achieving-cmmc-level-2-compliance skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- 1. Determine applicability and CUI categories
- 2. Scope the environment
- 3. Implement the 110 requirements (NIST SP 800-171 Rev 2)
- 4. Score with the DoD Assessment Methodology (SPRS)
- 5. Build a compliant POA&M
- 6. Assess (self or C3PAO)
- 7. Maintain certification
- Key Concepts
- Tools & Systems
- Common Scenarios
- Output Format
- Other files in this skill
- assets/template.md (verbatim)
- 1. Applicability & CUI Categories
- 2. Scope (CMMC Level 2 Scoping Guide)
- 3. Control Status by Family (NIST SP 800-171 Rev 2)
- 4. SPRS Score
- 5. POA&M (eligibility-checked)
- 6. Assessment Path
- 7. Remediation Roadmap (sequenced by point value, then effort)
- references/standards.md (verbatim)
- Governing rules
- Phased rollout (per the acquisition rule)
- The three CMMC levels
- NIST SP 800-171 Rev 2 — the 14 families (110 requirements)
- DoD Assessment Methodology — SPRS scoring
- POA&M rules under the CMMC rule (32 CFR Part 170)
- Scoping categories (CMMC Level 2 Scoping Guide)
- External Service Providers / cloud
- NIST CSF 2.0 alignment
What it does. Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/achieving-cmmc-level-2-compliance/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill achieving-cmmc-level-2-compliance, or copy the skill folder into~/.claude/skills/achieving-cmmc-level-2-compliance/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/achieving-cmmc-level-2-compliance/SKILL.md
SKILL.md (verbatim)
name: achieving-cmmc-level-2-compliance
description: >-
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI
and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14
families, compute the SPRS score with the DoD Assessment Methodology, manage a
compliant POA&M, and ready the organization for a C3PAO assessment. Use when an
organization handles Controlled Unclassified Information (CUI) under a DoD contract,
when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for
or responding to a CMMC assessment, when computing or improving an SPRS score, when
building a System Security Plan or POA&M for 800-171, or when scoping which systems
are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2,
CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment
Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
domain: cybersecurity
subdomain: compliance-governance
tags:
- cmmc
- nist-800-171
- cui
- sprs
- dfars
- c3pao
- poam
- compliance
- governance
- defense-industrial-base
version: "1.0"
author: andrewibrah
license: Apache-2.0
nist_csf:
- GV.OC-03
- GV.SC-01
- ID.AM-08
- ID.RA-05
- PR.AA-01
- PR.DS-01
mitre_attack:
- T1078
- T1190
- T1041
- T1048
- T1567
Achieving CMMC Level 2 Compliance
When to Use
- When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.
- When a contract includes DFARS 252.204-7012 (safeguarding/incident reporting), -7019/-7020 (NIST 800-171 self-assessment + SPRS), or the new -7021 (CMMC requirement).
- When preparing for a C3PAO third-party assessment or a DoD-led assessment.
- When you must compute, post, or improve an SPRS score based on the NIST SP 800-171 DoD Assessment Methodology.
- When authoring or remediating a System Security Plan (SSP) and POA&M for the 110 requirements.
- When scoping which assets fall inside the CUI/FCI boundary (CUI assets, security-protection assets, contractor risk-managed assets, out-of-scope).
Prerequisites
- Knowledge of which contracts carry CUI and the CUI categories involved (check the contract and the DoD CUI Registry).
- An asset inventory and network diagram so you can define the CMMC assessment scope before assessing controls.
- The NIST SP 800-171 Rev 2 requirements and the DoD Assessment Methodology scoring weights.
- A documented SSP (its absence is itself a failed requirement — 3.12.4).
- Identification of any External Service Providers (ESPs) / cloud services touching CUI, and whether they meet FedRAMP Moderate (or equivalency).
Workflow
1. Determine applicability and CUI categories
Confirm the contract requires CMMC Level 2 (CUI present, not just FCI). FCI-only contracts are Level 1 (the 15 FAR 52.204-21 requirements). Identify CUI categories from the contract and the DoD CUI Registry.
2. Scope the environment
Classify every asset into one of the CMMC scoping categories:
- CUI Assets — process/store/transmit CUI (in scope, assessed against all applicable controls).
- Security Protection Assets — provide security to the CUI environment (in scope).
- Contractor Risk Managed Assets — could but are not intended to handle CUI; managed by policy.
- Specialized Assets (IoT/OT, GFE, test equipment) — documented, limited assessment.
- Out-of-Scope — physically/logically isolated from CUI.
Minimize scope deliberately — a smaller, well-segmented CUI enclave is far cheaper to certify than a flat network.
