Free · No account · Published in the official MCP registry
Your AI assistant, fluent in CMMC.
Twenty-four tools across three Model Context Protocol servers: the exact DoD scoring methodology, 2,029 DISA STIG rules with real check and fix text, and live federal-market data - built and used daily by the SDVOSB that does this work. Including an air-gapped build, for the enclaves that can’t reach the internet at all.
claude mcp add --transport http mactech-cmmc https://www.mactechsolutionsllc.com/api/mcpCompliance is where models guess
Ask any assistant what NIST 800-171 3.13.11 is worth and it will answer instantly, fluently, and often wrong. Annex A weights, STIG check commands, DFARS deadlines, asset categories - this is precisely the detail that gets invented, and precisely the detail an assessment turns on. One misremembered 5-point requirement moves your SPRS score by five. One hallucinated registry path costs an afternoon. One wrong clause number ships in a proposal.
These servers remove the guessing. The assistant retrieves the published requirement, computes the score with the real methodology, and can tell you which source it used.
Install in about ten seconds
Everything at once (recommended)
The Claude Code plugin installs every server together and adds slash commands for the work they are actually for - scoring an assessment, running a gap review, hardening a host, exporting a checklist, sizing a market.
/plugin marketplace add MacTech-Solutions-LLC/mactech-mcp
/plugin install mactech-cmmc@mactechThen /mactech-cmmc:sprs-score, :gap-assessment, :stig-harden, :stig-checklist, or :market-scan.
Claude web & desktop
Settings → Connectors → Add custom connector → paste any server URL below.
Any client, by config
{
"mcpServers": {
"mactech-cmmc": { "url": "https://www.mactechsolutionsllc.com/api/mcp" },
"federal-market": { "url": "https://www.mactechsolutionsllc.com/api/mcp/market" },
"mactech-stig": { "url": "https://www.mactechsolutionsllc.com/api/mcp/stig" }
}
}The three servers
CMMC / NIST 800-171
13 tools · v1.2.0The compliance authority: all 110 Rev 2 requirements with official DoD assessment weights, the 320 assessment objectives a C3PAO actually scores, FAR/DFARS clause duties, assessment scoping, exact SPRS arithmetic, POA&M generation, and Rev 3 served as advisory.
lookup_controllist_controlscalculate_sprs_scoreget_assessment_objectivescrosswalk_controldetermine_cmmc_levellist_level1_practicesgenerate_poam_entriescheck_contract_type_eligibilitylookup_clausescope_assessmentlookup_rev3_requirementcrosswalk_revisionsclaude mcp add --transport http mactech-cmmc https://www.mactechsolutionsllc.com/api/mcpFederal Market
7 tools · v1.1.0The BD engine: live SAM.gov contract opportunities and entity registrations (bring your own free key, or use the shared budget) plus unlimited USASpending award history and spending rollups - incumbents, agency spend, and market size in a question.
search_opportunitieslookup_entitysearch_awardsget_awardfind_agencyfind_naicsspending_by_categoryclaude mcp add --transport http federal-market https://www.mactechsolutionsllc.com/api/mcp/marketSTIG
4 tools · v1.1.0The hardening reference: 2,029 DISA STIG rules across 15 benchmarks - RHEL 8/9, Ubuntu 22.04 LTS, Windows 11, Windows Server 2022, and ten Cisco IOS / NX-OS / ISE benchmarks - with real check and fix text, and .ckl export for the assessment hand-off.
search_stigget_stig_rulelist_stig_benchmarksexport_stig_checklistclaude mcp add --transport http mactech-stig https://www.mactechsolutionsllc.com/api/mcp/stigWhat you can just ask
There is no syntax to learn. Connect a server, then ask the way you would ask a colleague - the assistant picks the tool.
Compliance lead
- “We have no MFA for general users and no vulnerability scanning - what is our SPRS score?”
- “How will an assessor test 3.5.3, and what evidence should I have ready?”
- “Our contract cites 252.204-7012. What do we owe, and what flows down to subs?”
- “Is our GovCloud tenant a CUI Asset or a Security Protection Asset?”
