Skip to content
Back to search
100
MCP live MCP 2026-07-28 streamable-http

MacTech CMMC / NIST 800-171

com.mactechsolutionsllc.www/cmmc

NIST 800-171 controls and 800-171A objectives, crosswalks, exact SPRS scoring, POA&M generation.

Uptime
100.0%
2 direct probes · 30d
Response
712ms
last probe
Tools
13
callable
Resources
220
readable
Prompts
1
available

Tools · 13

lookup_control

Get one NIST SP 800-171 Rev 2 security requirement by number (e.g. "3.5.3"): the full requirement text, its control family, and its exact DoD Assessment Methodology (SPRS) point weight, including the …

list_controls

List NIST SP 800-171 Rev 2 requirements with their DoD Assessment Methodology (SPRS) weights, optionally filtered by control family name or by point weight (5, 3, or 1). Call this to enumerate the 110…

calculate_sprs_score

Compute an exact SPRS score per the DoD Assessment Methodology: start at 110 and subtract each unimplemented requirement's Annex A weight (floor −203). Pass the control numbers that are NOT implemente…

get_assessment_objectives

Get the official NIST SP 800-171A assessment objectives for one NIST SP 800-171 Rev 2 requirement - the exact "Determine if..." objectives a CMMC Level 2 assessor scores, plus the potential assessment…

crosswalk_control

Map a security control across frameworks: NIST SP 800-171 Rev 2 ↔ NIST SP 800-53 (FedRAMP Moderate) ↔ NIST CSF 2.0 ↔ SOC 2 Trust Services Criteria. Accepts an 800-171 number ("3.5.3"), an 800-53 id ("…

determine_cmmc_level

Determine which CMMC level (1, 2, or 3) applies to a defense contractor based on the data they handle and the clauses in their contracts, and - separately - which assessment type may actually be desig…

list_level1_practices

List all 17 CMMC Level 1 basic safeguarding practices with their FAR 52.204-21 clause citations - the complete requirement set for contractors handling Federal Contract Information (FCI) only. Call th…

generate_poam_entries

Turn a list of unimplemented NIST SP 800-171 controls into structured Plan of Action & Milestones (POA&M) entries - deficiency description, planned remediation, priority derived from the SPRS weight, …

check_contract_type_eligibility

Determine whether a contractor can legally be awarded a given contract type, based on the business systems that type requires. A cost-reimbursement contract may be awarded only if the accounting syste…

lookup_clause

Explain what a FAR or DFARS cybersecurity clause obliges a contractor to do: what triggers it, the concrete duties, the reporting deadlines, what it flows down to subcontractors, and which other claus…

scope_assessment

Work out which assets fall inside a CMMC assessment boundary, and what each category obliges. Returns the DoD asset categories (CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Spe…

lookup_rev3_requirement

Get one NIST SP 800-171 REVISION 3 requirement by its zero-padded number (e.g. "03.01.01"): the requirement statement, its organization-defined parameters, the 800-171A Rev 3 assessment objectives, an…

crosswalk_revisions

Explain how NIST SP 800-171 Rev 2 and Rev 3 differ, and what happened to a specific requirement between them. Call this when someone is implementing Rev 3 early, holds a Rev 3 citation and needs the R…

Resources · 220

3.1.1 - Access Control

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

cmmc://control/3.1.1
3.1.2 - Access Control

Limit system access to the types of transactions and functions that authorized users are permitted to execute.

cmmc://control/3.1.2
3.1.3 - Access Control

Control the flow of CUI in accordance with approved authorizations.

cmmc://control/3.1.3
3.1.4 - Access Control

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

cmmc://control/3.1.4
3.1.5 - Access Control

Employ the principle of least privilege, including for specific security functions and privileged accounts.

cmmc://control/3.1.5
3.1.6 - Access Control

Use non-privileged accounts or roles when accessing non-security functions.

cmmc://control/3.1.6
3.1.7 - Access Control

Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

cmmc://control/3.1.7
3.1.8 - Access Control

Limit unsuccessful logon attempts.

cmmc://control/3.1.8
3.1.9 - Access Control

Provide privacy and security notices consistent with applicable CUI rules.

cmmc://control/3.1.9
3.1.10 - Access Control

Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

cmmc://control/3.1.10
3.1.11 - Access Control

Terminate (automatically) a user session after a defined condition.

cmmc://control/3.1.11
3.1.12 - Access Control

Monitor and control remote access sessions.

