Agent skill

Achieving Cmmc Level 2 Compliance

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score…

Apache-2.0Auto-check passedSecurity

Install Achieving Cmmc Level 2 Compliance

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill achieving-cmmc-level-2-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills achieving-cmmc-level-2-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/achieving-cmmc-level-2-compliance .claude/skills/achieving-cmmc-level-2-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
achieving-cmmc-level-2-compliance
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
980 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score…

  • Works in 7 steps: Determine applicability and CUI categories → Scope the environment → Implement the 110 requirements (NIST SP… → …
  • An organization handles Controlled Unclassified Information (CUI) under a DoD contract
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Achieving Cmmc Level 2 Compliance is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • An organization handles Controlled Unclassified Information (CUI) under a DoD contract
  • A contract carries DFARS clause 252.204-7012/7019/7020/7021
  • Responding to a CMMC assessment
  • Improving an SPRS score

Example prompts

  • “/achieving-cmmc-level-2-compliance”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Determine applicability and CUI categories
  2. Scope the environment
  3. Implement the 110 requirements (NIST SP 800-171 Rev 2)
  4. Score with the DoD Assessment Methodology (SPRS)
  5. Build a compliant POA&M
  6. Assess (self or C3PAO)
  7. Maintain certification

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Achieving Cmmc Level 2 Compliance loads about 2.2k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 235 tokens; SKILL.md has 980 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~235
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 980 words, ~2,157 tokens.

Download SKILL.mdSave it as .claude/skills/achieving-cmmc-level-2-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
achieving-cmmc-level-2-compliance
description
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
domain
cybersecurity
subdomain
compliance-governance
tags
cmmc, nist-800-171, cui, sprs, dfars, c3pao, poam, compliance, governance, defense-industrial-base
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
GV.OC-03, GV.SC-01, ID.AM-08, ID.RA-05, PR.AA-01, PR.DS-01
mitre_attack
T1078, T1190, T1041, T1048, T1567

Achieving CMMC Level 2 Compliance

When to Use

  • When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.
  • When a contract includes DFARS 252.204-7012 (safeguarding/incident reporting), -7019/-7020 (NIST 800-171 self-assessment + SPRS), or the new -7021 (CMMC requirement).
  • When preparing for a C3PAO third-party assessment or a DoD-led assessment.
  • When you must compute, post, or improve an SPRS score based on the NIST SP 800-171 DoD Assessment Methodology.
  • When authoring or remediating a System Security Plan (SSP) and POA&M for the 110 requirements.
  • When scoping which assets fall inside the CUI/FCI boundary (CUI assets, security-protection assets, contractor risk-managed assets, out-of-scope).

Prerequisites

  • Knowledge of which contracts carry CUI and the CUI categories involved (check the contract and the DoD CUI Registry).
  • An asset inventory and network diagram so you can define the CMMC assessment scope before assessing controls.
  • The NIST SP 800-171 Rev 2 requirements and the DoD Assessment Methodology scoring weights.
  • A documented SSP (its absence is itself a failed requirement — 3.12.4).
  • Identification of any External Service Providers (ESPs) / cloud services touching CUI, and whether they meet FedRAMP Moderate (or equivalency).

Workflow

1. Determine applicability and CUI categories

Confirm the contract requires CMMC Level 2 (CUI present, not just FCI). FCI-only contracts are Level 1 (the 15 FAR 52.204-21 requirements). Identify CUI categories from the contract and the DoD CUI Registry.

2. Scope the environment

Classify every asset into one of the CMMC scoping categories:

  • CUI Assets — process/store/transmit CUI (in scope, assessed against all applicable controls).
  • Security Protection Assets — provide security to the CUI environment (in scope).
  • Contractor Risk Managed Assets — could but are not intended to handle CUI; managed by policy.
  • Specialized Assets (IoT/OT, GFE, test equipment) — documented, limited assessment.
  • Out-of-Scope — physically/logically isolated from CUI.

Minimize scope deliberately — a smaller, well-segmented CUI enclave is far cheaper to certify than a flat network.

3. Implement the 110 requirements (NIST SP 800-171 Rev 2)

Work the 14 families (3.1–3.14). For each requirement, implement, then write the how in the SSP. High-leverage early wins: MFA (3.5.3), FIPS-validated cryptography (3.13.11), audit logging (3.3.x), access control + least privilege (3.1.x), and incident response (3.6.x).

4. Score with the DoD Assessment Methodology (SPRS)

Start at 110 and subtract the weighted value (1, 3, or 5 points) of each unmet requirement; partial credit applies to a small number of controls (e.g., MFA, FIPS crypto). The result is the SPRS score (maximum 110; the methodology floor is −203). Post the score, the SSP date, and the assessment scope to SPRS (or eMASS for higher assessments).

5. Build a compliant POA&M

Document every unmet requirement with owner, remediation, and milestone. Constraints under the CMMC rule: a Conditional status requires a score of at least 80% (≥ 88 of 110), only POA&M-eligible requirements may be deferred (the highest-weighted security requirements must be fully met — verify eligibility against 32 CFR Part 170), and all POA&M items must be closed within 180 days to convert Conditional → Final.

6. Assess (self or C3PAO)
  • Level 1 and a subset of Level 2 = annual self-assessment with an affirmation in SPRS.
  • Level 2 (most CUI contracts) = triennial C3PAO certification assessment.
  • Level 3 = DoD (DIBCAC) assessment on top of Level 2, adding SP 800-172 enhanced requirements. Assessors evaluate each objective as MET / NOT MET / N/A with evidence (examine/interview/test). A senior official files the annual affirmation of continued compliance.
7. Maintain certification

Certification is valid three years with annual affirmations. Maintain the SSP, re-score on change, keep evidence current, and feed significant changes back into the assessment.

Show full SKILL.md (392 more words)Show less

Key Concepts

ConceptDefinition
FCIFederal Contract Information — Level 1 protects it (FAR 52.204-21).
CUIControlled Unclassified Information — Level 2 protects it (NIST 800-171).
110 requirementsThe SP 800-171 Rev 2 security requirements across 14 families.
SPRSSupplier Performance Risk System — where the 800-171 score is posted.
DoD Assessment MethodologyThe 1/3/5-point weighting used to compute the score from 110.
C3PAOCMMC Third-Party Assessment Organization — performs Level 2 certification.
POA&MPlan of Action & Milestones — limited, must close in 180 days for Final status.
Conditional vs FinalConditional = open POA&M (score ≥ 80%); Final = all controls met.
ESPExternal Service Provider — must meet FedRAMP Moderate / equivalency for CUI.
Scoping categoriesCUI / Security Protection / Contractor Risk Managed / Specialized / Out-of-Scope.

Tools & Systems

  • NIST SP 800-171 Rev 2 — the 110 requirements (and 800-171A for assessment objectives).
  • DoD NIST SP 800-171 Assessment Methodology — the scoring weights.
  • 32 CFR Part 170 (CMMC Program rule) and 48 CFR / DFARS 252.204-7021 (acquisition rule).
  • SPRS — score posting; SAM.gov for registration.
  • SP 800-172 / 800-172A — enhanced requirements for Level 3.
  • GRC / compliance tooling — to manage the SSP, POA&M, and evidence (e.g., Xacta, RegScale, FutureFeed-style trackers).

Common Scenarios

  • Prime flows CUI to a sub. The sub needs its own Level 2 scope, SSP, SPRS score, and (most likely) C3PAO certification.
  • Score is below 88. Prioritize the highest-weighted unmet requirements (5-point, then 3-point) to clear the conditional threshold and shrink the POA&M.
  • Cloud holds CUI. Confirm the service is FedRAMP Moderate authorized or meets equivalency; document the responsibility split.
  • Flat network. Re-scope into a segmented CUI enclave to cut the assessment surface before spending on controls.
  • Annual affirmation due. A senior official affirms continued compliance in SPRS; let it lapse and you risk contract eligibility.

