AccuSights
PartnersBlogAbout
Book my 30-minute demo

Federal & defense · NIST / DFARS 252.204-7012

NIST SP 800-171 Rev 2 (110 controls)

The 110 controls behind CMMC Level 2 and every DFARS 7012 contract. Rev 2 remains the contractual baseline.

One control set, every frameworkPractitioner-led, CRISC and CISAPublic pricing

Who it applies to

The businesses that carry NIST 800-171, and the pages written for them.

Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.

Which packages satisfy it

CMMC Level 2 Gap Readiness Package

Defense manufacturers, engineering and design firms, and IT and service suppliers of 10 to 300 people handling CUI

From $6,000published
Details →

CMMC Self-Assessment and SPRS Score Calculation

Suppliers who need a current, defensible SPRS score now and a clear path toward Level 2 later

Fixed feescoped in 30 minutes
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

Organizations within 90 days of a SOC 2 audit, an OCR inquiry or a C3PAO assessment, and any leadership team that wants to know before it counts

Fixed feescoped in 30 minutes
Details →

What it asks for

In plain English, what NIST 800-171 expects you to have in place.

  • Fourteen control familiesAccess control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
  • A defined CUI boundaryThe systems, people and locations in scope, and the flow of controlled information between them.
  • A System Security PlanHow each of the 110 requirements is implemented in your environment.
  • A Plan of Action and MilestonesWhat is not yet met, who owns it and when it closes.
  • A self-assessment score in SPRSPosted and current under DFARS 252.204-7019 and 7020.
  • Flow-down to suppliersThe same requirements passed to subcontractors and cloud providers that touch CUI.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

CMMC in more detail: the certification path · what drives the cost · the 12-item checklist · what the C3PAO assessment looks like · the enclave question

Or start with the 3-minute test

Questions we get about NIST 800-171

Do you certify NIST 800-171 compliance?
No. NIST / DFARS 252.204-7012 and the auditors or assessors it recognizes have the final say. We interpret the requirements for your business, scope what applies, close the gaps and keep the evidence current so the assessment or examination is a formality.
Where do we start with NIST 800-171?
With the 3-minute Cyber Hygiene Test if you want a number today, or with the 30-minute call if you want a written scope and a fixed fee. Either way the first deliverable is a gap list ranked by what would fail and what would hurt.
We also need other frameworks. Do we do NIST 800-171 separately?
No. We build one control set and map it to every framework you carry, so evidence is produced once and reused. Adding a framework later is a mapping exercise, not a second program.

Also in federal & defense: CMMC 2.0 · CJIS 6.0 · every framework by industry

Next step

Thirty minutes, an engineer, a written scope for NIST 800-171.

Book the demo and see how one control set carries NIST 800-171 and everything else you owe. Or leave your details and an engineer replies within one business day.

3-min test