CMMC and NIST 800-171
The 110 NIST 800-171 Controls, Family by Family
Most people think handling Controlled Unclassified Information (CUI) for the Department of Defense is only about following a few rules, but Level 2 compliance demands all 110 NIST 800-171 controls. These are split into 14 families, setting the official standard for protecting CUI in non-federal systems. In this article, you will see what each family covers, how many practices belong to it, and what actions are required.
What are the NIST 800-171 controls and how are they organized?
The NIST 800-171 controls are a set of 110 specific requirements designed to protect CUI. These are grouped into 14 control families. If your organization is subject to DFARS 252.204-7012, you must implement all 110 controls at Level 2 and post your self-assessment score in the Supplier Performance Risk System (SPRS). Each control is supported by assessment objectives in NIST SP 800-171A, and every objective must be met for the control to be considered satisfied.
What does each NIST 800-171 control family require?
Below you will find each control family, the number of Level 2 practices, and a summary of what you need to address.
Access Control (AC), 22 practices
Access Control is the largest family, with 22 practices. It requires you to limit system access to authorized users, control remote access, manage session timeouts, and enforce the principle of least privilege. You must also control access to CUI on portable media and within shared resources.
Awareness and Training (AT), 3 practices
This family requires you to ensure that users are aware of security risks and their responsibilities. You must provide regular security training and make sure users can recognize and report potential security incidents.
Audit and Accountability (AU), 9 practices
Audit and Accountability is about generating, protecting, and reviewing audit logs. You need to track user actions, protect audit information from unauthorized access or modification, and regularly review logs for suspicious activity.
Configuration Management (CM), 9 practices
Here, you must establish and enforce baseline configurations for your systems. This includes managing changes, tracking system components, and preventing unauthorized software installation.
Identification and Authentication (IA), 11 practices
This family requires you to identify and authenticate users and devices before granting access. You need strong password policies, multifactor authentication in certain situations, and controls to prevent password reuse or sharing.
Incident Response (IR), 3 practices
Incident Response covers your ability to prepare for, detect, report, and respond to security incidents. You must have documented procedures, test your response capability, and track incidents to closure.
Maintenance (MA), 6 practices
Maintenance controls require you to manage the maintenance of systems, both on-site and remotely. You must document maintenance activities, control remote maintenance sessions, and verify the effectiveness of maintenance procedures.
Media Protection (MP), 9 practices
This family covers protecting CUI on digital and non-digital media. You must limit access to media, sanitize or destroy media before disposal or reuse, and control the transport of media containing CUI.
Physical Protection (PE), 6 practices
Physical Protection focuses on limiting physical access to systems and CUI. You must control entry to facilities, escort visitors, monitor physical access, and protect equipment from unauthorized physical access.
Personnel Security (PS), 2 practices
Personnel Security requires you to screen individuals before authorizing access to CUI and to ensure CUI is protected when personnel leave or change roles.
Risk Assessment (RA), 3 practices
Risk Assessment requires you to perform security risk assessments, scan for vulnerabilities, and remediate identified risks in a timely manner.
Security Assessment (CA), 4 practices
This family covers regular assessment of your security controls, developing and updating your System Security Plan (SSP), and correcting deficiencies through Plan of Action and Milestones (POA&M).
System and Communications Protection (SC), 16 practices
System and Communications Protection is the second largest family. It requires you to monitor, control, and protect communications at system boundaries. This includes encrypting CUI in transit, isolating CUI systems, and controlling public network connections.
System and Information Integrity (SI), 7 practices
This family focuses on identifying and correcting flaws in your systems. You must monitor for malicious code, update systems promptly, and respond to security alerts and advisories.
How do I know if all 110 NIST 800-171 controls apply to my company?
If you process, store, or transmit CUI for the Department of Defense, all 110 controls apply to your CUI assets. Security Protection Assets are assessed against the controls relevant to their security function. Other assets, such as Contractor Risk Managed Assets and Specialized Assets, have a more limited scope but still require documentation and review. You are expected to provide four key scoping artifacts for assessment: a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List.
What is the current status of NIST 800-171 and CMMC requirements?
As of July 2026, the requirement for a third-party CMMC Level 2 certification before award is suspended pending a strategic review. However, DFARS 252.204-7012 is still in force. You must continue with annual self-assessments, SPRS score postings, and senior official affirmation. There is no CMMC certification deadline in effect at this time. The self-assessment and affirmation process now carries increased False Claims Act exposure for inaccurate reporting, as the senior official’s signature is the sole assurance in the absence of third-party certification.
What documentation and evidence are required for NIST 800-171 controls?
Policy defines your intent, procedure describes how you achieve it, and evidence is generated through real, timestamped system artifacts. Documentation alone is not sufficient. You must be able to prove execution through system records and logs. Assessors will validate that your controls are more than documented but also operating as intended.
What are the common challenges with NIST 800-171 controls?
Many organizations struggle with completing their System Security Plan (SSP) and Plan of Action and Milestones (POA&M) documentation. The average SPRS score in the defense industrial base is about 60 out of the required 110 for full compliance. Fewer than half of companies have completed SSP or POA&M documentation, which increases compliance risk. Budgeting for gap assessment, remediation, documentation, and ongoing consulting is also a significant challenge for small and mid-sized businesses.
Common questions
Do I need to implement all 110 NIST 800-171 controls if I only handle a small amount of CUI?
Yes. If you process, store, or transmit CUI, all 110 controls apply to your CUI assets. Scoping may reduce requirements for some specialized or non-CUI assets, but you must justify any exclusions.
What happens if my self-assessment score is not 110?
You are required to post your score in SPRS and update your POA&M to address any gaps. However, inaccurate or inflated scores can result in False Claims Act liability, especially now that the senior official’s affirmation is the primary assurance mechanism.
Is third-party CMMC certification required right now?
No. As of July 2026, third-party CMMC Level 2 certification before award is suspended pending review. Self-assessment and government-led assessments are still required under DFARS 252.204-7012.
Where can I get help with a NIST 800-171 gap assessment?
If you are a defense contractor and need to assess your readiness against all 110 NIST 800-171 controls, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services. This grant covers a full review of all 110 controls for qualifying organizations and can help you identify gaps, strengthen your documentation, and prepare for assessment.
How Can You Prioritize NIST 800-171 Controls
Understanding and implementing all 110 NIST 800-171 controls is critical for protecting CUI and maintaining compliance with DFARS 252.204-7012. If you need help getting started, consider applying for the Cyber Grants Alliance in kind CMMC Gap Assessment Grant. This service-based grant covers a complete review of all 110 controls for qualifying defense contractors, helping you build confidence in your compliance posture and prepare for future assessments.