cmmc://control/3.1.12
3.1.13 - Access Control

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

cmmc://control/3.1.13
3.1.14 - Access Control

Route remote access via managed access control points.

cmmc://control/3.1.14
3.1.15 - Access Control

Authorize remote execution of privileged commands and remote access to securityrelevant information.

cmmc://control/3.1.15
3.1.16 - Access Control

Authorize wireless access prior to allowing such connections.

cmmc://control/3.1.16
3.1.17 - Access Control

Protect wireless access using authentication and encryption.

cmmc://control/3.1.17
3.1.18 - Access Control

Control connection of mobile devices.

cmmc://control/3.1.18
3.1.19 - Access Control

Encrypt CUI on mobile devices and mobile computing platforms

cmmc://control/3.1.19
3.1.20 - Access Control

Verify and control/limit connections to and use of external systems.

cmmc://control/3.1.20
3.1.21 - Access Control

Limit use of portable storage devices on external systems.

cmmc://control/3.1.21
3.1.22 - Access Control

Control CUI posted or processed on publicly accessible systems.

cmmc://control/3.1.22
3.2.1 - Awareness & Training

Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of t

cmmc://control/3.2.1
3.2.2 - Awareness & Training

Ensure that personnel are trained to carry out their assigned information securityrelated duties and responsibilities.

cmmc://control/3.2.2
3.2.3 - Awareness & Training

Provide security awareness training on recognizing and reporting potential indicators of insider threat.

cmmc://control/3.2.3
3.3.1 - Audit & Accountability

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorize

cmmc://control/3.3.1
3.3.2 - Audit & Accountability

Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

cmmc://control/3.3.2
3.3.3 - Audit & Accountability

Review and update logged events.

cmmc://control/3.3.3
3.3.4 - Audit & Accountability

Alert in the event of an audit logging process failure.

cmmc://control/3.3.4
3.3.5 - Audit & Accountability

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual

cmmc://control/3.3.5
3.3.6 - Audit & Accountability

Provide audit record reduction and report generation to support on-demand analysis and reporting.

cmmc://control/3.3.6
3.3.7 - Audit & Accountability

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

cmmc://control/3.3.7
3.3.8 - Audit & Accountability

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

cmmc://control/3.3.8
3.3.9 - Audit & Accountability

Limit management of audit logging functionality to a subset of privileged users.

cmmc://control/3.3.9
3.4.1 - Configuration Management

Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout

cmmc://control/3.4.1
3.4.2 - Configuration Management

Establish and enforce security configuration settings for information technology products employed in organizational systems.

cmmc://control/3.4.2
3.4.3 - Configuration Management

Track, review, approve or disapprove, and log changes to organizational systems.

cmmc://control/3.4.3
3.4.4 - Configuration Management

Analyze the security impact of changes prior to implementation.

cmmc://control/3.4.4
3.4.5 - Configuration Management

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

cmmc://control/3.4.5
3.4.6 - Configuration Management

Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

cmmc://control/3.4.6
3.4.7 - Configuration Management

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

cmmc://control/3.4.7
3.4.8 - Configuration Management

Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the ex

cmmc://control/3.4.8
3.4.9 - Configuration Management

Control and monitor user-installed software.

cmmc://control/3.4.9
3.5.1 - Identification & Authentication

Identify system users, processes acting on behalf of users, and devices.

cmmc://control/3.5.1
3.5.2 - Identification & Authentication

Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

cmmc://control/3.5.2
3.5.3 - Identification & Authentication

Use multifactor authentication (MFA) for local and network access to privileged accounts and for network access to nonprivileged accounts.

cmmc://control/3.5.3
3.5.4 - Identification & Authentication

Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

cmmc://control/3.5.4
3.5.5 - Identification & Authentication

Prevent reuse of identifiers for a defined period.

cmmc://control/3.5.5
3.5.6 - Identification & Authentication

Disable identifiers after a defined period of inactivity.

cmmc://control/3.5.6
3.5.7 - Identification & Authentication

Enforce a minimum password complexity and change of characters when new passwords are created.

cmmc://control/3.5.7
3.5.8 - Identification & Authentication

Prohibit password reuse for a specified number of generations.

cmmc://control/3.5.8
3.5.9 - Identification & Authentication

Allow temporary password use for system logons with an immediate change to a permanent password.

cmmc://control/3.5.9
3.5.10 - Identification & Authentication

Store and transmit only cryptographicallyprotected passwords.

cmmc://control/3.5.10
3.5.11 - Identification & Authentication

Obscure feedback of authentication information.

cmmc://control/3.5.11
3.6.1 - Incident Response

Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user

cmmc://control/3.6.1
3.6.2 - Incident Response

Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

cmmc://control/3.6.2
3.6.3 - Incident Response

Test the organizational incident response capability.

cmmc://control/3.6.3
3.7.1 - Maintenance

Perform maintenance on organizational systems.

cmmc://control/3.7.1
3.7.2 - Maintenance

Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

cmmc://control/3.7.2
3.7.3 - Maintenance

Ensure equipment removed for off-site maintenance is sanitized of any CUI.

cmmc://control/3.7.3
3.7.4 - Maintenance

Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

cmmc://control/3.7.4
3.7.5 - Maintenance

Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal main

cmmc://control/3.7.5
3.7.6 - Maintenance

Supervise the maintenance activities of maintenance personnel without required access authorization.

cmmc://control/3.7.6
3.8.1 - Media Protection

Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.

cmmc://control/3.8.1
3.8.2 - Media Protection

Limit access to CUI on system media to authorized users.

cmmc://control/3.8.2
3.8.3 - Media Protection

Sanitize or destroy system media containing CUI before disposal or release for reuse.

cmmc://control/3.8.3
3.8.4 - Media Protection

Mark media with necessary CUI markings and distribution limitations.

cmmc://control/3.8.4
3.8.5 - Media Protection

Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.

cmmc://control/3.8.5
3.8.6 - Media Protection

Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative phys

cmmc://control/3.8.6
3.8.7 - Media Protection

Control the use of removable media on system components.

cmmc://control/3.8.7
3.8.8 - Media Protection

Prohibit the use of portable storage devices when such devices have no identifiable owner.

cmmc://control/3.8.8
3.8.9 - Media Protection

Protect the confidentiality of backup CUI at storage locations.

cmmc://control/3.8.9
3.9.1 - Personnel Security

Screen individuals prior to authorizing access to organizational systems containing CUI.

cmmc://control/3.9.1
3.9.2 - Personnel Security

Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

cmmc://control/3.9.2
3.10.1 - Physical Protection

Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

cmmc://control/3.10.1
3.10.2 - Physical Protection

Protect and monitor the physical facility and support infrastructure for organizational systems.

cmmc://control/3.10.2
3.10.3 - Physical Protection

Escort visitors and monitor visitor activity.

cmmc://control/3.10.3
3.10.4 - Physical Protection

Maintain audit logs of physical access.

cmmc://control/3.10.4
3.10.5 - Physical Protection

Control and manage physical access devices.

cmmc://control/3.10.5
3.10.6 - Physical Protection

Enforce safeguarding measures for CUI at alternate work sites.

cmmc://control/3.10.6
3.11.1 - Risk Assessment

Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resultin

cmmc://control/3.11.1
3.11.2 - Risk Assessment

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are ident

cmmc://control/3.11.2
3.11.3 - Risk Assessment

Remediate vulnerabilities in accordance with risk assessments.

cmmc://control/3.11.3
3.12.1 - Security Assessment

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

cmmc://control/3.12.1
3.12.2 - Security Assessment

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

cmmc://control/3.12.2
3.12.3 - Security Assessment

Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

cmmc://control/3.12.3
3.12.4 - Security Assessment

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements ar

cmmc://control/3.12.4
3.13.1 - System & Communications Protection

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal b

cmmc://control/3.13.1
3.13.2 - System & Communications Protection

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizatio

cmmc://control/3.13.2
3.13.3 - System & Communications Protection

Separate user functionality from system management functionality.

cmmc://control/3.13.3
3.13.4 - System & Communications Protection

Prevent unauthorized and unintended information transfer via shared system resources.

cmmc://control/3.13.4
3.13.5 - System & Communications Protection

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

cmmc://control/3.13.5
3.13.6 - System & Communications Protection

Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

cmmc://control/3.13.6
3.13.7 - System & Communications Protection

Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resour

cmmc://control/3.13.7
3.13.8 - System & Communications Protection

Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

cmmc://control/3.13.8
3.13.9 - System & Communications Protection

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

cmmc://control/3.13.9
3.13.10 - System & Communications Protection

Establish and manage cryptographic keys for cryptography employed in organizational systems.

cmmc://control/3.13.10
3.13.11 - System & Communications Protection

Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

cmmc://control/3.13.11
3.13.12 - System & Communications Protection

Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

cmmc://control/3.13.12
3.13.13 - System & Communications Protection

Control and monitor the use of mobile code.

