cmmc-nist-800-171-ngfw-compliance

Maps firewall controls and evidence to CMMC Level 2 and NIST SP 800-171 requirements.

9|Updated Mar 7, 2026
One-click install
npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill cmmc-nist-800-171-ngfw-compliance-fastrevmd-lab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cmmc-nist-800-171-ngfw-compliance
Source: https://github.com/fastrevmd-lab/fwskillsshare/tree/main/skills/cmmc-nist-800-171-ngfw-compliance
Command: npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill cmmc-nist-800-171-ngfw-compliance-fastrevmd-lab

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Assessing whether a firewall estate supports CMMC Level 2 or NIST SP 800-171 is error-prone: teams overclaim that an NGFW is "compliant", mix Rev. 2 and Rev. 3 requirement IDs, and lack structured evidence mapping for CUI boundary protection, remote access, and audit logging. ## Core Features & Use Cases - Control Mapping: Maps NGFW capabilities (segmentation, VPN, IDS/IPS, logging) to specific NIST SP 800-171 requirement IDs such as 3.1.1, 3.3.1, and 3.13.1 with evidence expectations. - Assessment Workflow: Provides a nine-step workflow covering CUI scoping, firewall-to-requirement matrices, rulebase review, evidence markers, and configuration management validation. - Evidence Markers: Defines a CMMC:/NIST: tagging pattern for firewall policies, NAT rules, zones, and VPNs so exports carry searchable audit references. - Use Case: A defense contractor preparing for a C3PAO assessment uses this Skill to review SRX firewall policies protecting a CUI enclave, producing a findings matrix with requirement mappings, gaps, and POA&M-ready remediation items. ## Quick Start Use the cmmc-nist-800-171-ngfw-compliance skill to assess this firewall configuration against CMMC Level 2 boundary protection requirements and list the gaps with evidence references.

Frequently Asked Questions about cmmc-nist-800-171-ngfw-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess a firewall for CMMC Level 2 compliance?

Assess a firewall for CMMC Level 2 by first establishing CUI scope and data flows, then mapping firewall controls to NIST SP 800-171 Rev. 2 requirements such as 3.1.3, 3.13.1, and 3.3.1. The Skill provides a nine-step workflow covering rulebase review, remote access validation, logging, and evidence collection.

What NIST 800-171 requirements can a firewall support?

A firewall can support requirements including 3.1.1 authorized access, 3.1.3 CUI flow control, 3.1.12 remote access monitoring, 3.3.1 audit logging, 3.13.1 boundary protection, and 3.13.6 deny-by-default. The control-mapping reference lists each requirement with the firewall capabilities and evidence to request.

Is an NGFW CMMC compliant by itself?

No, an NGFW is not CMMC compliant by itself. CMMC and NIST SP 800-171 are assessed against the contractor environment and CUI protection program, including policies, procedures, evidence, and people. The firewall only supports compliance when configured, monitored, and tied to SSP and assessment evidence.

Does this skill use NIST 800-171 Rev. 2 or Rev. 3?

The Skill defaults to NIST SP 800-171 Rev. 2 requirement IDs for CMMC Level 2 work, since current DFARS assessments remain on Rev. 2. It notes that Rev. 3 exists and warns against mixing Rev. 2 and Rev. 3 IDs without labeling the assessment basis.

What evidence should I collect for a CMMC firewall assessment?

Collect the SSP boundary sections, CUI data-flow diagrams, network diagrams, firewall policy and NAT exports, change tickets, rule review records, MFA and VPN evidence, SIEM log samples, and POA&M entries. The assessment-workflow reference includes a complete evidence request checklist.

What are the limitations of firewall-based CMMC assessment?

Firewall review alone cannot determine compliance because segmentation labels, zones, and VLANs are not evidence without policy, diagrams, access tests, and monitoring. Final determination belongs to the authorized assessor, and the Skill treats its output as research guidance, not legal or C3PAO advice.