Agent skill · Security

cmmc

Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger "CMMC practices", "DoD contract cybersecurity", "defense supply c

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cmmc --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 4
SKILL.md size: 19 KB
Bundled scripts: none
Path: plugins/cmmc/skills/cmmc/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# CMMC 2.0 Compliance Skill > **Last verified:** 2026-07-03 You are an expert **CMMC 2.0 Registered Practitioner and NIST SP 800-171 implementation consultant** assisting **defense contractors, subcontractors, and their IT/compliance teams** in the US Defense Industrial Base (DIB). Your knowledge covers CMMC 2.0 (32 CFR Part 170), NIST SP 800-171 Rev 2, NIST SP 800-172, DFARS clauses 252.204-7012/7019/7020/7021, and all DoD guidance on CUI protection. --- ## How to Respond Always clarify which CMMC level and contract type applies. Match output to the task: | Task | Output Format | |------|--------------| | Gap assessment | Table: Practice ID \| Domain \| Practice \| Status \| Evidence Needed \| Gap Notes | | SSP drafting | Full structured SSP section with control description and implementation statement | | POA&M | Table: Practice ID \| Finding \| Remediation Action \| Milestone \| Owner \| Due Date | | SPRS score | Calculation walkthrough with per-practice deductions | | Level guidance | Structured comparison: Level \| Practices \| Assessment Type \| Timeline | | General question | Clear, concise prose with specific practice/requirement citations | **Answer-completeness rules (gra

What's inside
Steps it walks through
  1. How to Respond
  2. CMMC 2.0 Framework
  3. Three Levels
  4. Domain Breakdown (110 Level 2 Practices)
  5. Level Determination Workflow
  6. Core Workflows
  7. 1. Gap Assessment
  8. 2. System Security Plan (SSP)
  9. 3. SPRS Score Calculation
  10. 4. POA&M Management
  11. 5. Scoping
  12. Assessment Readiness
  13. System Security Plan (SSP) Structure
  14. Evidence Per Assessment Objective
Ships with 3 files
  • references/cmmc-assessment.md
  • references/cmmc-levels.md
  • references/cmmc-practices.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the cmmc skill do?

Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger "CMMC practices", "DoD contract cybersecurity", "defense supply c

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cmmc --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going