此 MCP 可以做什么
Provides CMMC and NIST SP 800-171 guidance, control lookups, framework crosswalks, SPRS scoring, assessment scoping, eligibility checks, and POA&M generation.
工具
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['not_implemented'], 'properties': {'not_implemented': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rev 2 control numbers not implemented, e.g. ["3.5.3", "3.11.2"]. An empty array means all 110 implemented (score 110). Rev 3 identifiers are rejected - there is no DoD scoring methodology for Rev 3.'}, 'partially_implemented': {'type': 'array', 'items': {'enum': ['3.5.3', '3.13.11'], 'type': 'string'}, 'description': 'Sliding-scale controls at their partial value: 3.5.3 (MFA for privileged and remote users only) and/or 3.13.11 (encryption employed but not FIPS-validated). Deducts 3 instead of 5.'}}}
输出模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['sprs_score', 'scale', 'total_points_deducted', 'meets_conditional_level_2_threshold', 'deductions'], 'properties': {'scale': {'type': 'string'}, 'deductions': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'requirement', 'points'], 'properties': {'id': {'type': 'string'}, 'points': {'type': 'number'}, 'requirement': {'type': 'string'}}, 'additionalProperties': False}}, 'sprs_score': {'type': 'number', 'description': 'The computed score, from 110 down to the -203 floor.'}, 'missing_ssp': {'type': 'string', 'description': 'Present when 3.12.4 is unimplemented, in which case no score can be submitted to SPRS at all.'}, 'conditional_note': {'type': 'string'}, 'unknown_controls': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Inputs that matched no requirement - treat as caller error, not as implemented.'}, 'total_points_deducted': {'type': 'number'}, 'meets_conditional_level_2_threshold': {'type': 'boolean', 'description': 'Whether the score reaches 88. Clearing it is necessary but not sufficient - every open item must also be POA&M-eligible.'}}, 'additionalProperties': False}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'contract_type': {'enum': ['firm-fixed-price', 'fixed-price-incentive', 'fixed-price-economic-price-adjustment', 'time-and-materials', 'labor-hour', 'cost-plus-fixed-fee', 'cost-plus-incentive-fee', 'cost-plus-award-fee', 'cost-sharing', 'idiq'], 'type': 'string', 'description': 'The contract type named in the solicitation. Omit to compare all types.'}, 'include_sf1408': {'type': 'boolean', 'description': 'Include the SF1408 pre-award accounting system survey criteria.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'A control id from any supported framework, e.g. "3.1.1", "AC-2", "GV.RM", or "CC6"'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'requirement': {'type': 'string', 'description': 'Optional: a specific requirement in either scheme, e.g. "3.5.3" (Rev 2) or "03.05.03" (Rev 3). Omit for the structural summary alone.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['handles_cui'], 'properties': {'handles_cui': {'enum': ['yes', 'no', 'unsure'], 'type': 'string', 'description': 'Does the organization store, process, or transmit Controlled Unclassified Information (CUI) - e.g. technical data, drawings, specs above general descriptive material?'}, 'contract_clauses': {'type': 'array', 'items': {'enum': ['52.204-21', '252.204-7012', '252.204-7019', '252.204-7020', '252.204-7021', 'none', 'unsure'], 'type': 'string'}, 'description': 'FAR/DFARS clauses present in their contracts, if known'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['gaps'], 'properties': {'gaps': {'type': 'array', 'items': {'type': 'object', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': '800-171 control number, e.g. "3.5.3"'}, 'partial': {'type': 'boolean', 'description': 'Only meaningful for the two sliding-scale requirements. 3.13.11: encryption IS employed but is not FIPS-validated (3 points) - this is the single state the rule lets you carry on a POA&M. 3.5.3: MFA on privileged and remote access only (3 points) - still NOT eligible.'}, 'deficiency': {'type': 'string', 'description': 'Optional description of the specific deficiency observed'}}}, 'description': 'The unimplemented or partially implemented controls'}, 'conditionalStatusDate': {'type': 'string', 'description': 'Conditional CMMC Status Date (YYYY-MM-DD), if one exists. The 180-day closeout window runs from this date - NOT from the day the plan is written - so without it no deadline can be computed.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.5.3"'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'family': {'enum': ['Access Control', 'Awareness & Training', 'Audit & Accountability', 'Configuration Management', 'Identification & Authentication', 'Incident Response', 'Maintenance', 'Media Protection', 'Personnel Security', 'Physical Protection', 'Risk Assessment', 'Security Assessment', 'System & Communications Protection', 'System & Information Integrity'], 'type': 'string', 'description': 'Filter by control family'}, 'weight': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 3}, {'type': 'number', 'const': 5}], 'description': 'Filter by DoD assessment point weight'}, 'verbose': {'type': 'boolean', 'description': 'Include the full requirement text for every result. Off by default: an unfiltered verbose listing is ~25Ã\x97 larger and is rarely what the question needs.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'clause': {'type': 'string', 'description': 'Clause number - "7012", "252.204-7012", or "DFARS 252.204-7012" all work. Omit to list every clause covered.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['control'], 'properties': {'control': {'type': 'string', 'description': 'Control number, e.g. "3.1.1" or "3.13.11"'}, 'sections': {'type': 'array', 'items': {'enum': ['objectives', 'crosswalk'], 'type': 'string'}, 'description': 'Extra views to include: "objectives" for the 800-171A assessment objectives (how an assessor tests it), "crosswalk" for the 800-53 / CSF 2.0 / SOC 2 mappings. Omit for the requirement and its weight alone.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['requirement'], 'properties': {'requirement': {'type': 'string', 'description': 'Rev 3 requirement number, e.g. "03.01.01" or "3.1.1" (zero-padded automatically). This is a Rev 3 identifier - it is NOT the same requirement as the Rev 2 control with the similar number.'}}}
输入模式
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['level'], 'properties': {'level': {'anyOf': [{'type': 'number', 'const': 1}, {'type': 'number', 'const': 2}], 'description': 'CMMC level being scoped. Level 1 has no asset taxonomy - everything touching FCI is in scope.'}, 'include_cui_categories': {'type': 'boolean', 'description': 'Include the common CUI categories and the traps that hide them. Useful when the contractor is unsure whether they hold CUI at all.'}}}
近期工具变更
类似的 MCP 服务器
DataNexus MCP
Enables public-data research across domains, patents, government contracts, nonprofits, compliance registries, and software secur…
ampel
Assesses regulated entities and providers against DORA and related ESG, MiCA, and AML requirements, with contract analysis, evide…
predictionguard
Analyzes Polymarket and Kalshi markets for insider-trading signals, market integrity risks, sanctions and PEP exposure, conflicts…
Nist Standards
Searches and retrieves NIST SP 800-53 security controls and SP 800-171 CUI requirements, including requirements, guidance, and co…
Sanctions Screening
Screens names against US sanctions and export-control lists and retrieves detailed sanctions records.
Dilisense
Screens individuals and organizations against sanctions, PEP, criminal, and adverse-watchlist data for AML and KYC checks.
Open Sanctions
Looks up sanctioned and politically exposed entities, including identifiers, aliases, addresses, sanctions programs, and relation…
Sanctions Io
Screens individuals and organizations in bulk against sanctions, politically exposed person, and watchlists.