- “We already hold SOC 2 - which CMMC controls does CC6 already cover?”
Systems engineer
- “Which RHEL 9 CAT I rules cover SSH configuration, and what are the exact fixes?”
- “Give me the check and fix text for SV-257777.”
- “Build a hardening plan for Windows Server 2022, worst severity first.”
- “Export a .ckl for the Ubuntu 22.04 findings we just closed.”
Capture / BD
- “Find active SDVOSB set-aside solicitations for cybersecurity services.”
- “Who holds recent DISA contracts in NAICS 541512, and how big are they?”
- “Can we even accept a cost-reimbursement award right now?”
- “Top 10 contractors by obligations in our NAICS last year.”
Air-gapped, GCC High, or no internet
Hosted MCP servers all run in commercial cloud, so a CUI enclave cannot reach any of them - ours included. The offline build is the CMMC and STIG corpora compiled into one file with a published checksum: no install, no key, no network. Node 20 and nothing else.
curl -O https://www.mactechsolutionsllc.com/downloads/mactech-compliance-mcp.mjs
curl -O https://www.mactechsolutionsllc.com/downloads/mactech-compliance-mcp.mjs.sha256
# carry both across your boundary, then on the target host:
sha256sum -c mactech-compliance-mcp.mjs.sha256
claude mcp add --transport stdio mactech-compliance -- node ./mactech-compliance-mcp.mjsVerify the checksum on arrival - once the file is inside the enclave there is no route back out to re-download and compare.
The CMMC server, tool by tool
calculate_sprs_score
Exact SPRS arithmetic per the DoD Assessment Methodology: 110 minus each unimplemented requirement’s Annex A weight, the −203 floor, the 88-point conditional threshold, and the missing-SSP gate that blocks submission entirely.
“What does our score become if we close MFA and FIPS this quarter?”
get_assessment_objectives
The official NIST 800-171A assessment objectives for any control - the exact “Determine if…” statements a C3PAO scores one by one, plus what assessors examine, who they interview, and what they test.
“Walk me through everything an assessor checks for 3.13.11.”
lookup_clause
What a FAR or DFARS cybersecurity clause actually obliges you to do: the trigger, the concrete duties, reporting deadlines, subcontractor flowdown, and the clauses that travel with it.
“What does 252.204-7020 require that 7019 doesn’t?”
scope_assessment
Which assets fall inside the assessment boundary and how each is treated - CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and what is genuinely out of scope.
“Is our badge system in scope? What about the shop-floor CNC?”
check_contract_type_eligibility
The bid-feasibility gate most teams find out about too late: whether your business systems let you accept a contract type at all. A cost-reimbursement award requires an accounting system adequate for determining costs (FAR 16.301-3), and T&M billing has to be substantiable.
“This RFP is cost-plus-fixed-fee. Can we bid it, or do we fix accounting first?”
lookup_rev3_requirement + crosswalk_revisions
NIST 800-171 Rev 3 served as advisory - the active requirements, their organization-defined parameters, and the Rev 3 objectives - with a revision crosswalk for holding a Rev 3 citation against the Rev 2 obligation it maps to. It will not produce a Rev 3 score, because DoD does not assess against one.
“Our prime sent a Rev 3 citation - what’s the Rev 2 obligation behind it?”
generate_poam_entries
Turn assessment gaps into structured POA&M entries - priority from the SPRS weight, 90/180-day target dates per governance, and the closure rules a POA&M must satisfy to survive an assessment.
“We failed 3.11.2 and 3.14.1 - draft the remediation plan.”
crosswalk_control + determine_cmmc_level + list_level1_practices
Map a control across NIST 800-171 ↔ 800-53 (FedRAMP Moderate) ↔ CSF 2.0 ↔ SOC 2; decide whether FCI or CUI puts you at Level 1, 2, or 3; and get the complete 17-practice Level 1 set with FAR 52.204-21 citations.
“We only handle FCI - do we need CMMC at all?”
lookup_control + list_controls
The 110-requirement catalog: full requirement text, control family, and exact DoD assessment weight, filterable by family or point value.
“List every 5-point control in Access Control.”
