What problem does it solve? Assessing whether a firewall estate supports CMMC Level 2 or NIST SP 800-171 is error-prone: teams overclaim that an NGFW is "compliant", mix Rev. 2 and Rev. 3 requirement IDs, and lack structured evidence mapping for CUI boundary protection, remote access, and audit logging. ## Core Features & Use Cases - Control Mapping: Maps NGFW capabilities (segmentation, VPN, IDS/IPS, logging) to specific NIST SP 800-171 requirement IDs such as 3.1.1, 3.3.1, and 3.13.1 with evidence expectations. - Assessment Workflow: Provides a nine-step workflow covering CUI scoping, firewall-to-requirement matrices, rulebase review, evidence markers, and configuration management validation. - Evidence Markers: Defines a CMMC:/NIST: tagging pattern for firewall policies, NAT rules, zones, and VPNs so exports carry searchable audit references. - Use Case: A defense contractor preparing for a C3PAO assessment uses this Skill to review SRX firewall policies protecting a CUI enclave, producing a findings matrix with requirement mappings, gaps, and POA&M-ready remediation items. ## Quick Start Use the cmmc-nist-800-171-ngfw-compliance skill to assess this firewall configuration against CMMC Level 2 boundary protection requirements and list the gaps with evidence references.