What problem does it solve? Defense contractors struggle to determine which CMMC 2.0 level applies to their contracts, how to identify and handle CUI correctly, and when cybersecurity incidents must be reported to the DoD under DFARS clauses. ## Core Features & Use Cases - CMMC Level Determination: Walks through a step-by-step decision process to identify whether Level 1, 2, or 3 applies based on FCI and CUI presence in contracts. - CUI Identification & Handling: Explains CUI categories, marking requirements, storage rules, and enclave scoping strategies aligned with NIST SP 800-171. - Incident Disclosure Guidance: Provides a decision tree for the 72-hour DFARS 252.204-7012 reporting requirement, including what triggers reporting and common misconceptions. - Use Case: A subcontractor receives a DoD contract containing DFARS 252.204-7012 and needs to know their SPRS submission obligations, required CMMC level, and how to respond if they discover malware on a system storing technical drawings. ## Quick Start Ask the assistant to determine which CMMC level applies to your DoD contract and what your SPRS and incident reporting obligations are.