cmmc-expert

Guide DoD contractors through CMMC v2.0 readiness with NIST 800-171 mapping.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill cmmc-expert-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cmmc-expert
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/frameworks/cmmc/skills/cmmc-expert
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill cmmc-expert-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

DoD contractors often struggle to align with CMMC v2.0 requirements and prepare for formal assessments. This skill provides deep domain knowledge, mappings to NIST 800-171, and practical guidance to plan, evidence, and close gaps efficiently.

Core Features & Use Cases

  • Guidance across all 14 CMMC domains with emphasis on Level 2/3 alignment and C3PAO preparation.
  • NIST 800-171 mapping, SSP/POA&M guidance, and assessment planning workflows for defense contractors.
  • Use Case: A contractor assesses current controls, identifies gaps, and creates a remediation plan with evidence artifacts to support a CMMC readiness review.

Quick Start

Prepare a CMMC v2.0 assessment plan for a DoD contractor, including scoping and evidence collection.

Frequently Asked Questions about cmmc-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a CMMC v2.0 assessment as a DoD contractor?

To prepare for a CMMC v2.0 assessment, you need to evaluate current controls across all 14 domains, map them to NIST 800-171, and generate a remediation plan with evidence artifacts for C3PAO readiness.

What is the process for mapping NIST 800-171 controls to CMMC Level 2?

Mapping NIST 800-171 controls to CMMC Level 2 involves aligning your existing security practices with the 14 domains, identifying gaps, and documenting them in your POA&M for formal assessment preparation.

How do I create a POA&M for CMMC gap analysis?

Creating a POA&M for CMMC gap analysis requires identifying deficiencies against NIST 800-171 requirements, documenting remediation milestones, and planning evidence collection to support your CMMC readiness review.

Can I use this for CMMC Level 1 to Level 3 certification readiness?

Yes, CMMC readiness guidance applies to defense contractors seeking Level 1 through Level 3 certifications, providing domain-specific alignment and C3PAO preparation workflows across the required security frameworks.

What should be included in CMMC assessment planning and evidence collection?

CMMC assessment planning must include scoping your environment, mapping controls to NIST 800-171, and structuring evidence artifact collection to validate compliance across all 14 CMMC domains.

Why do DoD contractors need to align with CMMC v2.0 processes?

DoD contractors must align with CMMC v2.0 processes to qualify for defense contracts, requiring structured assessment planning and NIST 800-171 control mapping to pass formal C3PAO evaluations.