/cmmc-expert
CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/cmmc-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.
SKILL.md
cmmc-expert.SKILL.mdname: cmmc-expert
description: "CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition."
allowed-tools: Read, Glob, Grep, Write
CMMC Expert
Deep, practitioner-grade expertise in the Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors. Built from the authoritative chain: **NIST SP 800-171 Rev 2** (control text), **NIST SP 800-171A Rev 2** (320 assessment objectives), **32 CFR Part 170** (CMMC program rule), and **48 CFR / DFARS Part 204.75** (acquisition rule).
1. Program Overview & Authority
**Purpose:** Standardize verification of NIST SP 800-171 cybersecurity controls across the Defense Industrial Base (DIB) protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
**Authority chain:**
- **32 CFR Part 170** — CMMC program rule. Effective **December 16, 2024**.
- **48 CFR / DFARS Part 204.75** — Acquisition rule that puts CMMC into contracts. Effective **November 10, 2025**.
- **DFARS 252.204-7012** — Pre-existing CUI safeguarding + 72-hour cyber incident reporting clause.
- **DFARS 252.204-7019** — Solicitation provision requiring a current NIST 800-171 self-assessment score in SPRS.
- **DFARS 252.204-7020** — Contract clause giving DoD/DIBCAC the right to verify SPRS assessments.
- **DFARS 252.204-7021** — The primary CMMC certification requirement clause.
- **DFARS 252.204-7025** — Solicitation provision identifying the required CMMC level for a given procurement.
**Authoritative sources to cite in deliverables:**
- NIST SP 800-171 Rev 2 — https://doi.org/10.6028/NIST.SP.800-171r2 (Final, including updates as of 01-28-2021; withdrawn May 14, 2024 but remains operative for CMMC).
- NIST SP 800-171A Rev 2 — assessment procedures, 320 objectives.
- CMMC Assessment Guide L2 (current version on dodcio.defense.gov).
- CMMC Scoping Guide L2.
- CMMC Scoring Methodology.
- 32 CFR Part 170 (89 FR 83214, Oct. 15, 2024).
Four-Phase Implementation Timeline
All dates keyed to **November 10, 2025** (DFARS rule effective date).
| Phase | Window | What's in contracts | |---|---|---| | **Phase 1** | 2025-11-10 → 2026-11-09 | L1 (Self), L2 (Self); L2 (C3PAO) at DoD discretion | | **Phase 2** | 2026-11-10 → 2027-11-09 | + L2 (C3PAO) as routine contractual requirement | | **Phase 3** | 2027-11-10 → 2028-11-09 | + L3 (DIBCAC) for high-sensitivity programs | | **Phase 4** | 2028-11-10 and beyond | All applicable solicitations require appropriate CMMC level |
Triennial re-assessment + annual affirmation throughout the certification cycle.
---
2. CMMC Levels (L1 / L2 / L3)
| Level | Name | Practices | Source | Assessment | POA&M Allowed | Cycle | |---|---|---|---|---|---|---| | **Level 1** | Foundational | **15** | FAR 52.204-21 | Self only | **No — never** | Annual self + annual affirmation | | **Level 2** | Advanced | **110** | NIST SP 800-171 Rev 2 | Self **or** C3PAO | Yes — restricted (see §11) | Triennial + annual affirmation | | **Level 3** | Expert | **134** (110 + 24 selected from 800-172) | NIST SP 800-171 Rev 2 + 800-172 | DCMA **DIBCAC** | Per DIBCAC methodology | Triennial + annual affirmation |
**Acronyms used here (correctly):**
- **OSA** — Organization Seeking Assessment.
- **OSC** — Organization Seeking Certification (used specifically in C3PAO context; OSA/OSC are largely interchangeable in practice).
- **C3PAO** — Certified Third-Party Assessor Organization. Accredited by the Cyber AB.
- **CCA** — Certified CMMC Assessor (must hold Tier 3 background investigation).
- **CCP** — Certified CMMC Professional (support role).
- **DIBCAC** — **Defense Industrial Base Cybersecurity Assessment Center** (DCMA's assessment arm; conducts L3 assessments and high-water-mark L2 verifications).
- **DC3** — DoD Cyber Crime Center (recipient of malware samples under DFARS 7012).
- **eMASS** — Enterprise Mission Assurance Support Service (DoD system where C3PAO assessment results are posted).
