cmmc-cui

Guides CMMC 2.0 level determination, CUI handling, and DoD incident reporting compliance.

1|Updated Aug 10, 2026
One-click install
npx skills add https://github.com/TheViziusGroup/vibe-engineering-skills --skill cmmc-cui-theviziusgroup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cmmc-cui
Source: https://github.com/TheViziusGroup/vibe-engineering-skills/tree/main/plugins/compliance-frameworks/skills/cmmc-cui
Command: npx skills add https://github.com/TheViziusGroup/vibe-engineering-skills --skill cmmc-cui-theviziusgroup

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Defense contractors struggle to determine which CMMC 2.0 level applies to their contracts, how to identify and handle CUI correctly, and when cybersecurity incidents must be reported to the DoD under DFARS clauses. ## Core Features & Use Cases - CMMC Level Determination: Walks through a step-by-step decision process to identify whether Level 1, 2, or 3 applies based on FCI and CUI presence in contracts. - CUI Identification & Handling: Explains CUI categories, marking requirements, storage rules, and enclave scoping strategies aligned with NIST SP 800-171. - Incident Disclosure Guidance: Provides a decision tree for the 72-hour DFARS 252.204-7012 reporting requirement, including what triggers reporting and common misconceptions. - Use Case: A subcontractor receives a DoD contract containing DFARS 252.204-7012 and needs to know their SPRS submission obligations, required CMMC level, and how to respond if they discover malware on a system storing technical drawings. ## Quick Start Ask the assistant to determine which CMMC level applies to your DoD contract and what your SPRS and incident reporting obligations are.

Frequently Asked Questions about cmmc-cui

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which CMMC level my DoD contract requires?

CMMC level determination starts with checking whether your contract involves FCI (Level 1 minimum) or CUI (Level 2 minimum). Level 3 applies only when the DoD Program Office designates the acquisition as a critical program, which will be stated in the contract.

What triggers the 72-hour DoD incident reporting requirement?

DFARS 252.204-7012 requires reporting within 72 hours of discovering any incident affecting a system containing Covered Defense Information, including suspected compromise, malware, unauthorized access, or data exfiltration. Reports go to DC3 via DIBNet, and system images must be preserved for 90 days.

What is the difference between SPRS score and CMMC certification?

An SPRS score is a self-assessment result against NIST 800-171 submitted before contract award, while CMMC certification is third-party validation by a C3PAO required for designated contracts. Many contracts currently require SPRS submission plus a conditional CMMC compliance plan.

Does CMMC apply to subcontractors handling CUI?

Yes, DFARS clauses must be flowed down to subcontractors at all tiers that handle Covered Defense Information. Primes should add clauses 7012, 7019, 7020, and 7021 to subcontracts and obtain SPRS scores from subs, without imposing higher levels than the sub's scope requires.

When is a security event not reportable to the DoD?

Blocked port scans, unclicked phishing emails, and failed login attempts without account compromise do not require DFARS reporting. However, when compromise cannot be ruled out, reporting is the safer choice since False Claims Act risk applies to knowing failure to report.