CMMC Phase II Suspension FAQs
On Monday, July 13th, the DOW announced the immediate suspension of CMMC Phase II requirements, pausing the planned requirement for many contractors to obtain a
CMMC starts outside IT. Free webinar June 30 @ 12PM ET. Register Now →
Home » Cybersecurity Compliance » CMMC Compliance » What is NIST 800-171?
Are you compliant?
For contractors and subcontractors operating within the Defense Industrial Base (DIB), understanding the specific cybersecurity guidelines of the National Institute of Standards and Technology is the first step toward federal contract eligibility.
NIST SP 800-171 Rev. 2 is a set of 110 security requirements established to protect Controlled Unclassified Information (CUI) in non-federal systems. As the technical foundation for the Cybersecurity Maturity Model Certification (CMMC), compliance is mandatory for DoD, GSA, and NASA contractors to safeguard sensitive information and win federal contracts.
Since DFARS 252.204-7012 mandates compliance with NIST 800-171, contractors must implement these requirements to be eligible for Department of Defense contracts.
CMMC Level 2 is directly based on NIST 800-171, meaning that full compliance is necessary for companies seeking CMMC Level 2 certification.
NIST 800-171 establishes strong cybersecurity best practices to protect sensitive CUI from cyber threats and adversaries.
DFARS are a set of regulations designed to ensure defense contractors maintain adequate cybersecurity measures. We cover the ins and outs of DFARS requirements here.
What About NIST 800-171 Rev 3?
Getting Started with NIST 800-171 Compliance
First, check out our article, “What is SPRS” for a quick guide on SPRS, how to create an account, and how to submit your data. SPRS is a risk management tool that helps organizations meet Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7019 and 252.204-7012 compliance. Once you have established the appropriate account access in the SPRS, it’s time to take the assessment. Often – when a company commences completion of the self-assessment, they aren’t sure what to do and may not understand what is being asked with the controls.
The simple answer is – a company should determine if each control is implemented, partially implemented, or not implemented. The assessment score starts at a perfect 110, and points are deducted for each area of deficiency for a possible score of negative 203. The controls are weighted at 1 point, 3 points, or 5 points, depending on their criticality.
To complete the assessment, it is imperative that your organization understands what the controls mean in order to determine if they are implemented in your environment. This can be tricky if you aren’t a cyber pro. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) curated a list of the top NIST 800-171 requirements that have been determined as other than satisfied (OTS) during DIBCAC assessments.
Below, find a deep dive into four of those most commonly non-compliant controls to help you get on track; Multi-factor authentication, Risk Assessment, Incident Response, and FIPS Validated Encryption.
1. Identification and Authentication (IA) 3.5.3 – Multi-Factor Authentication
To protect CUI, it’s important to limit access to authorized users, to do this effectively you need to verify the identity of those users. That is where multi-factor authentication comes into play. Multi-factor Authentication is the means used to confirm the identity of a user, process, or device, a system which requires more than one distinct authentication factor for successful authentication. Multi-factor authentication includes three factors; something you know, such as passwords and personal identification numbers; something you have, such as a cryptographic identification device token; or something you are, such as biometrics. Authentication uses two or more different factors to achieve authentication.
2. Risk Assessment (RA) 3.11.1 – Periodically Assess Risk
The DoD expects organizations handling CUI to annually assess organizational risk as a means of keeping information safe. So, what are the best practices your organization should consider implementing to comply with this control? First, the control references “periodic” assessments. These should be conducted at a minimum of an annual basis to support the development of a risk management plan. Consider the following as part of your risk assessment process:
3. Incident Response (IR) 3.6.3 – Test Your Incident Response Capabilities
The Incident Response requirements within the NIST 800-171A and Cybersecurity Maturity Model Certification (CMMC) v2.0 framework requires an organization seeking certification to establish and test an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
With ever-evolving threats, incident response testing capabilities have become necessary components of information security programs. IR testing can include tabletop exercise, functional exercises, and tests which simulate attacks to examine your incident response procedures:
4. System Communications & Protection (SC) 3.13.11 – FIPS Validated Encryption
This is number one on DIBCAC’s list of most commonly non-compliant controls, and for good reason. A FIPS-validated cryptographic module is one that has been tested and approved by a NIST-approved laboratory per the Federal Information Processing Standard (FIPS) 140-2 U.S. Government standard. The NIST 800-171 control 3.13. 11 requires FIPS-validated cryptography to be used when protecting the Controlled Unclassified Information – whether you are storing it in your system(s) or transmitting it across the internet. Cryptography is the use of mathematical algorithms to ensure secure data communication. Encryption is the process of applying a cryptographic algorithm on data to transform into a new form that only an authorized party is able to understand. It’s like wrapping that sensitive information up in a bubble so that only desired and authorized recipients of the data can access it.
So, how do you comply with this standard? You will need to implement FIPS Validated Encryption in your systems that handle CUI. You will need to document this in policy, process and procedural documents – AND in your System Security Plan. BitLocker is an example of a FIPS-validated system, but it requires a setting before encryption that ensures that the encryption meets the standards set forth by FIPS 140-2.
Implementing the 110 controls of NIST 800-171 is a significant undertaking that requires thorough documentation and technical verification. Below are the answers to the most common questions contractors have when starting their compliance journey.
NIST 800-171 is the set of security requirements (the "what"), while CMMC is the certification program (the "proof") used to verify that a contractor has implemented those requirements. Under CMMC 2.0, Level 2 compliance is directly aligned with the 110 controls found in NIST 800-171.
Any non-federal organization—including manufacturers, universities, and service providers—that handles, stores, or transmits Controlled Unclassified Information (CUI) as part of a government contract must comply with NIST 800-171 requirements.
The 110 controls are organized into 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.
Yes. A System Security Plan (SSP) describes how your organization meets each NIST 800-171 requirement. A Plan of Action and Milestones (POA&M) outlines the steps you will take to correct any security "gaps" identified during your assessment. Both are mandatory documents.
Defense contractors must perform a self-assessment and upload their score to the Supplier Performance Risk System (SPRS). This score indicates to the Department of Defense how many of the 110 NIST 800-171 controls your organization has successfully implemented.
Performing a self-assessment for 110 technical controls is a high-risk task if your internal team is already stretched thin. Alluvionic provides professional gap analysis and remediation services to ensure your NIST 800-171 implementation is accurate, documented, and ready for audit.
We’ve helped dozens of companies complete the NIST Basic Assessment. Our experts guide you through each control, assess your score, document compliance, and provide clear next steps. If you’re looking to learn more, check out our articles on the basics of CMMC or What is SPRS.
Let’s talk about how Alluvionic can support your goals.
On Monday, July 13th, the DOW announced the immediate suspension of CMMC Phase II requirements, pausing the planned requirement for many contractors to obtain a

As the November CMMC deadline approaches, many organizations are accelerating their compliance efforts. Yet one of the most common—and costly—mistakes organizations make is treating CMMC

CMMC conversations across the Defense Industrial Base have entered a new phase. Certification requirements are now formally established, and organizations are currently grappling with timing,
It’s simple. A project that gets off on the right foot is likely to take a successful journey. So why do so many projects fail? Use this checklist to assure your project succeeds from the beginning.
Whether you need project management, process improvement, cybersecurity, product development, training, or government services, Alluvionic has the expertise to provide Peace of Mind and Project Assurance®.