cmmc://control/3.13.13
3.13.14 - System & Communications Protection

Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

cmmc://control/3.13.14
3.13.15 - System & Communications Protection

Protect the authenticity of communications sessions.

cmmc://control/3.13.15
3.13.16 - System & Communications Protection

Protect the confidentiality of CUI at rest.

cmmc://control/3.13.16
3.14.1 - System & Information Integrity

Identify, report, and correct system flaws in a timely manner.

cmmc://control/3.14.1
3.14.2 - System & Information Integrity

Provide protection from malicious code at designated locations within organizational systems.

cmmc://control/3.14.2
3.14.3 - System & Information Integrity

Monitor system security alerts and advisories and take action in response.

cmmc://control/3.14.3
3.14.4 - System & Information Integrity

Update malicious code protection mechanisms when new releases are available.

cmmc://control/3.14.4
3.14.5 - System & Information Integrity

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

cmmc://control/3.14.5
3.14.6 - System & Information Integrity

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

cmmc://control/3.14.6
3.14.7 - System & Information Integrity

Identify unauthorized use of organizational systems

cmmc://control/3.14.7
3.1.1 assessment objectives

How an assessor tests 3.1.1.

cmmc://objectives/3.1.1
3.1.2 assessment objectives

How an assessor tests 3.1.2.

cmmc://objectives/3.1.2
3.1.3 assessment objectives

How an assessor tests 3.1.3.

cmmc://objectives/3.1.3
3.1.4 assessment objectives

How an assessor tests 3.1.4.

cmmc://objectives/3.1.4
3.1.5 assessment objectives

How an assessor tests 3.1.5.

cmmc://objectives/3.1.5
3.1.6 assessment objectives

How an assessor tests 3.1.6.

cmmc://objectives/3.1.6
3.1.7 assessment objectives

How an assessor tests 3.1.7.

cmmc://objectives/3.1.7
3.1.8 assessment objectives

How an assessor tests 3.1.8.

cmmc://objectives/3.1.8
3.1.9 assessment objectives

How an assessor tests 3.1.9.

cmmc://objectives/3.1.9
3.1.10 assessment objectives

How an assessor tests 3.1.10.

cmmc://objectives/3.1.10
3.1.11 assessment objectives

How an assessor tests 3.1.11.

cmmc://objectives/3.1.11
3.1.12 assessment objectives

How an assessor tests 3.1.12.

cmmc://objectives/3.1.12
3.1.13 assessment objectives

How an assessor tests 3.1.13.

cmmc://objectives/3.1.13
3.1.14 assessment objectives

How an assessor tests 3.1.14.

cmmc://objectives/3.1.14
3.1.15 assessment objectives

How an assessor tests 3.1.15.

cmmc://objectives/3.1.15
3.1.16 assessment objectives

How an assessor tests 3.1.16.

cmmc://objectives/3.1.16
3.1.17 assessment objectives

How an assessor tests 3.1.17.

cmmc://objectives/3.1.17
3.1.18 assessment objectives

How an assessor tests 3.1.18.

cmmc://objectives/3.1.18
3.1.19 assessment objectives

How an assessor tests 3.1.19.

cmmc://objectives/3.1.19
3.1.20 assessment objectives

How an assessor tests 3.1.20.

cmmc://objectives/3.1.20
3.1.21 assessment objectives

How an assessor tests 3.1.21.

cmmc://objectives/3.1.21
3.1.22 assessment objectives

How an assessor tests 3.1.22.

cmmc://objectives/3.1.22
3.2.1 assessment objectives

How an assessor tests 3.2.1.

cmmc://objectives/3.2.1
3.2.2 assessment objectives

How an assessor tests 3.2.2.

cmmc://objectives/3.2.2
3.2.3 assessment objectives

How an assessor tests 3.2.3.

cmmc://objectives/3.2.3
3.3.1 assessment objectives

How an assessor tests 3.3.1.

cmmc://objectives/3.3.1
3.3.2 assessment objectives

How an assessor tests 3.3.2.

cmmc://objectives/3.3.2
3.3.3 assessment objectives

How an assessor tests 3.3.3.

cmmc://objectives/3.3.3
3.3.4 assessment objectives

How an assessor tests 3.3.4.

cmmc://objectives/3.3.4
3.3.5 assessment objectives

How an assessor tests 3.3.5.

cmmc://objectives/3.3.5
3.3.6 assessment objectives

How an assessor tests 3.3.6.

cmmc://objectives/3.3.6
3.3.7 assessment objectives

How an assessor tests 3.3.7.

