sha3:e91875c903446ba8ea2c1873604d36e72385c718d246901731f7c8be369d0bd3IntactNIST SP 800-171 Rev. 2 / Rev. 3 crosswalk / NIST SP 800-172
NIST 800-171 compliance evidence, ready for review.
NIST SP 800-171 Rev. 2 is the interim CMMC baseline: 110 requirements across 14 families. PolicyCortex keeps one evidence base for all 110, hash chained inside your tenant, with the Rev. 3 crosswalk held as an explicit mapping, so current obligations and transition planning stay distinct and every row can be recomputed by the assessor.
24c754a0dc838d0ac4aefb07bcf0547bc40389bb2b74c690b83e37e7a1873dd7prev:4e1d8e79adf4What the 110 requirements ask you to prove
The July 2026 CMMC suspension release names NIST SP 800-171 Rev. 2 as the interim enforcement baseline: 110 requirements across 14 families, enforced through self-assessments and selected government-led assessments. NIST published Rev. 3 in May 2024 and reorganized the requirement structure; it is not the 110-requirement CMMC baseline.
For each requirement the obligation is the same: show the technical state that satisfies it as of the assessment date, show what changed it and under what authority, and show that the SSP narrative and the POA&M describe the environment that actually exists, not the one someone remembers.
- 171.baseline
- Rev. 2, 110 requirements, 14 families: AC, AT, AU, CA, CM, IA, IR, MA, MP, PS, PE, RA, SC, SI.
- 171.rev3
- Kept as an explicit crosswalk. Evidence is not relabeled; Rev. 3 transition planning is a separate mapping over the same rows.
- 171.scope
- Controls are evidenced where CUI lives. The declared boundary is a field on every record.
- 171.172
- NIST SP 800-172 enhanced requirements are mapped as an overlay on the 110 baseline controls for Level 3 programs.
- 171.source
- Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
c94d573111a7d8db7991430d1014d7eca5351ed72ddf79c872b4cf532b448a94prev:24c754a0dc83The evidence produced for all 110 requirements
One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached. Where each proof files:
- AC · IA · SC · SI
- Proof of state: the configuration that satisfies each technical requirement, captured from the provider APIs, content hashed, and regenerable to any date inside retention.
- CM · AU · MA
- Proof of change: every alteration to a CUI-scope resource with actor, authority, before and after hashes, and a rollback identifier, on an append-only chain.
- Machine actions
- Proof of agency: what an autonomous action was permitted to do before it ran, what it did, and what would have stopped it.
- SSP · POA&M
- Narratives and open items generated from the same implementation record, so the document and the environment cannot drift apart unnoticed.
- CMMC Level 2 · SPRS
- The same rows serve the self-assessment score you affirm and the C3PAO assessment, as OSCAL 1.1.2 and an assessor handoff package.

Exhibit SB-12 · every one of the 110 requirements in one of five honest states, with the automatic fixes the envelope permits flagged per control. Illustrative demo data; the interface is real.
994fb26d4f2a88112a65b6038dc14da5b115270f685f9a08f375e6f8b2f92c5bprev:c94d573111a7How the record is verified against Rev. 2
Because the Rev. 3 crosswalk is a separate mapping over the same rows, the recomputation proves the Rev. 2 evidence was never relabeled: the digests belong to the requirement text in force when they were written.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
e15cddae6eae9ceb9ed55d992d01c5ee33c14b566d55683039d40f08108c9f7cprev:994fb26d4f2aAccess and scope for the 14 families
During agreed read-only onboarding, captures file against the 14 families with the CUI boundary declared on each record. The Rev. 2 evidence base and its Rev. 3 crosswalk can both be recomputed from those records.
Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
574b4bea65cf3ee84ecb30724c45b4e1cadf6278bc659dcd756a3ef14e080be0prev:e15cddae6eaeDelivery, if you want the record stood up for you
If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.
- engagement.price
- $15,000 flat for the standard engagement scope. No hourly, no overages.
- engagement.scope
- 30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
- engagement.package
- SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
- engagement.review
- In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.
e91875c903446ba8ea2c1873604d36e72385c718d246901731f7c8be369d0bd3prev:574b4bea65cfQuestions assessors and buyers ask
What evidence supports a NIST 800-171 assessment?
Start with the CUI system boundary, an accurate System Security Plan, and evidence tied to each applicable requirement. Technical configuration records, policies, interviews, and assessment results support different parts of the review. Track unmet requirements in a POA&M where permitted. Software organizes the record; the organization remains responsible for implementation and accurate reporting.
Rev. 2 or Rev. 3?
NIST published Rev. 3 in May 2024 and reorganized the requirement structure. The Department's July 2026 CMMC suspension release names Rev. 2 as the interim enforcement baseline. PolicyCortex tracks both without presenting Rev. 3 as the 110-requirement CMMC baseline.
How does this connect to CMMC?
During the reform review, the Department says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments. The same evidence base is cross-walked for Rev. 3 transition planning.
Self-assessment or C3PAO?
Both rest on the same evidence. A self-assessment uses the rows behind the SPRS score you affirm; a C3PAO assessment uses the OSCAL bundle and the assessor handoff package.
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
What about NIST SP 800-172?
Enhanced security requirements for high-value assets. Mapped as a Level 3 overlay on top of the 110 baseline controls.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Run the baseline as a record, not a spreadsheet.