AI Playbook for Federal Cybersecurity Compliance — CMMC 2.0
Your firm is pursuing a $15M DoD contract that requires CMMC Level 2 certification. You process Controlled Unclassified Information. A third-party assessor has conducted a gap assessment showing 47 practices not yet fully implemented. Certification is required before contract award, estimated in 8 months.
When to use this playbook
- Use this playbook when the decision looks like the situation above: Your firm is pursuing a $15M DoD contract that requires CMMC Level 2 certification.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Federal Cybersecurity Compliance — CMMC 2.0".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Third-party gap assessment results (47 practices not implemented)
- NIST SP 800-171 control requirements
- Current IT environment documentation
- 8-month timeline to contract award
- Budget constraint: $400,000 for remediation
Attachments: Documents (Documents)
The Prompt
You are a federal compliance manager developing a CMMC 2.0 Level 2 remediation plan for a DoD contractor. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Prioritize the 47 gap items by: (a) assessment weight in the CMMC scoring model and (b) implementation effort—identify the highest-impact, lowest-effort items to address first. 2. Identify any POA&M (Plan of Action & Milestones) items that the DoD will accept at time of award vs. items that must be closed before award. 3. Build the 8-month remediation roadmap with milestones, responsible owners, and dependencies. 4. Identify which gaps require third-party vendor solutions (MFA, SIEM, backup) vs. policy/procedure changes that can be done internally. 5. Tell me whether $400,000 is sufficient and where the highest-risk cost overruns are likely to occur. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Prioritized gap remediation list by impact and effort
- POA&M eligibility assessment for each gap
- 8-month remediation roadmap with milestones
- Vendor vs. internal solution split
- Budget adequacy analysis with cost overrun risks
Review before you act
- Validate this output against source files before relying on it: Prioritize the 47 gap items by: (a) assessment weight in the CMMC scoring model and (b) implementation effort—identify the highest-impact, lowest-effort items to address first.
- Validate this output against source files before relying on it: Identify any POA&M (Plan of Action & Milestones) items that the DoD will accept at time of award vs. items that must be closed before award.
- Validate this output against source files before relying on it: Build the 8-month remediation roadmap with milestones, responsible owners, and dependencies.
- Validate this output against source files before relying on it: Identify which gaps require third-party vendor solutions (MFA, SIEM, backup) vs. policy/procedure changes that can be done internally.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Federal Cybersecurity Compliance — CMMC 2.0, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface prioritized gap remediation list by impact and effort; poa&m eligibility assessment for each gap; 8-month remediation roadmap with milestones; vendor vs. internal solution split. Those are comparison artifacts — they only exist if more than one model runs. Models split on whether a requirement is mandatory, how to score a differentiator, and protest likelihood. Those splits should be resolved before color-team review, not after submission.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