cmmc://objectives/3.3.7
3.3.8 assessment objectives

How an assessor tests 3.3.8.

cmmc://objectives/3.3.8
3.3.9 assessment objectives

How an assessor tests 3.3.9.

cmmc://objectives/3.3.9
3.4.1 assessment objectives

How an assessor tests 3.4.1.

cmmc://objectives/3.4.1
3.4.2 assessment objectives

How an assessor tests 3.4.2.

cmmc://objectives/3.4.2
3.4.3 assessment objectives

How an assessor tests 3.4.3.

cmmc://objectives/3.4.3
3.4.4 assessment objectives

How an assessor tests 3.4.4.

cmmc://objectives/3.4.4
3.4.5 assessment objectives

How an assessor tests 3.4.5.

cmmc://objectives/3.4.5
3.4.6 assessment objectives

How an assessor tests 3.4.6.

cmmc://objectives/3.4.6
3.4.7 assessment objectives

How an assessor tests 3.4.7.

cmmc://objectives/3.4.7
3.4.8 assessment objectives

How an assessor tests 3.4.8.

cmmc://objectives/3.4.8
3.4.9 assessment objectives

How an assessor tests 3.4.9.

cmmc://objectives/3.4.9
3.5.1 assessment objectives

How an assessor tests 3.5.1.

cmmc://objectives/3.5.1
3.5.2 assessment objectives

How an assessor tests 3.5.2.

cmmc://objectives/3.5.2
3.5.3 assessment objectives

How an assessor tests 3.5.3.

cmmc://objectives/3.5.3
3.5.4 assessment objectives

How an assessor tests 3.5.4.

cmmc://objectives/3.5.4
3.5.5 assessment objectives

How an assessor tests 3.5.5.

cmmc://objectives/3.5.5
3.5.6 assessment objectives

How an assessor tests 3.5.6.

cmmc://objectives/3.5.6
3.5.7 assessment objectives

How an assessor tests 3.5.7.

cmmc://objectives/3.5.7
3.5.8 assessment objectives

How an assessor tests 3.5.8.

cmmc://objectives/3.5.8
3.5.9 assessment objectives

How an assessor tests 3.5.9.

cmmc://objectives/3.5.9
3.5.10 assessment objectives

How an assessor tests 3.5.10.

cmmc://objectives/3.5.10
3.5.11 assessment objectives

How an assessor tests 3.5.11.

cmmc://objectives/3.5.11
3.6.1 assessment objectives

How an assessor tests 3.6.1.

cmmc://objectives/3.6.1
3.6.2 assessment objectives

How an assessor tests 3.6.2.

cmmc://objectives/3.6.2
3.6.3 assessment objectives

How an assessor tests 3.6.3.

cmmc://objectives/3.6.3
3.7.1 assessment objectives

How an assessor tests 3.7.1.

cmmc://objectives/3.7.1
3.7.2 assessment objectives

How an assessor tests 3.7.2.

cmmc://objectives/3.7.2
3.7.3 assessment objectives

How an assessor tests 3.7.3.

cmmc://objectives/3.7.3
3.7.4 assessment objectives

How an assessor tests 3.7.4.

cmmc://objectives/3.7.4
3.7.5 assessment objectives

How an assessor tests 3.7.5.

cmmc://objectives/3.7.5
3.7.6 assessment objectives

How an assessor tests 3.7.6.

cmmc://objectives/3.7.6
3.8.1 assessment objectives

How an assessor tests 3.8.1.

cmmc://objectives/3.8.1
3.8.2 assessment objectives

How an assessor tests 3.8.2.

cmmc://objectives/3.8.2
3.8.3 assessment objectives

How an assessor tests 3.8.3.

cmmc://objectives/3.8.3
3.8.4 assessment objectives

How an assessor tests 3.8.4.

cmmc://objectives/3.8.4
3.8.5 assessment objectives

How an assessor tests 3.8.5.

cmmc://objectives/3.8.5
3.8.6 assessment objectives

How an assessor tests 3.8.6.

cmmc://objectives/3.8.6
3.8.7 assessment objectives

How an assessor tests 3.8.7.

cmmc://objectives/3.8.7
3.8.8 assessment objectives

How an assessor tests 3.8.8.

cmmc://objectives/3.8.8
3.8.9 assessment objectives

How an assessor tests 3.8.9.

cmmc://objectives/3.8.9
3.9.1 assessment objectives

How an assessor tests 3.9.1.

