS scoring work, what's POA&M-eligible? | `cmmc-expert` | | What does an assessor look for at the objective level for 3.1.1? What does 3.13.11[a] actually say? | **this skill** | | Where does Rev 2 3.5.7 land in Rev 3? Which Rev 2 controls were withdrawn? | **this skill** | | What FedRAMP level does a CSP need for CUI? | `cmmc-expert` | | What does FIPS-validated cryptography mean in Rev 3 vs. Rev 2? | **this skill** (note in 3.13.11 crosswalk row) |

**Lookup patterns:**

  • **By control:** Jump to the family heading (`## 3.X`) → find the practice number.
  • **By objective:** Each practice lists `[a], [b], [c]...` — these are the scoreable units.
  • **By Rev 3 equivalent:** Jump to "Rev 2 → Rev 3 Crosswalk" → find the family → row by Rev 2 ID.
  • **For withdrawn controls:** See the "Quick Reference: Withdrawn Rev 2 Controls" table.

Source & Verification Status

**Layer 1 — Assessment objectives (Rev 2):**

  • Source: **NIST SP 800-171A** (June 2018; published assessment guide for 800-171 Rev 2).
  • Status: Withdrawn May 14, 2024; **still operative for CMMC Level 2** under current DoD rulemaking.
  • DOI for parent 800-171 Rev 2: https://doi.org/10.6028/NIST.SP.800-171r2
  • Text below is verbatim from the PDF.

**Layer 2 — Rev 2 → Rev 3 crosswalk:**

  • Source: **NIST SP 800-171 Rev 3** (Final, May 2024).
  • AC, AT, AU families: PDF-verified.
  • CM through SI families: high-confidence training-knowledge mapping; verify against the Rev 3 PDF before relying on it for a Rev 3 assessment deliverable.

**Critical constants for Rev 2:**

  • 14 control families · 110 controls · **320 assessment objectives**.
  • Numbering scheme: `Chapter.Family.Requirement[Objective]` — e.g., `3.1.1[a]` = AC, requirement 1, objective a.

---

Quick Reference: Counts by Family

| Family | Rev 2 Controls | Rev 2 Assessment Objectives | |---|---|---| | 3.1 Access Control (AC) | 22 | **70** | | 3.2 Awareness & Training (AT) | 3 | 9 | | 3.3 Audit & Accountability (AU) | 9 | 29 | | 3.4 Configuration Management (CM) | 9 | **44** | | 3.5 Identification & Authentication (IA) | 11 | 25 | | 3.6 Incident Response (IR) | 3 | 14 | | 3.7 Maintenance (MA) | 6 | 10 | | 3.8 Media Protection (MP) | 9 | 15 | | 3.9 Personnel Security (PS) | 2 | 4 | | 3.10 Physical Protection (PE) | 6 | 16 | | 3.11 Risk Assessment (RA) | 3 | 9 | | 3.12 Security Assessment (CA) | 4 | 14 | | 3.13 System & Comms Protection (SC) | 16 | **41** | | 3.14 System & Info Integrity (SI) | 7 | 20 | | **TOTAL** | **110** | **320** |

---

Assessment Methods Reference (per NIST SP 800-171A)

Three methods — **not four.** "Determine" is the verb each objective opens with, not a separate method.

| Method | What it means | Depth attributes | |---|---|---| | **EXAMINE** | Reviewing, inspecting, observing, studying, or analyzing assessment objects (specifications, mechanisms, activities). | Basic / Focused / Comprehensive | | **INTERVIEW** | Discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. | Basic / Focused / Comprehensive | | **TEST** | Exercising assessment objects under specified conditions to compare actual with expected behavior. | Basic (black box) / Focused (gray box) / Comprehensive (white box) |

Assessment Objects

  • **Specifications** — policies, procedures, plans, SSP, designs, requirements.
  • **Mechanisms** — hardware, software, firmware controls.
  • **Activities** — system operations, exercises, backup operations.
  • **Individuals** — system owners, admins, security personnel, users.

How to read an assessment objective

Each lettered sub-item (`[a]`, `[b]`, ...) is **one scoreable assessment objective**. For each, the assessor will (per NIST 800-171A):

1. **Determine** if the objective is satisfied. 2. Support that determination with **E/I/T** evidence — typically all three for any non-trivial control. 3. Mark it **Satisfied** or **Other Than Satisfied** for SPRS / CMMC purposes.

**Practice-level rollup:** all AOs within a practice must be Satisfied for the practice to be **MET** in a C3PAO assessment.

---

320 Assessment Objectives (NIST SP 800-171A Rev 2)

> Text below is verbatim from NIST SP 800-171A. Each lettered sub-item is one scoreable assessment objective.

3.1 ACCESS CONTROL (22 controls, 70 objectives)

**3.1.1** — Limit system access to authorized users, processes acting on behalf of authorized users, and devices.

  • [a] authorized users are identified
  • [b] processes acting on behalf of authorized users are identified
  • [c] devices (and other systems) authorized to connect to the system are identified
  • [d] system access is limited to authorized users
  • [e] system access is limited to processes acting on behalf of authorized users
  • [f] system access is limited to authorized devices (including other systems)

**3.1.2** — Limit system access to the types of transactions and functions that authorized users are permitted to execute.

  • [a] the types of transactions and functions that authorized users are permitted to execute are defined
  • [b] system access is limited to the defined types of transactions and functions for authorized users

**3.1.3** — Control the flow of CUI in accordance with approved a

Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked