sha3:5bb790e86688ac7b9d66688d80160f9c03b9b73b9f288fa45650c64d19046851Intactaff2611bd0ac4a6063b7837458a4fd3f0bae5eed8d277098707a192e6c92e4b9prev:16a60f665d9cRegisterGlossary
What is NIST SP 800-171?
NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2.
7a6acaf1e5f2fbba0cf82db6d55e5dca9628dad649557301ddd8bd3103c185f5prev:aff2611bd0acNIST Special Publication 800-171 defines 110 security requirements across 14 control families, from Access Control to System and Communications Protection. CMMC Level 2 is, in practice, an assessment against these 110 controls.
Revision 2 remains the assessment baseline under DoD's current class deviation. Revision 3 restructures the families and introduces Organization-Defined Parameters, but CMMC has not yet moved its assessment baseline to Rev 3.
Each control is scored, and unimplemented controls subtract points from a maximum of 110 — which is how an environment that feels 'mostly compliant' can produce a deeply negative SPRS score.
5bb790e86688ac7b9d66688d80160f9c03b9b73b9f288fa45650c64d19046851prev:7a6acaf1e5f2Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended