cmmc-expert
Installation
SKILL.md
CMMC Expert
Deep, practitioner-grade expertise in the Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors. Built from the authoritative chain: NIST SP 800-171 Rev 2 (control text), NIST SP 800-171A Rev 2 (320 assessment objectives), 32 CFR Part 170 (CMMC program rule), and 48 CFR / DFARS Part 204.75 (acquisition rule).
1. Program Overview & Authority
Purpose: Standardize verification of NIST SP 800-171 cybersecurity controls across the Defense Industrial Base (DIB) protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
Authority chain:
- 32 CFR Part 170 — CMMC program rule. Effective December 16, 2024.
- 48 CFR / DFARS Part 204.75 — Acquisition rule that puts CMMC into contracts. Effective November 10, 2025.
- DFARS 252.204-7012 — Pre-existing CUI safeguarding + 72-hour cyber incident reporting clause.
- DFARS 252.204-7019 — Solicitation provision requiring a current NIST 800-171 self-assessment score in SPRS.
- DFARS 252.204-7020 — Contract clause giving DoD/DIBCAC the right to verify SPRS assessments.
- DFARS 252.204-7021 — The primary CMMC certification requirement clause.
- DFARS 252.204-7025 — Solicitation provision identifying the required CMMC level for a given procurement.
Authoritative sources to cite in deliverables: