
A NIST 800-171 checklist lists the security requirements for protecting controlled unclassified information (CUI) on your systems and the evidence that each one is met. This checklist follows Revision 3, which NIST published in May 2024: 97 requirements in 17 families. If you are a defense contractor, CMMC Level 2 still assesses the 110 requirements of Revision 2: when we checked on October 10, 2026, the Department of War CIO's CMMC pages said the Department enforces Revision 2.
Our CMMC compliance services scope where CUI lives, build these controls and write the System Security Plan; we are not a C3PAO and certify no one. For the standard in brief, see our NIST SP 800-171 glossary entry, and for the Revision 2 families that CMMC scores, see CMMC Level 2 requirements. This is general information, not legal advice.
What does NIST 800-171 compliance mean?
It means the systems that process, store or transmit CUI meet the security requirements in NIST SP 800-171, and you can prove it. NIST writes the requirements; contracts make them binding. In defense work, DFARS 252.204-7012 required contractors to implement them by December 31, 2017, and that clause remains in effect. The CMMC program then checks them against Revision 2: during the Phase II suspension, Level 2 means a self-assessment every three years with an affirmation every year, and no new contract can require the rule's third-party C3PAO assessment.
Keep the two ideas apart. Compliance is the state of your systems. An assessment, whether your own, a government-led review or a C3PAO's, is a check of that state on a date.
Which revision should your checklist follow?
| Revision 2 | Revision 3 | |
|---|---|---|
| Published | February 2020, with updates to January 28, 2021 | May 14, 2024 |
| Status at NIST | Withdrawn May 14, 2024 | Current |
| Requirements | 110 | 97 |
| Families | 14 | 17, adding Planning, System and Services Acquisition, and Supply Chain Risk Management |
| Numbering | 3.1.1 style | 03.01.01 style |
| Organization-defined parameters | None | Values such as time periods and frequencies, set by the agency or, if it sets none, by you |
| Assessment guide | SP 800-171A, June 2018 | SP 800-171A Rev. 3, May 2024 |
| Used by CMMC Level 2 | Yes, all 110 requirements | No, as of October 10, 2026 |
If you hold defense contracts, score your self-assessment against Revision 2: 32 CFR part 170 names it, and the Department says it enforces it during the Phase II suspension. Revision 3 is still worth reading: it is NIST's current version, and its additions, such as a supply chain risk management plan, are sound practice. If you implement it now, the Department's CMMC FAQ says to use the organization-defined parameter values in its April 2025 memo and to close any gaps between the two revisions, because assessments stay on Revision 2 until the class deviation that keeps Revision 2 is withdrawn. Keep one numbering scheme in your System Security Plan, and map any Revision 3 work back to the Revision 2 requirement it supports.
How do you scope CUI before you start?
- Find the CUI. Read each contract and its flow-down clauses, look for CUI markings on drawings and specifications, and ask the prime in writing what you will receive.
- Map where it goes. Revision 3 asks you to identify and document where CUI is processed and stored and on which system components (03.04.11), and to keep a component inventory (03.04.10).
- Draw the boundary. Under 32 CFR 170.19, assets that process, store or transmit CUI are assessed against all Level 2 requirements; security tools that protect them are assessed against the requirements relevant to what they do; contractor risk managed assets and specialized assets, such as test equipment, are documented in the SSP with limited or no assessment; and assets that cannot process, store or transmit CUI, for example because they are physically or logically separated from CUI assets, and that provide no security protection for them are out of scope. An enclave that keeps CUI with a few people and systems often gives the smallest scope.
- Write it down in the System Security Plan, with the network diagram and asset inventory beside it.
