NIST SP 800-171

NIST SP 800-171 — 110 requirements, scoped to the environment you actually run.

NIST SP 800-171 is the control set behind DFARS 252.204-7012 and CMMC Level 2. It is not a product you buy or a box you tick: it is 110 security requirements across 14 families, and most of the work is deciding which systems they apply to before implementing anything. Cyberneza scopes that boundary, implements the requirements, and builds the evidence an assessor expects.

Score your SPRS self-assessment →

A control-by-control gap assessment against the 110 requirements carries a published fixed fee, as does the CUI Boundary Definition engagement that establishes which of them apply to you. See federal pricing →

Personal reply within one business day.

When 800-171 applies to you

  • Your contract carries DFARS 252.204-7012, or a prime has flowed it down to you.
  • You store, process, or transmit Controlled Unclassified Information (CUI).
  • You need a current SPRS score on file to remain eligible for DoD awards.
  • You are working toward CMMC Level 2, which assesses these same 110 requirements.

What people get wrong first

  • Treating it as an IT project. Roughly a third of the requirements are policy, process, and training.
  • Scoping the whole company when only a handful of systems touch CUI.
  • Writing an SSP that describes an intended environment rather than the running one.
  • Buying tooling before the boundary is drawn, then paying to license systems that were never in scope.
The standard

14 requirement families

The 110 requirements are grouped into fourteen families. They are published and public — the difficulty is never finding them, it is evidencing them consistently across a real environment.

Access & identity

Access Control, Identification & Authentication. The largest family by count, and where most scoping decisions ultimately land.

People & awareness

Awareness & Training, Personnel Security. Requirements that no tool satisfies on your behalf.

Operations

Audit & Accountability, Configuration Management, Maintenance, Media Protection.

Response & recovery

Incident Response, including the reporting obligations DFARS attaches to it.

Assurance

Risk Assessment, Security Assessment, System & Information Integrity.

Environment

Physical Protection, System & Communications Protection — including the boundary itself.

What we do

800-171 compliance support

Milestone-based and scoped to where you stand today. The right first move depends heavily on whether a boundary already exists.

CUI boundary scoping

Establish where CUI actually lives and define a defensible assessment boundary — the decision that determines the cost of everything downstream.

Gap assessment against the 110

Assess current implementation requirement by requirement and produce a written report with findings, severity, and a sequenced remediation path. See a sample report →

Control implementation

Close the gaps that matter, aligned to how your environment actually runs rather than to a generic reference architecture.

Documentation & evidence

System Security Plan, POA&M, and the operating records that show a requirement is met in practice. SSP, POA&M & SPRS support →

SPRS self-assessment support

Help you score your implementation accurately and defensibly. Your organization performs and submits the self-assessment; we help you get it right.

800-171 and CMMC are not the same thing

NIST SP 800-171 is the standard — the 110 requirements themselves. CMMC is the verification program the Department of Defense uses to check that they are met. Level 2 assesses the same 110 requirements; what CMMC adds is who verifies them and how often. You can be compliant with 800-171 and not yet certified under CMMC.

CMMC readiness → · Which CMMC level applies to you →

A note on revisions

NIST published Revision 3 of SP 800-171 in May 2024, restructuring the requirements and introducing organization-defined parameters. DoD contract clauses continue to reference the revision named in the clause, so read your contract before assuming which revision applies to you — the answer is a contractual question, not a technical one, and getting it wrong changes what you are assessed against.

Who does the work

Experience-backed, not checklist-delivered

You work directly with a Cyber AB Registered Practitioner (CPN 76768) who has implemented NIST 800-53 control families and run RMF lifecycle activities in production federal environments, backed by a network of specialist partners for specialized needs. Much of the small-contractor 800-171 market is sold by large integrators and delivered by junior staff working from a template.

Start with the boundary

Tell us about your contract, where CUI lands today, and your timeline. We will tell you honestly where you stand and what the realistic sequence looks like.