NIST SP 800-171 readiness for DoD contractors who handle CUI.
NIST 800-171 defines the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. If you store, process, or transmit CUI on behalf of the Department of Defense, this standard is the baseline you must meet — and it is the foundation of CMMC Level 2.
What is NIST 800-171?
NIST Special Publication 800-171 provides 110 security requirements across 14 control families. It is mandated through DFARS 252.204-7012 and related clauses for contractors and subcontractors that manage CUI.
Compliance is not a paperwork exercise — it requires technical safeguards, operational processes, and documented evidence that your controls are implemented and effective.
Who needs it?
- DoD prime contractors handling CUI in internal systems.
- Subcontractors flowing down CUI requirements from primes.
- Managed service providers supporting federal or defense clients.
- Engineering, manufacturing, and software vendors in the defense industrial base.
The 14 control families
Each family includes detailed requirements and assessment objectives. Together they cover governance, technical safeguards, and operational security practices.
Access Control (AC)
Restrict system access to authorized users, devices, and transactions.
Awareness & Training (AT)
Ensure personnel understand security responsibilities and threats.
Audit & Accountability (AU)
Log, review, and retain records of system activity.
Configuration Management (CM)
Baseline and control system configurations and changes.
Identification & Authentication (IA)
Verify user identities and manage credentials securely.
Incident Response (IR)
Prepare for, detect, and respond to security incidents.
Maintenance (MA)
Control system maintenance and protect maintenance tools.
Media Protection (MP)
Safeguard and properly handle physical and digital media.
Physical Protection (PE)
Limit physical access to systems, equipment, and facilities.
Personnel Security (PS)
Screen, manage, and separate personnel with system access.
Risk Assessment (RA)
Assess risks, vulnerabilities, and likelihood of compromise.
Security Assessment (CA)
Assess controls and maintain system security plans.
System & Communications Protection (SC)
Protect data in transit and at rest across networks.
System & Information Integrity (SI)
Monitor, remediate, and guard against malicious code.
NIST 800-171 and CMMC 2.0
CMMC Level 2 is built directly on the 110 NIST 800-171 requirements. If you can demonstrate full implementation of those controls, you are already aligned to the technical expectations for Level 2.
The difference is the assessment method: CMMC brings an official certification process with defined scoping, evidence expectations, and assessment oversight.
CMMC Level 2 = NIST 800-171
Level 2 requires the full set of NIST 800-171 practices. Contracts determine whether you can self-assess or must complete a third-party assessment.
Self-assessment vs. C3PAO assessment
Some contracts allow a self-assessment with an annual affirmation. Others require a certified third-party assessment by a C3PAO. The contract language dictates which path you must follow, but both demand evidence, validated controls, and updated documentation.
Self-assessment
- Internal validation against the 110 requirements.
- Annual affirmation of compliance and evidence retention.
- Still requires an SSP, POA&M, and SPRS score submission.
Third-party (C3PAO)
- Independent assessment with validated artifacts and interviews.
- Formal findings report, remediation window, and final score.
- Certification required for prioritized contracts and programs.
SPRS scoring explained
Your SPRS score reflects how closely your environment meets NIST 800-171. The score starts at 110 and deductions are taken for each unmet requirement, resulting in a score that can fall below zero. Scores and associated POA&Ms are submitted to the Supplier Performance Risk System (SPRS) and are required for many DoD awards.
What assessors expect
- Evidence that each requirement is implemented and documented.
- Traceability from controls to policies, procedures, and artifacts.
- Risk-based POA&Ms with realistic completion dates.
How BMT helps you achieve compliance
Blue Mantle Technology delivers practical, evidence-driven compliance programs for the defense industrial base. We align your people, process, and technology to NIST 800-171 and prepare you for CMMC certification.
Executive readiness briefings and compliance roadmaps
SSP and POA&M development aligned to assessment objectives
Technical control implementation and hardening support
Mock assessments and evidence package preparation
Ready for a clear path to compliance?
Schedule a no-cost gap assessment and get a prioritized roadmap for NIST 800-171 and CMMC Level 2 readiness.