- **SPRS** — Supplier Performance Risk System (where self-assessment scores and CMMC Status live).
**Who needs what:**
- Handles FCI only → L1.
- Handles CUI → L2 (Self) or L2 (C3PAO) per the contract.
- Sensitive national-security CUI → L3.
---
3. NIST 800-171 Rev 2 — 14 Families, 110 Controls
**These are the only 14 families in Rev 2.** Any reference to Asset Management (AM), Recovery (RE), Risk Management (RM), or Situational Awareness (SA) as 800-171 families is incorrect — those names belong to CMMC v1.0 or to other catalogs.
| # | ID | Family | Controls | |---|---|---|---| | 1 | AC | Access Control | 22 | | 2 | AT | Awareness and Training | 3 | | 3 | AU | Audit and Accountability | 9 | | 4 | CM | Configuration Management | 9 | | 5 | IA | Identification and Authentication | 11 | | 6 | IR | Incident Response | 3 | | 7 | MA | Maintenance | 6 | | 8 | MP | Media Protection | 9 | | 9 | PS | Personnel Security | 2 | | 10 | PE | Physical Protection | 6 | | 11 | **RA** | **Risk Assessment** | 3 | | 12 | CA | Security Assessment | 4 | | 13 | SC | System and Communications Protection | 16 | | 14 | SI | System and Information Integrity | 7 | | | | **TOTAL** | **110** |
**Numbering scheme:** `Chapter.Family.Requirement` (e.g., 3.1.1 = Chapter 3, AC family, Requirement 1). Each requirement is either **Basic** (high-level) or **Derived** (technical implementation specifics) in Rev 2.
---
4. 320 Assessment Objectives (NIST SP 800-171A Rev 2)
Each 800-171 requirement decomposes into **lettered assessment objectives** (e.g., 3.1.1[a]–[f]). All objectives within a practice must be satisfied for the practice to be **Met** in a C3PAO assessment.
| Family | Controls | Assessment Objectives | |---|---|---| | 3.1 Access Control | 22 | **70** | | 3.2 Awareness & Training | 3 | 9 | | 3.3 Audit & Accountability | 9 | 29 | | 3.4 Configuration Ma
Read more
name: cmmc-expert description: "CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition." allowed-tools: Read, Glob, Grep, Write
CMMC Expert
Deep, practitioner-grade expertise in the Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors. Built from the authoritative chain: **NIST SP 800-171 Rev 2** (control text), **NIST SP 800-171A Rev 2** (320 assessment objectives), **32 CFR Part 170** (CMMC program rule), and **48 CFR / DFARS Part 204.75** (acquisition rule).
1. Program Overview & Authority
**Purpose:** Standardize verification of NIST SP 800-171 cybersecurity controls across the Defense Industrial Base (DIB) protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
**Authority chain:**
- **32 CFR Part 170** — CMMC program rule. Effective **December 16, 2024**.
- **48 CFR / DFARS Part 204.75** — Acquisition rule that puts CMMC into contracts. Effective **November 10, 2025**.
- **DFARS 252.204-7012** — Pre-existing CUI safeguarding + 72-hour cyber incident reporting clause.
- **DFARS 252.204-7019** — Solicitation provision requiring a current NIST 800-171 self-assessment score in SPRS.
- **DFARS 252.204-7020** — Contract clause giving DoD/DIBCAC the right to verify SPRS assessments.
- **DFARS 252.204-7021** — The primary CMMC certification requirement clause.
- **DFARS 252.204-7025** — Solicitation provision identifying the required CMMC level for a given procurement.
**Authoritative sources to cite in deliverables:**
- NIST SP 800-171 Rev 2 — https://doi.org/10.6028/NIST.SP.800-171r2 (Final, including updates as of 01-28-2021; withdrawn May 14, 2024 but remains operative for CMMC).
- NIST SP 800-171A Rev 2 — assessment procedures, 320 objectives.
- CMMC Assessment Guide L2 (current version on dodcio.defense.gov).
- CMMC Scoping Guide L2.
- CMMC Scoring Methodology.
- 32 CFR Part 170 (89 FR 83214, Oct. 15, 2024).
Four-Phase Implementation Timeline
All dates keyed to **November 10, 2025** (DFARS rule effective date).
| Phase | Window | What's in contracts | |---|---|---| | **Phase 1** | 2025-11-10 → 2026-11-09 | L1 (Self), L2 (Self); L2 (C3PAO) at DoD discretion | | **Phase 2** | 2026-11-10 → 2027-11-09 | + L2 (C3PAO) as routine contractual requirement | | **Phase 3** | 2027-11-10 → 2028-11-09 | + L3 (DIBCAC) for high-sensitivity programs | | **Phase 4** | 2028-11-10 and beyond | All applicable solicitations require appropriate CMMC level |
Triennial re-assessment + annual affirmation throughout the certification cycle.
---
2. CMMC Levels (L1 / L2 / L3)
| Level | Name | Practices | Source | Assessment | POA&M Allowed | Cycle | |---|---|---|---|---|---|---| | **Level 1** | Foundational | **15** | FAR 52.204-21 | Self only | **No — never** | Annual self + annual affirmation | | **Level 2** | Advanced | **110** | NIST SP 800-171 Rev 2 | Self **or** C3PAO | Yes — restricted (see §11) | Triennial + annual affirmation | | **Level 3** | Expert | **134** (110 + 24 selected from 800-172) | NIST SP 800-171 Rev 2 + 800-172 | DCMA **DIBCAC** | Per DIBCAC methodology | Triennial + annual affirmation |
**Acronyms used here (correctly):**
- **OSA** — Organization Seeking Assessment.
- **OSC** — Organization Seeking Certification (used specifically in C3PAO context; OSA/OSC are largely interchangeable in practice).
- **C3PAO** — Certified Third-Party Assessor Organization. Accredited by the Cyber AB.
- **CCA** — Certified CMMC Assessor (must hold Tier 3 background investigation).
- **CCP** — Certified CMMC Professional (support role).
- **DIBCAC** — **Defense Industrial Base Cybersecurity Assessment Center** (DCMA's assessment arm; conducts L3 assessments and high-water-mark L2 verifications).
- **DC3** — DoD Cyber Crime Center (recipient of malware samples under DFARS 7012).
- **eMASS** — Enterprise Mission Assurance Support Service (DoD system where C3PAO assessment results are posted).
- **SPRS** — Supplier Performance Risk System (where self-assessment scores and CMMC Status live).
**Who needs what:**
- Handles FCI only → L1.
- Handles CUI → L2 (Self) or L2 (C3PAO) per the contract.
- Sensitive national-security CUI → L3.
---
3. NIST 800-171 Rev 2 — 14 Families, 110 Controls
**These are the only 14 families in Rev 2.** Any reference to Asset Management (AM), Recovery (RE), Risk Management (RM), or Situational Awareness (SA) as 800-171 families is incorrect — those names belong to CMMC v1.0 or to other catalogs.
| # | ID | Family | Controls | |---|---|---|---| | 1 | AC | Access Control | 22 | | 2 | AT | Awareness and Training | 3 | | 3 | AU | Audit and Accountability | 9 | | 4 | CM | Configuration Management | 9 | | 5 | IA | Identification and Authentication | 11 | | 6 | IR | Incident Response | 3 | | 7 | MA | Maintenance | 6 | | 8 | MP | Media Protection | 9 | | 9 | PS | Personnel Security | 2 | | 10 | PE | Physical Protection | 6 | | 11 | **RA** | **Risk Assessment** | 3 | | 12 | CA | Security Assessment | 4 | | 13 | SC | System and Communications Protection | 16 | | 14 | SI | System and Information Integrity | 7 | | | | **TOTAL** | **110** |
**Numbering scheme:** `Chapter.Family.Requirement` (e.g., 3.1.1 = Chapter 3, AC family, Requirement 1). Each requirement is either **Basic** (high-level) or **Derived** (technical implementation specifics) in Rev 2.
---
4. 320 Assessment Objectives (NIST SP 800-171A Rev 2)
Each 800-171 requirement decomposes into **lettered assessment objectives** (e.g., 3.1.1[a]–[f]). All objectives within a practice must be satisfied for the practice to be **Met** in a C3PAO assessment.
| Family | Controls | Assessment Objectives | |---|---|---| | 3.1 Access Control | 22 | **70** | | 3.2 Awareness & Training | 3 | 9 | | 3.3 Audit & Accountability | 9 | 29 | | 3.4 Configuration Ma
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