More than tool calls
The servers implement the parts of MCP most do not:
- 2,249 resources - every 800-171 requirement and every STIG rule is individually addressable, so an assistant can read one directly instead of searching for it.
- Guided workflows - prompts that run a real procedure end to end: a full SPRS self-assessment, a reviewable host-hardening plan, a grounded bid/no-bid.
- Argument completion - control numbers and benchmark names autocomplete instead of being guessed at.
- Declared output schemas - where a result shape is stable it is typed, so downstream automation can rely on it.
What these will not do
- Score you against Rev 3. Rev 3 is served as advisory only. DoD scores against Rev 2, so producing a Rev 3 “score” would be inventing a number nobody accepts.
- Replace an assessment. A computed score is only as good as the answers behind it. We make you assessment-ready; a C3PAO certifies.
- Cover every STIG. Fifteen benchmarks today. If yours is not among them, DISA publishes the full library - and tell us, because the converter that built these takes new ones quickly.
Frequently asked questions
What are the MacTech MCP servers?
Three free, public Model Context Protocol servers that give AI assistants authoritative defense-industrial-base data. CMMC/NIST 800-171: all 110 Rev 2 requirements with official DoD Assessment Methodology weights, the 320 NIST 800-171A assessment objectives, FAR/DFARS clause duties, assessment scoping, exact SPRS scoring, POA&M generation, and Rev 3 as advisory. Federal Market: live SAM.gov contract opportunities, entity registrations, and USASpending award data. STIG: 2,029 DISA hardening rules across 15 benchmarks with full check and fix text plus .ckl checklist export. 24 tools in total. Once connected, your assistant answers from source data instead of memory.
Why use these instead of asking the AI directly?
Because compliance detail is exactly what language models invent most confidently. A misremembered Annex A weight moves an SPRS score by five points; a hallucinated sysctl key or registry path wastes an afternoon; a wrong clause number ends up in a proposal. These servers carry the published values, so weights, rules, and scores are retrieved or computed - never recalled - and the assistant can tell you which source it used.
Do they require an account, an API key, or payment?
No account, no key, no cost. All three are free, unauthenticated, and stateless. One nuance: SAM.gov rate-limits its own API keys, so the two SAM-backed tools on the Federal Market server work best if you pass your own free SAM.gov key (an X-Sam-Api-Key header); without one you share a limited daily budget. Everything else - all CMMC tools, all STIG tools, all USASpending tools - is unlimited.
Can I use them in an air-gapped or GCC High environment?
Yes, and that is the point of the offline build. Every hosted MCP server runs in commercial cloud, which a CUI enclave cannot reach - ours included. So the CMMC and STIG corpora are also compiled into a single 6.7 MB file with a published SHA-256: carry it across the boundary, verify the checksum on arrival, and run it over stdio with Node 20. No install, no key, no network.
Is anything I send stored?
Nothing you send is stored: we keep daily aggregate counts only (how many connections, which tools were called, client application names). No request or response payloads, no raw IP addresses, and no user agents are ever recorded.
What is MCP?
The Model Context Protocol is the open standard that lets AI assistants like Claude connect to external tools and data sources. Adding a server takes one line in Claude Code, one click in Cursor or VS Code, or one URL in a client’s connector settings - after that, the assistant calls the server’s tools automatically whenever they are relevant. You just ask your question normally.
Who maintains them, and why are they free?
MacTech Solutions, an SDVOSB that takes defense contractors from first SSP to C3PAO-ready. The servers run on the same data as our paid work. They are free because a contractor whose assistant can suddenly compute a real SPRS score usually discovers exactly how much remediation stands between them and an award - and we would rather be the firm that showed them.
When the score comes back low
Most people connect these, compute a real number for the first time, and find it well below the 88 they need. That is the useful moment. Start with the free 5-minute readiness check, or have us verify it properly - the Verified Readiness Scan scores all 110 against your actual environment in five business days and credits fully toward any engagement that follows.
MacTech Solutions is an SDVOSB that takes defense contractors from first SSP to C3PAO-ready - CMMC services, the full catalog, or talk to us.