Access & identity
Access Control, Identification & Authentication. The largest family by count, and where most scoping decisions ultimately land.
NIST SP 800-171 is the control set behind DFARS 252.204-7012 and CMMC Level 2. It is not a product you buy or a box you tick: it is 110 security requirements across 14 families, and most of the work is deciding which systems they apply to before implementing anything. Cyberneza scopes that boundary, implements the requirements, and builds the evidence an assessor expects.
Personal reply within one business day.
The 110 requirements are grouped into fourteen families. They are published and public — the difficulty is never finding them, it is evidencing them consistently across a real environment.
Access Control, Identification & Authentication. The largest family by count, and where most scoping decisions ultimately land.
Awareness & Training, Personnel Security. Requirements that no tool satisfies on your behalf.
Audit & Accountability, Configuration Management, Maintenance, Media Protection.
Incident Response, including the reporting obligations DFARS attaches to it.
Risk Assessment, Security Assessment, System & Information Integrity.
Physical Protection, System & Communications Protection — including the boundary itself.
Milestone-based and scoped to where you stand today. The right first move depends heavily on whether a boundary already exists.
Establish where CUI actually lives and define a defensible assessment boundary — the decision that determines the cost of everything downstream.
Assess current implementation requirement by requirement and produce a written report with findings, severity, and a sequenced remediation path. See a sample report →
Close the gaps that matter, aligned to how your environment actually runs rather than to a generic reference architecture.
System Security Plan, POA&M, and the operating records that show a requirement is met in practice. SSP, POA&M & SPRS support →
Help you score your implementation accurately and defensibly. Your organization performs and submits the self-assessment; we help you get it right.
Where CUI handling can be confined to an encrypted enclave, the boundary — and the bill — shrinks. GCC High & enclave planning →
NIST SP 800-171 is the standard — the 110 requirements themselves. CMMC is the verification program the Department of Defense uses to check that they are met. Level 2 assesses the same 110 requirements; what CMMC adds is who verifies them and how often. You can be compliant with 800-171 and not yet certified under CMMC.
NIST published Revision 3 of SP 800-171 in May 2024, restructuring the requirements and introducing organization-defined parameters. DoD contract clauses continue to reference the revision named in the clause, so read your contract before assuming which revision applies to you — the answer is a contractual question, not a technical one, and getting it wrong changes what you are assessed against.
You work directly with a Cyber AB Registered Practitioner (CPN 76768) who has implemented NIST 800-53 control families and run RMF lifecycle activities in production federal environments, backed by a network of specialist partners for specialized needs. Much of the small-contractor 800-171 market is sold by large integrators and delivered by junior staff working from a template.
Tell us about your contract, where CUI lands today, and your timeline. We will tell you honestly where you stand and what the realistic sequence looks like.