3. Implement the 110 requirements (NIST SP 800-171 Rev 2)
Work the 14 families (3.1–3.14). For each requirement, implement, then write the how in the SSP. High-leverage early wins: MFA (3.5.3), FIPS-validated cryptography (3.13.11), audit logging (3.3.x), access control + least privilege (3.1.x), and incident response (3.6.x).
4. Score with the DoD Assessment Methodology (SPRS)
Start at 110 and subtract the weighted value (1, 3, or 5 points) of each unmet requirement; partial credit applies to a small number of controls (e.g., MFA, FIPS crypto). The result is the SPRS score (maximum 110; the methodology floor is −203). Post the score, the SSP date, and the assessment scope to SPRS (or eMASS for higher assessments).
5. Build a compliant POA&M
Document every unmet requirement with owner, remediation, and milestone. Constraints under the CMMC rule: a Conditional status requires a score of at least 80% (≥ 88 of 110), only POA&M-eligible requirements may be deferred (the highest-weighted security requirements must be fully met — verify eligibility against 32 CFR Part 170), and all POA&M items must be closed within 180 days to convert Conditional → Final.
6. Assess (self or C3PAO)
- Level 1 and a subset of Level 2 = annual self-assessment with an affirmation in SPRS.
- Level 2 (most CUI contracts) = triennial C3PAO certification assessment.
- Level 3 = DoD (DIBCAC) assessment on top of Level 2, adding SP 800-172 enhanced requirements. Assessors evaluate each objective as MET / NOT MET / N/A with evidence (examine/interview/test). A senior official files the annual affirmation of continued compliance.
7. Maintain certification
Certification is valid three years with annual affirmations. Maintain the SSP, re-score on change, keep evidence current, and feed significant changes back into the assessment.
Key Concepts
| Concept | Definition |
|---|---|
| FCI | Federal Contract Information — Level 1 protects it (FAR 52.204-21). |
| CUI | Controlled Unclassified Information — Level 2 protects it (NIST 800-171). |
| 110 requirements | The SP 800-171 Rev 2 security requirements across 14 families. |
| SPRS | Supplier Performance Risk System — where the 800-171 score is posted. |
| DoD Assessment Methodology | The 1/3/5-point weighting used to compute the score from 110. |
| C3PAO | CMMC Third-Party Assessment Organization — performs Level 2 certification. |
| POA&M | Plan of Action & Milestones — limited, must close in 180 days for Final status. |
| Conditional vs Final | Conditional = open POA&M (score ≥ 80%); Final = all controls met. |
| ESP | External Service Provider — must meet FedRAMP Moderate / equivalency for CUI. |
| Scoping categories | CUI / Security Protection / Contractor Risk Managed / Specialized / Out-of-Scope. |
Tools & Systems
- NIST SP 800-171 Rev 2 — the 110 requirements (and 800-171A for assessment objectives).
- DoD NIST SP 800-171 Assessment Methodology — the scoring weights.
- 32 CFR Part 170 (CMMC Program rule) and 48 CFR / DFARS 252.204-7021 (acquisition rule).
- SPRS — score posting; SAM.gov for registration.
- SP 800-172 / 800-172A — enhanced requirements for Level 3.
- GRC / compliance tooling — to manage the SSP, POA&M, and evidence (e.g., Xacta, RegScale, FutureFeed-style trackers).
Common Scenarios
- Prime flows CUI to a sub. The sub needs its own Level 2 scope, SSP, SPRS score, and (most likely) C3PAO certification.
- Score is below 88. Prioritize the highest-weighted unmet requirements (5-point, then 3-point) to clear the conditional threshold and shrink the POA&M.
- Cloud holds CUI. Confirm the service is FedRAMP Moderate authorized or meets equivalency; document the responsibility split.
- Flat network. Re-scope into a segmented CUI enclave to cut the assessment surface before spending on controls.
- Annual affirmation due. A senior official affirms continued compliance in SPRS; let it lapse and you risk contract eligibility.
Output Format
Produce a CMMC Level 2 Readiness Report using assets/template.md, containing:
- Applicability & CUI categories — why Level 2 applies.
- Scope — assets by scoping category and the CUI boundary diagram reference.
- Control status by family — met / not met / N/A across the 14 families.
- SPRS score — computed score, deductions, and the gap to 110 and to the 88 threshold.
- POA&M — unmet requirements, eligibility check, owners, 180-day milestones.
- Assessment path — self vs C3PAO, target date, affirmation owner.
- Remediation roadmap — sequenced by point value and effort.
Use scripts/process.py to compute the SPRS score from a control-status JSON, flag POA&M-eligibility concerns, and report the gap to the conditional-certification threshold.
