Skip to content

/cmmc-expert

CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cmmc-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.

SKILL.md

cmmc-expert.SKILL.md
name: cmmc-expert
description: "CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition."
allowed-tools: Read, Glob, Grep, Write

CMMC Expert

Deep, practitioner-grade expertise in the Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors. Built from the authoritative chain: **NIST SP 800-171 Rev 2** (control text), **NIST SP 800-171A Rev 2** (320 assessment objectives), **32 CFR Part 170** (CMMC program rule), and **48 CFR / DFARS Part 204.75** (acquisition rule).

1. Program Overview & Authority

**Purpose:** Standardize verification of NIST SP 800-171 cybersecurity controls across the Defense Industrial Base (DIB) protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

**Authority chain:**

  • **32 CFR Part 170** — CMMC program rule. Effective **December 16, 2024**.
  • **48 CFR / DFARS Part 204.75** — Acquisition rule that puts CMMC into contracts. Effective **November 10, 2025**.
  • **DFARS 252.204-7012** — Pre-existing CUI safeguarding + 72-hour cyber incident reporting clause.
  • **DFARS 252.204-7019** — Solicitation provision requiring a current NIST 800-171 self-assessment score in SPRS.
  • **DFARS 252.204-7020** — Contract clause giving DoD/DIBCAC the right to verify SPRS assessments.
  • **DFARS 252.204-7021** — The primary CMMC certification requirement clause.
  • **DFARS 252.204-7025** — Solicitation provision identifying the required CMMC level for a given procurement.

**Authoritative sources to cite in deliverables:**

  • NIST SP 800-171 Rev 2 — https://doi.org/10.6028/NIST.SP.800-171r2 (Final, including updates as of 01-28-2021; withdrawn May 14, 2024 but remains operative for CMMC).
  • NIST SP 800-171A Rev 2 — assessment procedures, 320 objectives.
  • CMMC Assessment Guide L2 (current version on dodcio.defense.gov).
  • CMMC Scoping Guide L2.
  • CMMC Scoring Methodology.
  • 32 CFR Part 170 (89 FR 83214, Oct. 15, 2024).

Four-Phase Implementation Timeline

All dates keyed to **November 10, 2025** (DFARS rule effective date).

| Phase | Window | What's in contracts | |---|---|---| | **Phase 1** | 2025-11-10 → 2026-11-09 | L1 (Self), L2 (Self); L2 (C3PAO) at DoD discretion | | **Phase 2** | 2026-11-10 → 2027-11-09 | + L2 (C3PAO) as routine contractual requirement | | **Phase 3** | 2027-11-10 → 2028-11-09 | + L3 (DIBCAC) for high-sensitivity programs | | **Phase 4** | 2028-11-10 and beyond | All applicable solicitations require appropriate CMMC level |

Triennial re-assessment + annual affirmation throughout the certification cycle.

---

2. CMMC Levels (L1 / L2 / L3)

| Level | Name | Practices | Source | Assessment | POA&M Allowed | Cycle | |---|---|---|---|---|---|---| | **Level 1** | Foundational | **15** | FAR 52.204-21 | Self only | **No — never** | Annual self + annual affirmation | | **Level 2** | Advanced | **110** | NIST SP 800-171 Rev 2 | Self **or** C3PAO | Yes — restricted (see §11) | Triennial + annual affirmation | | **Level 3** | Expert | **134** (110 + 24 selected from 800-172) | NIST SP 800-171 Rev 2 + 800-172 | DCMA **DIBCAC** | Per DIBCAC methodology | Triennial + annual affirmation |

**Acronyms used here (correctly):**

  • **OSA** — Organization Seeking Assessment.
  • **OSC** — Organization Seeking Certification (used specifically in C3PAO context; OSA/OSC are largely interchangeable in practice).
  • **C3PAO** — Certified Third-Party Assessor Organization. Accredited by the Cyber AB.
  • **CCA** — Certified CMMC Assessor (must hold Tier 3 background investigation).
  • **CCP** — Certified CMMC Professional (support role).
  • **DIBCAC** — **Defense Industrial Base Cybersecurity Assessment Center** (DCMA's assessment arm; conducts L3 assessments and high-water-mark L2 verifications).
  • **DC3** — DoD Cyber Crime Center (recipient of malware samples under DFARS 7012).
  • **eMASS** — Enterprise Mission Assurance Support Service (DoD system where C3PAO assessment results are posted).
  • **SPRS** — Supplier Performance Risk System (where self-assessment scores and CMMC Status live).

**Who needs what:**

  • Handles FCI only → L1.
  • Handles CUI → L2 (Self) or L2 (C3PAO) per the contract.
  • Sensitive national-security CUI → L3.

---

3. NIST 800-171 Rev 2 — 14 Families, 110 Controls

**These are the only 14 families in Rev 2.** Any reference to Asset Management (AM), Recovery (RE), Risk Management (RM), or Situational Awareness (SA) as 800-171 families is incorrect — those names belong to CMMC v1.0 or to other catalogs.

| # | ID | Family | Controls | |---|---|---|---| | 1 | AC | Access Control | 22 | | 2 | AT | Awareness and Training | 3 | | 3 | AU | Audit and Accountability | 9 | | 4 | CM | Configuration Management | 9 | | 5 | IA | Identification and Authentication | 11 | | 6 | IR | Incident Response | 3 | | 7 | MA | Maintenance | 6 | | 8 | MP | Media Protection | 9 | | 9 | PS | Personnel Security | 2 | | 10 | PE | Physical Protection | 6 | | 11 | **RA** | **Risk Assessment** | 3 | | 12 | CA | Security Assessment | 4 | | 13 | SC | System and Communications Protection | 16 | | 14 | SI | System and Information Integrity | 7 | | | | **TOTAL** | **110** |

**Numbering scheme:** `Chapter.Family.Requirement` (e.g., 3.1.1 = Chapter 3, AC family, Requirement 1). Each requirement is either **Basic** (high-level) or **Derived** (technical implementation specifics) in Rev 2.

---

4. 320 Assessment Objectives (NIST SP 800-171A Rev 2)

Each 800-171 requirement decomposes into **lettered assessment objectives** (e.g., 3.1.1[a]–[f]). All objectives within a practice must be satisfied for the practice to be **Met** in a C3PAO assessment.

| Family | Controls | Assessment Objectives | |---|---|---| | 3.1 Access Control | 22 | **70** | | 3.2 Awareness & Training | 3 | 9 | | 3.3 Audit & Accountability | 9 | 29 | | 3.4 Configuration Ma

Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked