academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cmmc-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.
name: cmmc-expert description: "CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition." allowed-tools: Read, Glob, Grep, Write
Deep, practitioner-grade expertise in the Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors. Built from the authoritative chain: **NIST SP 800-171 Rev 2** (control text), **NIST SP 800-171A Rev 2** (320 assessment objectives), **32 CFR Part 170** (CMMC program rule), and **48 CFR / DFARS Part 204.75** (acquisition rule).
**Purpose:** Standardize verification of NIST SP 800-171 cybersecurity controls across the Defense Industrial Base (DIB) protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
**Authority chain:**
**Authoritative sources to cite in deliverables:**
All dates keyed to **November 10, 2025** (DFARS rule effective date).
| Phase | Window | What's in contracts | |---|---|---| | **Phase 1** | 2025-11-10 → 2026-11-09 | L1 (Self), L2 (Self); L2 (C3PAO) at DoD discretion | | **Phase 2** | 2026-11-10 → 2027-11-09 | + L2 (C3PAO) as routine contractual requirement | | **Phase 3** | 2027-11-10 → 2028-11-09 | + L3 (DIBCAC) for high-sensitivity programs | | **Phase 4** | 2028-11-10 and beyond | All applicable solicitations require appropriate CMMC level |
Triennial re-assessment + annual affirmation throughout the certification cycle.
---
| Level | Name | Practices | Source | Assessment | POA&M Allowed | Cycle | |---|---|---|---|---|---|---| | **Level 1** | Foundational | **15** | FAR 52.204-21 | Self only | **No — never** | Annual self + annual affirmation | | **Level 2** | Advanced | **110** | NIST SP 800-171 Rev 2 | Self **or** C3PAO | Yes — restricted (see §11) | Triennial + annual affirmation | | **Level 3** | Expert | **134** (110 + 24 selected from 800-172) | NIST SP 800-171 Rev 2 + 800-172 | DCMA **DIBCAC** | Per DIBCAC methodology | Triennial + annual affirmation |
**Acronyms used here (correctly):**
**Who needs what:**
---
**These are the only 14 families in Rev 2.** Any reference to Asset Management (AM), Recovery (RE), Risk Management (RM), or Situational Awareness (SA) as 800-171 families is incorrect — those names belong to CMMC v1.0 or to other catalogs.
| # | ID | Family | Controls | |---|---|---|---| | 1 | AC | Access Control | 22 | | 2 | AT | Awareness and Training | 3 | | 3 | AU | Audit and Accountability | 9 | | 4 | CM | Configuration Management | 9 | | 5 | IA | Identification and Authentication | 11 | | 6 | IR | Incident Response | 3 | | 7 | MA | Maintenance | 6 | | 8 | MP | Media Protection | 9 | | 9 | PS | Personnel Security | 2 | | 10 | PE | Physical Protection | 6 | | 11 | **RA** | **Risk Assessment** | 3 | | 12 | CA | Security Assessment | 4 | | 13 | SC | System and Communications Protection | 16 | | 14 | SI | System and Information Integrity | 7 | | | | **TOTAL** | **110** |
**Numbering scheme:** `Chapter.Family.Requirement` (e.g., 3.1.1 = Chapter 3, AC family, Requirement 1). Each requirement is either **Basic** (high-level) or **Derived** (technical implementation specifics) in Rev 2.
---
Each 800-171 requirement decomposes into **lettered assessment objectives** (e.g., 3.1.1[a]–[f]). All objectives within a practice must be satisfied for the practice to be **Met** in a C3PAO assessment.
| Family | Controls | Assessment Objectives | |---|---|---| | 3.1 Access Control | 22 | **70** | | 3.2 Awareness & Training | 3 | 9 | | 3.3 Audit & Accountability | 9 | 29 | | 3.4 Configuration Ma
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.