Skip to content
CMMC Guidance
← Knowledge Base

One hundred and ten requirements, in fourteen families.

NIST SP 800-171 is the requirement set underneath CMMC Level 2. It is the document your score is calculated against and the document an assessor works from.

The publication defines security requirements for protecting Controlled Unclassified Information when it lives in a nonfederal system. For a defense supplier that is the practical definition of the job: these are the requirements a contract expects to be implemented, and the ones an assessment tests.

They are organised into families. The distribution is uneven and worth knowing before planning any remediation, because the families are not equally expensive and they do not fall on the same teams.

CodeFamilyReqs
ACAccess Control22
ATAwareness and Training3
AUAudit and Accountability9
CMConfiguration Management9
IAIdentification and Authentication11
IRIncident Response3
MAMaintenance6
MPMedia Protection9
PSPersonnel Security2
PEPhysical Protection6
RARisk Assessment3
CASecurity Assessment4
SCSystem and Communications Protection16
SISystem and Information Integrity7
Total110

Access Control and System and Communications Protection together account for a substantial share of the total, and they are also the two families most sensitive to how the boundary was drawn. That is the practical argument for doing scoping before remediation rather than after.

Implemented is not the same as documented

A requirement is not satisfied because a policy says it is. It is satisfied when the control is in place in the environment and there is evidence a third party can examine. The companion assessment publication defines, for each requirement, what an assessor examines, who they interview and what they test — which is why a self-assessment built from a questionnaire and a self-assessment built from the assessment objectives can produce very different numbers for the same company.

The gap between those two numbers is the single most common unpleasant surprise in this work. It is also the reason a technical assessment against the live environment is worth more than a maturity survey, however thorough the survey looks.

Revisions

There is more than one revision of SP 800-171 in circulation, and they differ in requirement structure and in how organisation-defined parameters are handled. Which revision applies to you is a function of your contract and the program rule, not of which one is newest. Confirm it before scoping work begins, because reorganising an assessment mid-engagement is expensive.

Primary sources

Reference material, not legal advice. Where a specific number, deadline or level determination affects a decision, work from the source document and your own contract language.

Need this answered for your environment?

These pages are general. The readiness call is where it gets specific to your boundary, your contracts and your actual score.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.