MacTech CMMC / NIST 800-171
Ce que fait ce MCP
Provides CMMC and NIST SP 800-171 guidance, control lookups, framework crosswalks, SPRS scoring, assessment scoping, eligibility checks, and POA&M generation.
Outils
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['not_implemented'], 'properties': {'not_implemented': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rev 2 control numbers not implemented, e.g. ["3.5.3", "3.11.2"]. An empty array means all 110 implemented (score 110). Rev 3 identifiers are rejected - there is no DoD scoring methodology for Rev 3.'}, 'partially_implemented': {'type': 'array', 'items': {'enum': ['3.5.3', '3.13.11'], 'type': 'string'}, 'description': 'Sliding-scale controls at their partial value: 3.5.3 (MFA for privileged and remote users only) and/or 3.13.11 (encryption employed but not FIPS-validated). Deducts 3 instead of 5.'}}}
Schéma de sortie
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['sprs_score', 'scale', 'total_points_deducted', 'meets_conditional_level_2_threshold', 'deductions'], 'properties': {'scale': {'type': 'string'}, 'deductions': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'requirement', 'points'], 'properties': {'id': {'type': 'string'}, 'points': {'type': 'number'}, 'requirement': {'type': 'string'}}, 'additionalProperties': False}}, 'sprs_score': {'type': 'number', 'description': 'The computed score, from 110 down to the -203 floor.'}, 'missing_ssp': {'type': 'string', 'description': 'Present when 3.12.4 is unimplemented, in which case no score can be submitted to SPRS at all.'}, 'conditional_note': {'type': 'string'}, 'unknown_controls': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Inputs that matched no requirement - treat as caller error, not as implemented.'}, 'total_points_deducted': {'type': 'number'}, 'meets_conditional_level_2_threshold': {'type': 'boolean', 'description': 'Whether the score reaches 88. Clearing it is necessary but not sufficient - every open item must also be POA&M-eligible.'}}, 'additionalProperties': False}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'contract_type': {'enum': ['firm-fixed-price', 'fixed-price-incentive', 'fixed-price-economic-price-adjustment', 'time-and-materials', 'labor-hour', 'cost-plus-fixed-fee', 'cost-plus-incentive-fee', 'cost-plus-award-fee', 'cost-sharing', 'idiq'], 'type': 'string', 'description': 'The contract type named in the solicitation. Omit to compare all types.'}, 'include_sf1408': {'type': 'boolean', 'description': 'Include the SF1408 pre-award accounting system survey criteria.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'A control id from any supported framework, e.g. "3.1.1", "AC-2", "GV.RM", or "CC6"'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'requirement': {'type': 'string', 'description': 'Optional: a specific requirement in either scheme, e.g. "3.5.3" (Rev 2) or "03.05.03" (Rev 3). Omit for the structural summary alone.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['handles_cui'], 'properties': {'handles_cui': {'enum': ['yes', 'no', 'unsure'], 'type': 'string', 'description': 'Does the organization store, process, or transmit Controlled Unclassified Information (CUI) - e.g. technical data, drawings, specs above general descriptive material?'}, 'contract_clauses': {'type': 'array', 'items': {'enum': ['52.204-21', '252.204-7012', '252.204-7019', '252.204-7020', '252.204-7021', 'none', 'unsure'], 'type': 'string'}, 'description': 'FAR/DFARS clauses present in their contracts, if known'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['gaps'], 'properties': {'gaps': {'type': 'array', 'items': {'type': 'object', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': '800-171 control number, e.g. "3.5.3"'}, 'partial': {'type': 'boolean', 'description': 'Only meaningful for the two sliding-scale requirements. 3.13.11: encryption IS employed but is not FIPS-validated (3 points) - this is the single state the rule lets you carry on a POA&M. 3.5.3: MFA on privileged and remote access only (3 points) - still NOT eligible.'}, 'deficiency': {'type': 'string', 'description': 'Optional description of the specific deficiency observed'}}}, 'description': 'The unimplemented or partially implemented controls'}, 'conditionalStatusDate': {'type': 'string', 'description': 'Conditional CMMC Status Date (YYYY-MM-DD), if one exists. The 180-day closeout window runs from this date - NOT from the day the plan is written - so without it no deadline can be computed.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.5.3"'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'family': {'enum': ['Access Control', 'Awareness & Training', 'Audit & Accountability', 'Configuration Management', 'Identification & Authentication', 'Incident Response', 'Maintenance', 'Media Protection', 'Personnel Security', 'Physical Protection', 'Risk Assessment', 'Security Assessment', 'System & Communications Protection', 'System & Information Integrity'], 'type': 'string', 'description': 'Filter by control family'}, 'weight': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 3}, {'type': 'number', 'const': 5}], 'description': 'Filter by DoD assessment point weight'}, 'verbose': {'type': 'boolean', 'description': 'Include the full requirement text for every result. Off by default: an unfiltered verbose listing is ~25Ã\x97 larger and is rarely what the question needs.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'clause': {'type': 'string', 'description': 'Clause number - "7012", "252.204-7012", or "DFARS 252.204-7012" all work. Omit to list every clause covered.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.1.1" or "3.13.11"'}, 'sections': {'type': 'array', 'items': {'enum': ['objectives', 'crosswalk'], 'type': 'string'}, 'description': 'Extra views to include: "objectives" for the 800-171A assessment objectives (how an assessor tests it), "crosswalk" for the 800-53 / CSF 2.0 / SOC 2 mappings. Omit for the requirement and its weight alone.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['requirement'], 'properties': {'requirement': {'type': 'string', 'description': 'Rev 3 requirement number, e.g. "03.01.01" or "3.1.1" (zero-padded automatically). This is a Rev 3 identifier - it is NOT the same requirement as the Rev 2 control with the similar number.'}}}
Schéma d’entrée
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['level'], 'properties': {'level': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 2}], 'description': 'CMMC level being scoped. Level 1 has no asset taxonomy - everything touching FCI is in scope.'}, 'include_cui_categories': {'type': 'boolean', 'description': 'Include the common CUI categories and the traps that hide them. Useful when the contractor is unsure whether they hold CUI at all.'}}}
Modifications récentes des outils
Serveurs MCP similaires
DataNexus MCP
Enables public-data research across domains, patents, government contracts, nonprofits, compliance registries, and software secur…
ampel
Assesses regulated entities and providers against DORA and related ESG, MiCA, and AML requirements, with contract analysis, evide…
predictionguard
Analyzes Polymarket and Kalshi markets for insider-trading signals, market integrity risks, sanctions and PEP exposure, conflicts…
Nist Standards
Searches and retrieves NIST SP 800-53 security controls and SP 800-171 CUI requirements, including requirements, guidance, and co…
Sanctions Screening
Screens names against US sanctions and export-control lists and retrieves detailed sanctions records.
Dilisense
Screens individuals and organizations against sanctions, PEP, criminal, and adverse-watchlist data for AML and KYC checks.
Open Sanctions
Looks up sanctioned and politically exposed entities, including identifiers, aliases, addresses, sanctions programs, and relation…
Sanctions Io
Screens individuals and organizations in bulk against sanctions, politically exposed person, and watchlists.