SOLUTIONS // NIST 800-171

Rev. 2 live. Rev. 3 mapped. Not at audit time.

The July 2026 CMMC interim baseline is NIST SP 800-171 Rev. 2: 110 requirements across 14 families. PolicyCortex validates that baseline continuously, captures evidence, remediates drift, and maintains a Rev. 3 crosswalk so current obligations and transition planning stay distinct.

Current PolicyCortex compliance workspace showing framework posture and prioritized policy findings in the production demo tenant
Current product · /governance/compliance · demo tenant
MISSION READINESS
STANDARD
REV. 2 + 3
MAPPED
REV. 2
110 / 110
VALIDATED
FAMILIES
14
MAPPED
OPERATIONS
24 / 7 LIVE
ACTIVE
LIVE OPS // SAMPLE TENANT
STREAM
14:22:09okevidence.captured control=3.1.1 family=AC status=PASS hash=4b3a…ce19
14:22:11infocontrol.validated control=3.3.8 family=AU finding=none
14:22:14warndrift.detected control=3.13.11 family=SC severity=HIGH
14:22:15okremediation.applied control=3.13.11 action=enforce-tls-1.2 gates=3/3
14:22:18infossp.section.regenerated family=IA controls=11 output=docx
14:22:21okpoam.updated open=0 closed=12 retention=7y
CAPABILITIES
  1. CAP-01
    Rev. 2 baseline coveredAll 110 requirements across the 14-family CMMC interim baseline.
  2. CAP-02
    Rev. 3 deltas trackedRev. 2 → Rev. 3 mappings kept explicit; evidence is not relabeled.
  3. CAP-03
    Auto-SSP narrativesGenerated from live state. Always current, never stale.
  4. CAP-04
    CUI scope respectedControls only enforced where CUI lives.
  5. CAP-05
    Auto-remediationDrift fixed with rollback-safe actions. Type-checked.
  6. CAP-06
    POA&M liveFindings open → closed with closure evidence.
OPERATIONS · 30-DAY PILOT
  1. 01
    ScopeCUI boundary defined. Resources mapped to control families.
  2. 02
    BaselineAll 110 controls validated. SSP narratives auto-drafted.
  3. 03
    MaintainContinuous validation. POA&M updates as findings cycle.
FIELD-TESTED · FOUNDER OPERATED AT
  1. DOE National LabActive consultant
  2. MITRECybersecurity engineering
  3. USAAFinancial-grade ops
  4. FrontierProduction cloud architecture
CLEARANCES · PATENTS
DoD SECRETDoE Q

Founder runs every engagement personally. 4 U.S. patent applications filed.

FAQ

Rev 2 vs Rev 3?

NIST published Rev. 3 in May 2024 and reorganized the requirement structure. The Department's July 2026 CMMC suspension release names Rev. 2 as the interim enforcement baseline. PolicyCortex tracks both without presenting Rev. 3 as the 110-requirement CMMC baseline.

Connection to CMMC?

During the reform review, the Department says it will enforce NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments. The same live-state evidence can be cross-walked for Rev. 3 transition planning.

Self-assessment vs C3PAO?

Both supported. Self-attestation uses the same evidence; C3PAO assessment uses the OSCAL bundle and auditor ZIP.

What about NIST 800-172?

Enhanced security requirements for high-value assets. Mapped as an L3-overlay on top of the 110 baseline controls.

PROCUREMENT · NEXT STEP

Run the baseline as a runtime. Not a spreadsheet.

$15,000 flat for the 30-day pilot. All 110 Rev. 2 requirements baselined and continuously validated, with a separate Rev. 3 transition crosswalk.