CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

NIST SP 800-171

What are the 110 NIST SP 800-171 requirements, family by family?

NIST SP 800-171 Rev 2 contains 110 security requirements for protecting Controlled Unclassified Information in contractor systems, organized into 14 families. CMMC Level 2 uses the same 110 requirements. Knowing what each family covers, and how many requirements sit in it, makes it much easier to plan the work and to read an assessment report. This article takes the families one at a time, with the count for each and what it asks of a small defense contractor in plain terms.

How are the 110 requirements organized?

They are organized into 14 families, each covering one area of security, and each requirement is numbered by family. Within each family there are basic requirements, drawn from the federal minimum security standard, and derived requirements, drawn from the NIST SP 800-53 control catalog. NIST SP 800-171A then breaks each requirement into assessment objectives that an assessor judges one at a time.

The families vary a great deal in size. Access Control holds 22 requirements, while Personnel Security holds 2. The count is not a measure of effort, but it is a good guide to where the documentation will be heaviest.

What does Access Control (AC, 22 requirements) cover?

Access Control covers who can use the system and what they can do once they are in. It includes limiting access to authorized users and functions, least privilege, separation of duties, session lock and termination, control of remote and wireless access, mobile devices, and control of CUI posted on publicly accessible systems. It is the largest family and usually the one with the most findings.

What does Awareness and Training (AT, 3 requirements) cover?

Awareness and Training covers making sure people know the risks and their responsibilities. It requires security awareness for all users, role based training for people with security duties, and insider threat awareness, including how to recognize and report potential indicators. Records of who completed what, and when, are the usual evidence.

What does Audit and Accountability (AU, 9 requirements) cover?

Audit and Accountability covers creating, keeping and reviewing logs so actions can be traced to users. It includes deciding which events to log, reviewing and correlating logs, alerting when logging fails, synchronizing time sources, protecting logs from tampering and limiting who can manage logging. Many small contractors meet it with a managed logging service, which then becomes a Security Protection Asset.

What does Configuration Management (CM, 9 requirements) cover?

Configuration Management covers knowing what you have and keeping it in a known, secure state. It requires baseline configurations and inventories, security settings, change control with security impact analysis, least functionality, restrictions on nonessential programs and ports, and control over software users can install. Application allowlisting is a common way to meet several of these at once.

What does Identification and Authentication (IA, 11 requirements) cover?

Identification and Authentication covers proving that users and devices are who they claim to be. It includes unique identification, multifactor authentication for privileged accounts and for network access to non privileged accounts, replay resistant authentication, identifier management, password rules and protecting stored and transmitted passwords. Multifactor authentication is one of the heaviest weighted requirements in the scoring methodology.

What does Incident Response (IR, 3 requirements) cover?

Incident Response covers being ready to detect, handle and report security incidents. It requires an operational incident handling capability, tracking and reporting incidents to the right people inside and outside the company, and testing the response capability. For a DFARS 252.204-7012 contractor, reporting includes the obligation to report cyber incidents to DoD within 72 hours of discovery.

What does Maintenance (MA, 6 requirements) cover?

Maintenance covers how systems are repaired and serviced without creating a way in. It includes performing and controlling maintenance, sanitizing equipment removed for offsite maintenance, checking diagnostic media for malicious code, requiring multifactor authentication for remote maintenance sessions and supervising maintenance personnel who lack authorized access. Outside IT providers fall under this family.

What does Media Protection (MP, 9 requirements) cover?

Media Protection covers CUI on paper and on removable or portable storage. It includes protecting and limiting access to media, sanitizing or destroying it before disposal or reuse, marking it with CUI markings, controlling it during transport, encrypting CUI on digital media, controlling removable media and protecting backups. Printed drawings on a shop floor are media too.

What does Personnel Security (PS, 2 requirements) cover?

Personnel Security covers the people who will have access. It requires screening individuals before authorizing access to systems containing CUI, and protecting those systems during and after personnel actions such as terminations and transfers. In practice that means a documented screening step and an offboarding checklist that actually removes access on time.

What does Physical Protection (PE, 6 requirements) cover?

Physical Protection covers the buildings and rooms where CUI systems live. It includes limiting physical access to authorized people, protecting and monitoring the facility, escorting and monitoring visitors, keeping audit logs of physical access, controlling keys, badges and locks, and enforcing safeguards at alternate work sites such as home offices.

What does Risk Assessment (RA, 3 requirements) cover?

Risk Assessment covers understanding and reducing risk on a regular basis. It requires periodic risk assessments, scanning for vulnerabilities on a schedule and when new vulnerabilities are identified, and remediating vulnerabilities according to the risk they pose. The scan reports and the record of what was fixed are the evidence.

What does Security Assessment (CA, 4 requirements) cover?

Security Assessment covers checking your own controls and planning the fixes. It requires periodic assessment of whether controls are effective, plans of action to correct deficiencies, ongoing monitoring of controls, and a System Security Plan that describes the boundary, the environment and how each requirement is met. The SSP and POA&M live here.

What does System and Communications Protection (SC, 16 requirements) cover?

System and Communications Protection covers the network and the data moving through it. It includes boundary protection, network segmentation, deny by default traffic rules, preventing split tunneling, encrypting CUI in transit, FIPS validated cryptography where cryptography protects CUI, session authenticity, control of collaborative devices and mobile code, and protecting CUI at rest. Enclave design decisions show up mostly in this family.

What does System and Information Integrity (SI, 7 requirements) cover?

System and Information Integrity covers finding and fixing flaws and catching malicious activity. It requires timely flaw remediation, malicious code protection that is updated and runs scans, monitoring of security alerts and advisories, and monitoring systems and traffic to detect attacks and unauthorized use. Patch records and endpoint protection reports are the usual evidence.

Where should a small contractor start?

Start with scope, then with the requirements that carry the most weight and the most findings: multifactor authentication, encryption, logging, boundary protection, and the System Security Plan itself. Those are the gaps that cost the most points and the ones assessors look at first.

Then work family by family with a named owner for each, collecting evidence as each requirement is implemented. A contractor that can show who owns each family, how each requirement is met and where the evidence lives is in a far better position than one with good technology and nothing written down.

Which engagements cover this?

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

C3PAO readiness and mock assessment

CMMC Level 2 mock assessment and C3PAO readiness, including C3PAO selection, for defense contractors preparing for certification.

What else do readers ask?

Are the 110 requirements the same for CMMC Level 2 and DFARS 7012?

Yes. Both use the 110 requirements of NIST SP 800-171 Rev 2. CMMC Level 2 adds the structure for assessing, scoring and affirming them.

Which family usually has the most findings?

Access Control, which is also the largest family with 22 requirements. System and Communications Protection and Audit and Accountability are also common sources of findings.

What is an assessment objective?

NIST SP 800-171A breaks each requirement into specific objectives that an assessor judges as met or not met. A requirement is met only when all of its objectives are.

Does NIST SP 800-171 Rev 3 replace Rev 2 for CMMC?

The CMMC program rule references Rev 2, so Level 2 assessments are performed against Rev 2. Check your contract clauses for the revision that applies to you.

This article is general information about the regulations as written, not legal advice. Read your contract clauses and the regulation text, and take legal advice where the answer matters.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.