MacTech CMMC / NIST 800-171
このMCPでできること
Provides CMMC and NIST SP 800-171 guidance, control lookups, framework crosswalks, SPRS scoring, assessment scoping, eligibility checks, and POA&M generation.
ツール
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['not_implemented'], 'properties': {'not_implemented': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rev 2 control numbers not implemented, e.g. ["3.5.3", "3.11.2"]. An empty array means all 110 implemented (score 110). Rev 3 identifiers are rejected - there is no DoD scoring methodology for Rev 3.'}, 'partially_implemented': {'type': 'array', 'items': {'enum': ['3.5.3', '3.13.11'], 'type': 'string'}, 'description': 'Sliding-scale controls at their partial value: 3.5.3 (MFA for privileged and remote users only) and/or 3.13.11 (encryption employed but not FIPS-validated). Deducts 3 instead of 5.'}}}
出力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['sprs_score', 'scale', 'total_points_deducted', 'meets_conditional_level_2_threshold', 'deductions'], 'properties': {'scale': {'type': 'string'}, 'deductions': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'requirement', 'points'], 'properties': {'id': {'type': 'string'}, 'points': {'type': 'number'}, 'requirement': {'type': 'string'}}, 'additionalProperties': False}}, 'sprs_score': {'type': 'number', 'description': 'The computed score, from 110 down to the -203 floor.'}, 'missing_ssp': {'type': 'string', 'description': 'Present when 3.12.4 is unimplemented, in which case no score can be submitted to SPRS at all.'}, 'conditional_note': {'type': 'string'}, 'unknown_controls': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Inputs that matched no requirement - treat as caller error, not as implemented.'}, 'total_points_deducted': {'type': 'number'}, 'meets_conditional_level_2_threshold': {'type': 'boolean', 'description': 'Whether the score reaches 88. Clearing it is necessary but not sufficient - every open item must also be POA&M-eligible.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'contract_type': {'enum': ['firm-fixed-price', 'fixed-price-incentive', 'fixed-price-economic-price-adjustment', 'time-and-materials', 'labor-hour', 'cost-plus-fixed-fee', 'cost-plus-incentive-fee', 'cost-plus-award-fee', 'cost-sharing', 'idiq'], 'type': 'string', 'description': 'The contract type named in the solicitation. Omit to compare all types.'}, 'include_sf1408': {'type': 'boolean', 'description': 'Include the SF1408 pre-award accounting system survey criteria.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'A control id from any supported framework, e.g. "3.1.1", "AC-2", "GV.RM", or "CC6"'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'requirement': {'type': 'string', 'description': 'Optional: a specific requirement in either scheme, e.g. "3.5.3" (Rev 2) or "03.05.03" (Rev 3). Omit for the structural summary alone.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['handles_cui'], 'properties': {'handles_cui': {'enum': ['yes', 'no', 'unsure'], 'type': 'string', 'description': 'Does the organization store, process, or transmit Controlled Unclassified Information (CUI) - e.g. technical data, drawings, specs above general descriptive material?'}, 'contract_clauses': {'type': 'array', 'items': {'enum': ['52.204-21', '252.204-7012', '252.204-7019', '252.204-7020', '252.204-7021', 'none', 'unsure'], 'type': 'string'}, 'description': 'FAR/DFARS clauses present in their contracts, if known'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['gaps'], 'properties': {'gaps': {'type': 'array', 'items': {'type': 'object', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': '800-171 control number, e.g. "3.5.3"'}, 'partial': {'type': 'boolean', 'description': 'Only meaningful for the two sliding-scale requirements. 3.13.11: encryption IS employed but is not FIPS-validated (3 points) - this is the single state the rule lets you carry on a POA&M. 3.5.3: MFA on privileged and remote access only (3 points) - still NOT eligible.'}, 'deficiency': {'type': 'string', 'description': 'Optional description of the specific deficiency observed'}}}, 'description': 'The unimplemented or partially implemented controls'}, 'conditionalStatusDate': {'type': 'string', 'description': 'Conditional CMMC Status Date (YYYY-MM-DD), if one exists. The 180-day closeout window runs from this date - NOT from the day the plan is written - so without it no deadline can be computed.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.5.3"'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'family': {'enum': ['Access Control', 'Awareness & Training', 'Audit & Accountability', 'Configuration Management', 'Identification & Authentication', 'Incident Response', 'Maintenance', 'Media Protection', 'Personnel Security', 'Physical Protection', 'Risk Assessment', 'Security Assessment', 'System & Communications Protection', 'System & Information Integrity'], 'type': 'string', 'description': 'Filter by control family'}, 'weight': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 3}, {'type': 'number', 'const': 5}], 'description': 'Filter by DoD assessment point weight'}, 'verbose': {'type': 'boolean', 'description': 'Include the full requirement text for every result. Off by default: an unfiltered verbose listing is ~25Ã\x97 larger and is rarely what the question needs.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'clause': {'type': 'string', 'description': 'Clause number - "7012", "252.204-7012", or "DFARS 252.204-7012" all work. Omit to list every clause covered.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.1.1" or "3.13.11"'}, 'sections': {'type': 'array', 'items': {'enum': ['objectives', 'crosswalk'], 'type': 'string'}, 'description': 'Extra views to include: "objectives" for the 800-171A assessment objectives (how an assessor tests it), "crosswalk" for the 800-53 / CSF 2.0 / SOC 2 mappings. Omit for the requirement and its weight alone.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['requirement'], 'properties': {'requirement': {'type': 'string', 'description': 'Rev 3 requirement number, e.g. "03.01.01" or "3.1.1" (zero-padded automatically). This is a Rev 3 identifier - it is NOT the same requirement as the Rev 2 control with the similar number.'}}}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['level'], 'properties': {'level': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 2}], 'description': 'CMMC level being scoped. Level 1 has no asset taxonomy - everything touching FCI is in scope.'}, 'include_cui_categories': {'type': 'boolean', 'description': 'Include the common CUI categories and the traps that hide them. Useful when the contractor is unsure whether they hold CUI at all.'}}}
最近のツール変更
類似のMCPサーバー
DataNexus MCP
Enables public-data research across domains, patents, government contracts, nonprofits, compliance registries, and software secur…
ampel
Assesses regulated entities and providers against DORA and related ESG, MiCA, and AML requirements, with contract analysis, evide…
predictionguard
Analyzes Polymarket and Kalshi markets for insider-trading signals, market integrity risks, sanctions and PEP exposure, conflicts…
Nist Standards
Searches and retrieves NIST SP 800-53 security controls and SP 800-171 CUI requirements, including requirements, guidance, and co…
Sanctions Screening
Screens names against US sanctions and export-control lists and retrieves detailed sanctions records.
Dilisense
Screens individuals and organizations against sanctions, PEP, criminal, and adverse-watchlist data for AML and KYC checks.
Open Sanctions
Looks up sanctioned and politically exposed entities, including identifiers, aliases, addresses, sanctions programs, and relation…
Sanctions Io
Screens individuals and organizations in bulk against sanctions, politically exposed person, and watchlists.