CAPITALCYBER

NIST SP 800-171

The 110 controls, and what they ask of a company your size.

CMMC Level 2 does not invent requirements. It assesses your implementation of NIST SP 800-171 against the objectives in 800-171A. Understanding that relationship is most of understanding CMMC.

The fourteen families

AC · Access Control

22 controls. Who can reach CUI, from where, and on what. Usually the largest family and the one scope decisions most affect.

AT · Awareness and Training

3 controls. Role-based training with records. Cheap to do and routinely missing its evidence.

AU · Audit and Accountability

9 controls. Logging, retention and review. Retention needs elapsed time, so it cannot be fixed late.

CM · Configuration Management

9 controls. Baselines, change control and least functionality. Where a documented baseline earns its keep.

IA · Identification and Authentication

11 controls. Multi-factor, password policy and identity. Frequently already met and rarely evidenced.

IR · Incident Response

3 controls, plus the DFARS 72-hour reporting obligation that sits alongside them and stays yours.

MA · Maintenance

6 controls. Including remote maintenance and how equipment leaves your premises.

MP · Media Protection

9 controls. Media marking, transport, sanitisation and backup. Backups are a common outright gap.

PE · Physical Protection

6 controls. Visitors, escorting and physical access records. A site diagram usually resolves several at once.

PS · Personnel Security

2 controls. Screening, and access removal on termination. Offboarding evidence is the usual weak point.

RA · Risk Assessment

3 controls. Including vulnerability scanning, which needs scan history and therefore needs starting early.

CA · Security Assessment

4 controls. The SSP, the POA&M and periodic self-assessment. The documents an assessor opens first.

SC · System and Communications Protection

16 controls. Boundary protection, encryption and the architecture your enclave decision drives.

SI · System and Information Integrity

7 controls. Flaw remediation, malicious code protection and monitoring.

The three that have a clock on them

Most controls can be implemented and evidenced inside a working session. Three cannot, because they need history: vulnerability scanning under RA, audit log retention under AU, and training records under AT. Each of those only proves itself over elapsed time.

If you take one thing from this page, take that. Start those three the week you decide to pursue Level 2, even if nothing else has begun, because a day not scanned in August cannot be recovered in October.

Ask us about the three with a clock.

If you are inside six months of a deadline, those are the conversation. Everything else can be sequenced afterwards.

If you are a defense supplier under 25 people, start with the grant. Cyber Grants Alliance, a nonprofit, awards a fully funded gap assessment. It costs you nothing and you are under no obligation to buy anything afterwards, from us or from anyone.