cmmc

Guides CMMC 2.0 compliance assessments, SSP drafting, POA&M management, and SPRS scoring for defense contractors.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill cmmc-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cmmc
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/cmmc
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill cmmc-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Defense contractors and subcontractors in the Defense Industrial Base must navigate CMMC 2.0, NIST SP 800-171, and DFARS cybersecurity requirements to win and keep DoD contracts. This Skill provides expert guidance on determining the required CMMC level, performing gap assessments, drafting System Security Plans, calculating SPRS scores, and managing POA&Ms without hiring a consultant for every question. ## Core Features & Use Cases - Level Determination & Gap Assessment: Identify whether Level 1, 2, or 3 applies based on DFARS clauses and FCI/CUI handling, then produce structured gap tables across all 110 NIST SP 800-171 practices. - SSP, POA&M & SPRS Support: Draft audit-ready SSP sections, build POA&M entries that respect the 180-day closeout and critical-practice rules, and walk through weighted SPRS score calculations (110 to -203). - Assessment Readiness & Flow-Down: Prepare for C3PAO or DIBCAC assessments with evidence checklists, and manage subcontractor flow-down obligations under DFARS 252.204-7021. - Use Case: A subcontractor discovers DFARS 252.204-7021 in a new contract and asks what CMMC level applies. The Skill classifies their data as CUI, determines Level 2 with C3PAO assessment, and produces a prioritized remediation roadmap with SPRS score impact. ## Quick Start Ask the assistant to determine which CMMC level applies to your contract and produce a gap assessment table for your current security controls.

Frequently Asked Questions about cmmc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which CMMC level my contract requires?

Check the contract for DFARS clauses: 252.204-7021 means the level is stated in Section L or the PWS. If you handle only FCI, Level 1 applies; if you handle CUI, Level 2 applies, with Level 3 reserved for highest-priority DoD programs.

How is the SPRS score calculated for NIST SP 800-171?

The SPRS score starts at 110 and deducts 1, 3, or 5 points per NOT MET practice based on security impact, with a floor of -203. Partial implementation receives the full deduction, and a senior official must affirm the submitted score annually.

Can I get CMMC Level 2 certified with open POA&M items?

Yes, conditional certification is possible if the score is at least 88 and all open items are 1-point practices. Critical practices like MFA (IA.L2-3.5.3) and FIPS cryptography (SC.L2-3.13.11) can never be on a POA&M, and all items must close within 180 days.

What CMMC level do subcontractors need under DFARS flow-down rules?

DFARS 252.204-7021(c) requires primes to flow CMMC requirements to all tiers: FCI-only subcontractors need Level 1, while subcontractors handling CUI need Level 2. Primes must verify subcontractor status in SPRS before flowing CUI.

What evidence does a C3PAO expect during a Level 2 assessment?

Assessors expect documentary evidence (policies, SSP, training records with dates and approvals), technical evidence (configuration exports, vulnerability scans, MFA reports), and interviews with ISSOs, administrators, and executives. Documentation alone cannot substitute for interviews.

Does this guidance replace legal or accredited assessor advice?

No. The Skill provides general compliance information, not legal advice. Certification decisions should be verified against official sources like 32 CFR Part 170 and made with qualified counsel or an accredited C3PAO.