cmmc://objectives/3.9.1
3.9.2 assessment objectives

How an assessor tests 3.9.2.

cmmc://objectives/3.9.2
3.10.1 assessment objectives

How an assessor tests 3.10.1.

cmmc://objectives/3.10.1
3.10.2 assessment objectives

How an assessor tests 3.10.2.

cmmc://objectives/3.10.2
3.10.3 assessment objectives

How an assessor tests 3.10.3.

cmmc://objectives/3.10.3
3.10.4 assessment objectives

How an assessor tests 3.10.4.

cmmc://objectives/3.10.4
3.10.5 assessment objectives

How an assessor tests 3.10.5.

cmmc://objectives/3.10.5
3.10.6 assessment objectives

How an assessor tests 3.10.6.

cmmc://objectives/3.10.6
3.11.1 assessment objectives

How an assessor tests 3.11.1.

cmmc://objectives/3.11.1
3.11.2 assessment objectives

How an assessor tests 3.11.2.

cmmc://objectives/3.11.2
3.11.3 assessment objectives

How an assessor tests 3.11.3.

cmmc://objectives/3.11.3
3.12.1 assessment objectives

How an assessor tests 3.12.1.

cmmc://objectives/3.12.1
3.12.2 assessment objectives

How an assessor tests 3.12.2.

cmmc://objectives/3.12.2
3.12.3 assessment objectives

How an assessor tests 3.12.3.

cmmc://objectives/3.12.3
3.12.4 assessment objectives

How an assessor tests 3.12.4.

cmmc://objectives/3.12.4
3.13.1 assessment objectives

How an assessor tests 3.13.1.

cmmc://objectives/3.13.1
3.13.2 assessment objectives

How an assessor tests 3.13.2.

cmmc://objectives/3.13.2
3.13.3 assessment objectives

How an assessor tests 3.13.3.

cmmc://objectives/3.13.3
3.13.4 assessment objectives

How an assessor tests 3.13.4.

cmmc://objectives/3.13.4
3.13.5 assessment objectives

How an assessor tests 3.13.5.

cmmc://objectives/3.13.5
3.13.6 assessment objectives

How an assessor tests 3.13.6.

cmmc://objectives/3.13.6
3.13.7 assessment objectives

How an assessor tests 3.13.7.

cmmc://objectives/3.13.7
3.13.8 assessment objectives

How an assessor tests 3.13.8.

cmmc://objectives/3.13.8
3.13.9 assessment objectives

How an assessor tests 3.13.9.

cmmc://objectives/3.13.9
3.13.10 assessment objectives

How an assessor tests 3.13.10.

cmmc://objectives/3.13.10
3.13.11 assessment objectives

How an assessor tests 3.13.11.

cmmc://objectives/3.13.11
3.13.12 assessment objectives

How an assessor tests 3.13.12.

cmmc://objectives/3.13.12
3.13.13 assessment objectives

How an assessor tests 3.13.13.

cmmc://objectives/3.13.13
3.13.14 assessment objectives

How an assessor tests 3.13.14.

cmmc://objectives/3.13.14
3.13.15 assessment objectives

How an assessor tests 3.13.15.

cmmc://objectives/3.13.15
3.13.16 assessment objectives

How an assessor tests 3.13.16.

cmmc://objectives/3.13.16
3.14.1 assessment objectives

How an assessor tests 3.14.1.

cmmc://objectives/3.14.1
3.14.2 assessment objectives

How an assessor tests 3.14.2.

cmmc://objectives/3.14.2
3.14.3 assessment objectives

How an assessor tests 3.14.3.

cmmc://objectives/3.14.3
3.14.4 assessment objectives

How an assessor tests 3.14.4.

cmmc://objectives/3.14.4
3.14.5 assessment objectives

How an assessor tests 3.14.5.

cmmc://objectives/3.14.5
3.14.6 assessment objectives

How an assessor tests 3.14.6.

cmmc://objectives/3.14.6
3.14.7 assessment objectives

How an assessor tests 3.14.7.

cmmc://objectives/3.14.7

Prompts · 1

sprs_self_assessment

Walk a DoD contractor through a NIST SP 800-171 self-assessment and produce an exact, submittable SPRS score.

How to use

Add to your Claude Desktop / Cursor / Cline MCP config:

{
  "mcpServers": {
    "mactech_cmmc_/_nist_800-171": {
      "url": "https://www.mactechsolutionsllc.com/api/mcp",
      "transport": "streamable-http"
    }
  }
}