Building for a DoD contract, handling CUI (Controlled Unclassified Information), or in the defense supply chain? GreatCTO auto-detects the defense-govcon archetype and ships CMMC 2.0 level selection, NIST SP 800-171 (110 controls), DFARS 252.204-7012 72-hour incident reporting, CUI boundary scoping, ITAR/EAR export controls, and Section 889 supply-chain screening from day one.
CMMC / NIST 800-171 / DFARS / CUI / ITAR / Section 889 →Compliance auto-suggested: cmmc-2.0 · nist-800-171 · dfars-252.204-7012 · itar · ear · section-889 · fedramp. Specialist agents activated:
CMMC level selection (FCI vs CUI) · 110-control NIST SP 800-171 gap analysis · DFARS 252.204-7012 72-hour reporting + media preservation · CUI boundary/data-flow · SPRS/SSP/POA&M integrity · ITAR/EAR export controls · Section 889 supply-chain screening.
FedRAMP Moderate equivalence for cloud storing CUI · NIST 800-53 control mapping · authorization-boundary scoping · Section 508 accessibility for federal-facing apps.
Access-control by citizenship for ITAR data · encryption of CUI at rest/in transit · incident-response path to DIBNet · least-privilege for the CUI enclave.
$ npx great-cto init