Output Format

Produce a CMMC Level 2 Readiness Report using assets/template.md, containing:

  1. Applicability & CUI categories — why Level 2 applies.
  2. Scope — assets by scoping category and the CUI boundary diagram reference.
  3. Control status by family — met / not met / N/A across the 14 families.
  4. SPRS score — computed score, deductions, and the gap to 110 and to the 88 threshold.
  5. POA&M — unmet requirements, eligibility check, owners, 180-day milestones.
  6. Assessment path — self vs C3PAO, target date, affirmation owner.
  7. Remediation roadmap — sequenced by point value and effort.

Use scripts/process.py to compute the SPRS score from a control-status JSON, flag POA&M-eligibility concerns, and report the gap to the conditional-certification threshold.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/achieving-cmmc-level-2-compliance of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Achieving Cmmc Level 2 Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Achieving Cmmc Level 2 Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Achieving Cmmc Level 2 Compliance this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4kAutomated safety check: PassMIT
OmniRoute Audit and Policy CLIdiegosouzapw/OmniRoute75k—~733Automated safety check: PassMIT
Google Cloud Waf Securitygoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Exa Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
Cis ControlsHack23/cia239—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • OmniRoute Audit and Policy CLI

    diegosouzapw/OmniRoute

    Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.

    75k GitHub stars~733 tokensUpdated today
    SecurityAuto-check passed
  • Official

    Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Exa Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Threat-model Exa credentials, query intent, retrieved web content, generated output, and retained operational evidence as separate trust boundaries.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cis Controls

    Hack23/cia

    Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform

    239 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform

    239 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Achieving Cmmc Level 2 Compliance

What does Achieving Cmmc Level 2 Compliance do?

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score…. Achieving Cmmc Level 2 Compliance is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment.

When should I use Achieving Cmmc Level 2 Compliance?

Achieving Cmmc Level 2 Compliance fits situations like: an organization handles Controlled Unclassified Information (CUI) under a DoD contract; A contract carries DFARS clause 252.204-7012/7019/7020/7021; responding to a CMMC assessment; improving an SPRS score.

How do I install Achieving Cmmc Level 2 Compliance in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill achieving-cmmc-level-2-compliance -a claude-code`. Or copy the skill folder (skills/achieving-cmmc-level-2-compliance in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/achieving-cmmc-level-2-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Achieving Cmmc Level 2 Compliance in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill achieving-cmmc-level-2-compliance -a codex`. Or copy the skill folder (skills/achieving-cmmc-level-2-compliance in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/achieving-cmmc-level-2-compliance in your project. Codex loads it when a task matches its description.

Can I use Achieving Cmmc Level 2 Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill achieving-cmmc-level-2-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/achieving-cmmc-level-2-compliance, .gemini/skills/achieving-cmmc-level-2-compliance, .github/skills/achieving-cmmc-level-2-compliance and .opencode/skills/achieving-cmmc-level-2-compliance in your project.

What does Achieving Cmmc Level 2 Compliance need to run?

Going by SKILL.md and its folder, Achieving Cmmc Level 2 Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Achieving Cmmc Level 2 Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Achieving Cmmc Level 2 Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Achieving Cmmc Level 2 Compliance use?

Achieving Cmmc Level 2 Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Achieving Cmmc Level 2 Compliance use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Achieving Cmmc Level 2 Compliance?

Skills that share tags, products or a category with Achieving Cmmc Level 2 Compliance: Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), OmniRoute Audit and Policy CLI (diegosouzapw/OmniRoute, 75k stars), Google Cloud Waf Security (google/skills, 21k stars) and Exa Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Achieving Cmmc Level 2 Compliance?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.