What problem does it solve? Defense contractors and subcontractors in the Defense Industrial Base must navigate CMMC 2.0, NIST SP 800-171, and DFARS cybersecurity requirements to win and keep DoD contracts. This Skill provides expert guidance on determining the required CMMC level, performing gap assessments, drafting System Security Plans, calculating SPRS scores, and managing POA&Ms without hiring a consultant for every question. ## Core Features & Use Cases - Level Determination & Gap Assessment: Identify whether Level 1, 2, or 3 applies based on DFARS clauses and FCI/CUI handling, then produce structured gap tables across all 110 NIST SP 800-171 practices. - SSP, POA&M & SPRS Support: Draft audit-ready SSP sections, build POA&M entries that respect the 180-day closeout and critical-practice rules, and walk through weighted SPRS score calculations (110 to -203). - Assessment Readiness & Flow-Down: Prepare for C3PAO or DIBCAC assessments with evidence checklists, and manage subcontractor flow-down obligations under DFARS 252.204-7021. - Use Case: A subcontractor discovers DFARS 252.204-7021 in a new contract and asks what CMMC level applies. The Skill classifies their data as CUI, determines Level 2 with C3PAO assessment, and produces a prioritized remediation roadmap with SPRS score impact. ## Quick Start Ask the assistant to determine which CMMC level applies to your contract and produce a gap assessment table for your current security controls.