skills/legal/dd-form-254/SKILL.md
Drafts DD Form 254 Contract Security Classification Specifications for classified government contracts. Use when preparing security classification specs for prime contractors, subcontractors, SAP/SCI access, or facility clearance documentation per NISPOM (32 CFR Part 117) and DCSA regulations.
npx skillsauth add casemark/skills dd-form-254Install this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Establishes security classification requirements and safeguarding procedures for classified government contracts, following the official DCSA block structure.
Collect before drafting:
| Field | Requirement | |---|---| | Contract number | Exact match to award document (all dashes, mod suffixes) | | Contractor name | Legal name per SAM — no DBAs or abbreviations | | Facility address | Physical location of classified work; must match DCSA facility clearance records | | CAGE code | Links contract to facility security clearance | | Subcontractors | Each: legal name, CAGE code, address, prime relationship, classified scope, whether separate DD 254 needed |
Determine highest level (Confidential / Secret / Top Secret) for government-furnished and contractor-generated information. The narrative must cover:
| Category | Key Requirements | |---|---| | SAP | Program-specific briefings, indoctrination | | SCI | SSBI/Tier 5 investigation, SCI access approval | | RD / FRD | DOE classification guides | | NATO / Foreign Gov't | Level equivalencies, separate specification |
Storage: GSA-approved container (Class 5/6) per level; secure room/vault as needed; SCIF for SCI.
Transmission:
| Method | Requirements | |---|---| | Electronic (encrypted) | Approved systems only; specify encryption standard | | Hand-carry | Chain-of-custody documentation between cleared facilities | | Defense Courier Service | TS or higher / special categories | | Authorized courier | Packaging, marking, receipting per contract |
Destruction: Approved methods per level and media type; witnessed destruction; certificates and records.
Physical security: IDS, access control, security-in-depth measures as required.
Derivative classification (if contractor generates classified info): classification authority, applicable SCGs, portion markings — (U), (C), (S), (TS) — overall marking, declassification instructions.
| Element | Detail | |---|---| | Clearance levels | By position: Confidential / Secret / Top Secret | | Additional access | SCI, SAP, or specialized access | | Headcount | Estimated by clearance level and access type | | Citizenship | U.S. citizen / LPR / LAA eligibility | | Interim clearances | Conditions and access limitations while interim | | Pre-access | NDAs, security briefings, specialized training | | Enhanced screening | CI-scope polygraph if applicable |
Government certifying official block: name, title, org, office symbol, phone, email. Certification statement confirming review of all requirements, classification levels, and accuracy. Signature and date.
Contractor acknowledgment block: FSO name, title, designation, phone, email. Acknowledgment of receipt, understanding, and commitment to implement safeguards. Signature and date.
Apply to the DD 254 itself:
Key changes made:
development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.