Other files in this skill
assets/template.md (verbatim)
CMMC Level 2 Readiness Report — Worked Example
Filled example for a small DIB manufacturer handling CUI on a segmented enclave. Replace bracketed content for your own organization.
1. Applicability & CUI Categories
- Contract drivers: Prime subcontract with DFARS 252.204-7012 and -7021; CUI present → CMMC Level 2 required.
- CUI categories (from contract + DoD CUI Registry): Controlled Technical Information (CTI), Export Controlled (EAR).
- Target assessment path: Triennial C3PAO certification (Phase 2 applies from Nov 10, 2026).
2. Scope (CMMC Level 2 Scoping Guide)
| Category | Examples in this environment |
|---|---|
| CUI Assets | Engineering workstations, CUI file share, the segmented "Enclave-1" VLAN |
| Security Protection Assets | EDR console, SIEM, firewall, IdP/MFA, jump host |
| Contractor Risk Managed | General corporate laptops (policy-blocked from CUI) |
| Specialized Assets | CNC machine controllers (documented, isolated) |
| Out-of-Scope | Guest Wi-Fi, marketing SaaS |
Boundary note: CUI is confined to Enclave-1 behind segmentation and MFA. Deliberately minimized to shrink the assessment surface. See network diagram CUI-boundary-v3.
3. Control Status by Family (NIST SP 800-171 Rev 2)
(summary; full per-requirement status lives in the SSP)
| Family | Met | Partial | Not Met | N/A |
|---|---|---|---|---|
| 3.1 Access Control | 22 | 0 | 0 | 0 |
| 3.3 Audit & Accountability | 8 | 0 | 1 | 0 |
| 3.5 Identification & Auth | 10 | 1 | 0 | 0 |
| 3.8 Media Protection | 8 | 0 | 1 | 0 |
| 3.13 System & Comms Protection | 15 | 0 | 1 | 0 |
| 3.14 System & Info Integrity | 6 | 0 | 1 | 0 |
| (others) | all met | — | — | — |
4. SPRS Score
(computed by scripts/process.py from the control-status JSON)
- Score: 97 / 110 (started at 110; deducted 13).
- Gap to perfect: 13 points across 4 not-met + 1 partial requirement.
- Conditional threshold (≥ 88): MET (margin 9) — eligible for Conditional status if the remaining items are POA&M-eligible.
- Posted to SPRS: score, SSP date, and assessment scope.
5. POA&M (eligibility-checked)
| ID | Requirement | Points | Eligibility | Remediation | Owner | Milestone (≤180d) |
|---|---|---|---|---|---|---|
| 3.3.1 | Audit log generation/coverage | 5 | Verify — high weight; confirm against 32 CFR 170 | Enable full audit policy + ship to SIEM | SecOps | 2026-07-30 |
| 3.13.11 | FIPS-validated cryptography | 3 | Verify eligibility | Replace non-validated module with FIPS 140-validated | Infra | 2026-08-15 |
| 3.5.3 | MFA (partial) | 3 | Partial-credit control | Extend MFA to remaining admin paths | IAM | 2026-07-20 |
| 3.8.9 | Backup CUI protection | 1 | Eligible | Encrypt + access-control backup store | Infra | 2026-08-31 |
| 3.14.1 | Flaw remediation | 1 | Eligible | Formalize patch SLA + tracking | IT | 2026-08-31 |
The two 3-point and one 5-point items must clear eligibility review; the highest-weighted security requirements generally cannot remain on a POA&M. All items close within 180 days to convert Conditional → Final.
6. Assessment Path
- Type: C3PAO certification assessment.
- Target window: Q4 2026, after POA&M closure of the high-weight items.
- Affirmation owner: [senior official] files the annual affirmation in SPRS.
7. Remediation Roadmap (sequenced by point value, then effort)
- 3.3.1 audit logging (5 pts) — biggest score lever and likely POA&M-ineligible → do first.
- 3.13.11 FIPS crypto (3 pts) and 3.5.3 MFA gap (3 pts) — close to remove eligibility risk.
- 3.8.9, 3.14.1 (1 pt each) — low-effort cleanups before the C3PAO date.
- Re-run the SPRS calculator after each closure; goal is 110 before assessment.
references/standards.md (verbatim)
CMMC Level 2 — Standards & Reference
Governing rules
| Rule | Citation | Status / effective date |
|---|---|---|
| CMMC Program rule | 32 CFR Part 170 | Effective December 16, 2024 |
| CMMC acquisition rule (DFARS) | 48 CFR; DFARS clause 252.204-7021 (and 204.7503) | Published Sept 10, 2025; effective November 10, 2025 |
| Safeguarding CUI / incident reporting | DFARS 252.204-7012 | In effect |
| NIST 800-171 self-assessment + SPRS posting | DFARS 252.204-7019 / -7020 | In effect |
Always confirm current status at the source — acquisition rules and phase dates have moved before. Authoritative: https://dodcio.defense.gov/CMMC/ and the eCFR for 32 CFR Part 170.
