Federal & defense · NIST / DFARS 252.204-7012
NIST SP 800-171 Rev 2 (110 controls)
The 110 controls behind CMMC Level 2 and every DFARS 7012 contract. Rev 2 remains the contractual baseline.
Who it applies to
The businesses that carry NIST 800-171, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
CMMC Level 2 Gap Readiness Package
Defense manufacturers, engineering and design firms, and IT and service suppliers of 10 to 300 people handling CUI
CMMC Self-Assessment and SPRS Score Calculation
Suppliers who need a current, defensible SPRS score now and a clear path toward Level 2 later
Mock Audit Package: SOC 2, HIPAA or CMMC
Organizations within 90 days of a SOC 2 audit, an OCR inquiry or a C3PAO assessment, and any leadership team that wants to know before it counts
What it asks for
In plain English, what NIST 800-171 expects you to have in place.
- Fourteen control familiesAccess control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
- A defined CUI boundaryThe systems, people and locations in scope, and the flow of controlled information between them.
- A System Security PlanHow each of the 110 requirements is implemented in your environment.
- A Plan of Action and MilestonesWhat is not yet met, who owns it and when it closes.
- A self-assessment score in SPRSPosted and current under DFARS 252.204-7019 and 7020.
- Flow-down to suppliersThe same requirements passed to subcontractors and cloud providers that touch CUI.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
CMMC in more detail: the certification path · what drives the cost · the 12-item checklist · what the C3PAO assessment looks like · the enclave question
Questions we get about NIST 800-171
Do you certify NIST 800-171 compliance?
Where do we start with NIST 800-171?
We also need other frameworks. Do we do NIST 800-171 separately?
Also in federal & defense: CMMC 2.0 · CJIS 6.0 · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for NIST 800-171.
Book the demo and see how one control set carries NIST 800-171 and everything else you owe. Or leave your details and an engineer replies within one business day.