---
title: "Tag: NIST 800-171"
description: "8 blog entries tagged NIST 800-171, newest first, each with sealed and amended dates."
url: https://policycortex.com/blog/tags/nist-800-171
sealed: 2025-11-20
amended: 2026-07-13
register: blog/tags/nist-800-171
records: 3
digest: sha3:324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2
---

# Blog entries tagged NIST 800-171

Register / Blog / Tag: NIST 800-171

Every blog entry tagged NIST 800-171, newest first. Tags group the register by subject so a reader working one requirement can follow it across entries as the rules change. Each entry is sealed on the date shown and amended in place when it is updated; the full register is at the blog index.

8 entries · Latest sealed 2026-07-13

## Entries, newest first

| Sealed | Entry | Reading |
|---|---|---|
| 2026-07-13 | [CMMC Phase II Is Suspended: What Defense Contractors Still Have to Do](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now): The Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place. | 7 min |
| 2026-07-01 | [The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act Evidence](https://policycortex.com/blog/logzone-false-claims-act-sprs-score): DOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment. | 9 min |
| 2026-03-17 | [CMMC Level 2 Requirements in 2026: The Complete Guide for Defense Contractors](https://policycortex.com/blog/cmmc-level-2-requirements-2026-complete-guide): CMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active. | 14 min |
| 2026-03-10 | [NIST 800-171 Cloud Compliance: The Practical Guide for AWS, Azure, and GCP](https://policycortex.com/blog/nist-800-171-cloud-compliance-guide): Implementing NIST 800-171 in cloud environments is fundamentally different from on-premises. | 12 min |
| 2026-02-18 | [The CMMC Level 2 Self-Assessment Trap (And How to Avoid It)](https://policycortex.com/blog/cmmc-level-2-self-assessment): Most defense contractors who submit optimistic SPRS scores don't realize they're creating legal exposure, not just compliance risk. | 9 min |
| 2026-02-10 | [Cloud Misconfiguration Statistics 2026: What's Actually Breaking Defense Contractor Environments](https://policycortex.com/blog/cloud-misconfiguration-statistics-2026): Data-driven analysis of cloud misconfiguration patterns across the Defense Industrial Base: top finding categories, specific failure modes, and what the numbers tell us about effective remediation. | 8 min |
| 2026-01-14 | [NIST 800-171 Rev 3: Key Changes and How to Prepare](https://policycortex.com/blog/nist-800-171-rev-3-key-changes): NIST SP 800-171 Revision 3 brings significant changes to the security requirements for protecting CUI. | 2 min |
| 2025-11-20 | [CMMC 2.0: What Defense Contractors Need to Know](https://policycortex.com/blog/cmmc-2-what-defense-contractors-need-to-know): The CMMC program is officially active with assessments underway. | 2 min |

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Read the entries. Then verify the record they describe. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 4e0af546b46b | ba9928da042c |
| REC 0001 | ENTRIES | 07f98b1da6fe | 4e0af546b46b |
| REC 0002 | RELATED RECORDS | 324eccf9454a | 07f98b1da6fe |

Head sha3:324eccf9454a96d15f7d5a328655df4d5123fce0b44f61f32eb6bc3799dfe0d2. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