Phased rollout (per the acquisition rule)
| Phase | Begins | What applies |
|---|---|---|
| Phase 1 | Nov 10, 2025 | Level 1 and some Level 2 self-assessment required in solicitations |
| Phase 2 | Nov 10, 2026 | Level 2 C3PAO certification required for applicable contracts |
| Phase 3 | Nov 10, 2027 | Level 2 C3PAO + Level 3 DIBCAC assessment phased in |
| Phase 4 | Nov 10, 2028 | Full implementation across applicable DoD contracts |
The three CMMC levels
| Level | Protects | Requirements | Assessment |
|---|---|---|---|
| Level 1 | FCI | 15 requirements (FAR 52.204-21) | Annual self-assessment + affirmation |
| Level 2 | CUI | 110 requirements (NIST SP 800-171 Rev 2) | Self or triennial C3PAO certification |
| Level 3 | CUI (high priority) | 110 + selected SP 800-172 enhanced | DoD (DIBCAC) assessment |
Certification validity: 3 years, with annual affirmation by a senior official in SPRS.
NIST SP 800-171 Rev 2 — the 14 families (110 requirements)
| § | Family | # reqs |
|---|---|---|
| 3.1 | Access Control | 22 |
| 3.2 | Awareness and Training | 3 |
| 3.3 | Audit and Accountability | 9 |
| 3.4 | Configuration Management | 9 |
| 3.5 | Identification and Authentication | 11 |
| 3.6 | Incident Response | 3 |
| 3.7 | Maintenance | 6 |
| 3.8 | Media Protection | 9 |
| 3.9 | Personnel Security | 2 |
| 3.10 | Physical Protection | 6 |
| 3.11 | Risk Assessment | 3 |
| 3.12 | Security Assessment | 4 |
| 3.13 | System and Communications Protection | 16 |
| 3.14 | System and Information Integrity | 7 |
| Total | 110 |
(Assessment objectives for each requirement are in NIST SP 800-171A.)
DoD Assessment Methodology — SPRS scoring
- Start at 110. Subtract the weighted value of each NOT MET requirement.
- Weights: 1, 3, or 5 points. The most security-significant requirements are weighted 3 or 5.
- Partial credit applies to a small number of requirements (notably MFA at 3.5.3 and FIPS-validated cryptography at 3.13.11) where partial implementation reduces the deduction.
- Maximum score 110; the methodology floor is −203 (more is deducted than the 110 starting points because of the weighting).
- The complete per-requirement point assignment is published in the DoD NIST SP 800-171 Assessment Methodology — use that document for the authoritative weight of each control rather than estimating.
POA&M rules under the CMMC rule (32 CFR Part 170)
- A Conditional Level 2 status is allowed only if the assessment score is at least 80% (≥ 88 of 110).
- Only POA&M-eligible requirements may be deferred. The highest-weighted security requirements generally must be fully met and cannot sit on a POA&M — verify each item's eligibility against the rule.
- All POA&M items must be closed within 180 days; a closeout assessment then converts Conditional → Final.
Scoping categories (CMMC Level 2 Scoping Guide)
| Category | Treatment |
|---|---|
| CUI Assets | Process/store/transmit CUI — assessed against applicable requirements. |
| Security Protection Assets | Provide security to the CUI environment — in scope. |
| Contractor Risk Managed Assets | Capable of handling CUI but not intended to — managed by policy/config. |
| Specialized Assets | IoT/OT, GFE, test equipment — documented, limited assessment. |
| Out-of-Scope Assets | Isolated from CUI — not assessed. |
External Service Providers / cloud
- Cloud services that store/process/transmit CUI must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency.
- Document the customer/provider responsibility split (CRM) and inherited controls in the SSP.
NIST CSF 2.0 alignment
| CSF 2.0 ID | Relevance |
|---|---|
| GV.OC-03 | Legal/regulatory (DFARS/CMMC) requirements understood. |
| GV.SC-01 | Supply-chain risk management — flowdown to subs / ESPs. |
| ID.AM-08 | Assets managed across the lifecycle (scoping). |
| ID.RA-05 | Risk informs prioritization of unmet requirements. |
| PR.AA-01 | Identity and access (3.1 / 3.5 families). |
| PR.DS-01 | Data-at-rest protection (FIPS crypto, media protection). |
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.