What problem does it solve? Federal contractors handling Controlled Unclassified Information (CUI) must comply with all 110 NIST SP 800-171 security requirements under DFARS 252.204-7012, but navigating the 14 control families, calculating SPRS scores, and building POA&Ms is complex and error-prone without structured guidance. ## Core Features & Use Cases - Control Family Navigation: Covers all 14 families and 110 controls with critical-control callouts, from Access Control (3.1.x) through System and Information Integrity (3.14.x). - SPRS Scoring & Self-Assessment: Walks through the six-step self-assessment methodology, from defining the CUI boundary and writing the SSP to gap analysis and SPRS score submission. - POA&M and Remediation Guidance: Provides a POA&M template plus remediation patterns for common deficiencies like missing MFA, absent SSPs, and unencrypted CUI at rest. - Use Case: A defense subcontractor preparing for a CMMC Level 2 assessment uses this Skill to identify NOT MET controls, calculate their current SPRS score, and build a milestone-driven POA&M before their C3PAO audit. ## Quick Start Ask the assistant to assess your organization's compliance with NIST 800-171 and identify gaps in your current controls.