cmmc

Guide CMMC 2.0 compliance with gap assessments and SSP development.

811|169|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cmmc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cmmc
Source: https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/cmmc/skills/cmmc
Command: npx skills add https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cmmc

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This Skill provides comprehensive guidance and assistance for attaining and maintaining NIST SP 800-171 and CMMC compliance standards in the US defense supply chain.

Core Features & Use Cases

  • Gap Assessments: Evaluate existing controls against CMMC requirements and generate detailed practice status reports.
  • System Security Planning: Assist in developing and reviewing SSP documentation aligned with NIST frameworks.
  • SPRS Score Management: Help calculate, review, and improve SPRS self-assessment scores.
  • Scope Definition & Control: Aid in identifying CUI boundaries and implementing appropriate safeguarding measures.
  • Use Case: A defense contractor working to achieve Level 2 compliance can utilize this Skill to prepare documentation, assess gaps, and develop a remediation plan.

Quick Start

Use the cmmc skill to review your current security controls and generate a compliance report for your environment.

Frequently Asked Questions about cmmc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess my current controls against NIST SP 800-171 requirements for CMMC compliance?

To prepare documentation for a CMMC Level 2 assessment, develop a System Security Plan (SSP) aligned with NIST frameworks. This document details your security boundaries, control implementations, and safeguarding measures for CUI.

What is the best way to calculate and improve my SPRS self-assessment score?

Calculating and improving a SPRS self-assessment score involves reviewing your NIST SP 800-171 control implementation. The process requires identifying gaps, applying remediation strategies, and updating your score submission based on resolved deficiencies.

How do I identify CUI boundaries and implement appropriate safeguarding measures for defense contracts?

Identifying CUI boundaries requires scoping your environment to define where Controlled Unclassified Information resides. You then implement appropriate safeguarding measures aligned with NIST SP 800-171 to protect those specific assets.

When do defense contractors need to implement NIST SP 800-172 standards?

Yes, you can review existing System Security Plan (SSP) documentation to ensure alignment with current NIST SP 800-171 frameworks. This review process validates control implementations, identifies documentation gaps, and supports overall audit readiness.