NIST 800-171 Rev. 3 checklist by family
Copy this table into a spreadsheet, add columns for owner, status and evidence location, and work family by family. Requirement numbers and titles are NIST's; withdrawn numbers are skipped, and NIST's dashes in some titles are shown here as commas.
| Family | Requirements | Evidence to keep |
|---|---|---|
| 03.01 Access Control (16) | 03.01.01 Account Management; 03.01.02 Access Enforcement; 03.01.03 Information Flow Enforcement; 03.01.04 Separation of Duties; 03.01.05 Least Privilege; 03.01.06 Least Privilege, Privileged Accounts; 03.01.07 Least Privilege, Privileged Functions; 03.01.08 Unsuccessful Logon Attempts; 03.01.09 System Use Notification; 03.01.10 Device Lock; 03.01.11 Session Termination; 03.01.12 Remote Access; 03.01.16 Wireless Access; 03.01.18 Access Control for Mobile Devices; 03.01.20 Use of External Systems; 03.01.22 Publicly Accessible Content | Account list with approvals, role assignments, remote access and sign-in policies, lockout and session settings, wireless and mobile device configuration |
| 03.02 Awareness and Training (2) | 03.02.01 Literacy Training and Awareness; 03.02.02 Role-Based Training | Training records by person and date |
| 03.03 Audit and Accountability (8) | 03.03.01 Event Logging; 03.03.02 Audit Record Content; 03.03.03 Audit Record Generation; 03.03.04 Response to Audit Logging Process Failures; 03.03.05 Audit Record Review, Analysis, and Reporting; 03.03.06 Audit Record Reduction and Report Generation; 03.03.07 Time Stamps; 03.03.08 Protection of Audit Information | The event types you log, retention settings, review records, alerts on logging failures |
| 03.04 Configuration Management (10) | 03.04.01 Baseline Configuration; 03.04.02 Configuration Settings; 03.04.03 Configuration Change Control; 03.04.04 Impact Analyses; 03.04.05 Access Restrictions for Change; 03.04.06 Least Functionality; 03.04.08 Authorized Software, Allow by Exception; 03.04.10 System Component Inventory; 03.04.11 Information Location; 03.04.12 System and Component Configuration for High-Risk Areas | Baselines, change tickets with approvals, the allowed software list, the inventory, a map of where CUI lives |
| 03.05 Identification and Authentication (8) | 03.05.01 User Identification and Authentication; 03.05.02 Device Identification and Authentication; 03.05.03 Multi-Factor Authentication; 03.05.04 Replay-Resistant Authentication; 03.05.05 Identifier Management; 03.05.07 Password Management; 03.05.11 Authentication Feedback; 03.05.12 Authenticator Management | MFA enforcement for privileged and non-privileged accounts, password settings, device registration |
| 03.06 Incident Response (5) | 03.06.01 Incident Handling; 03.06.02 Incident Monitoring, Reporting, and Response Assistance; 03.06.03 Incident Response Testing; 03.06.04 Incident Response Training; 03.06.05 Incident Response Plan | The incident response plan, incident log, test record and training records |
| 03.07 Maintenance (3) | 03.07.04 Maintenance Tools; 03.07.05 Nonlocal Maintenance; 03.07.06 Maintenance Personnel | Maintenance log, remote maintenance settings, approved maintenance staff |
| 03.08 Media Protection (7) | 03.08.01 Media Storage; 03.08.02 Media Access; 03.08.03 Media Sanitization; 03.08.04 Media Marking; 03.08.05 Media Transport; 03.08.07 Media Use; 03.08.09 System Backup, Cryptographic Protection | Sanitization records, marking procedure, removable media policy, backup encryption settings |
| 03.09 Personnel Security (2) | 03.09.01 Personnel Screening; 03.09.02 Personnel Termination and Transfer | Screening records, offboarding tickets with dates |
| 03.10 Physical Protection (5) | 03.10.01 Physical Access Authorizations; 03.10.02 Monitoring Physical Access; 03.10.06 Alternate Work Site; 03.10.07 Physical Access Control; 03.10.08 Access Control for Transmission | Access lists, visitor and badge logs, remote work rules, protected cabling and network closets |
| 03.11 Risk Assessment (3) | 03.11.01 Risk Assessment; 03.11.02 Vulnerability Monitoring and Scanning; 03.11.04 Risk Response | The risk assessment, scan reports, remediation records within your set response times |
| 03.12 Security Assessment and Monitoring (4) | 03.12.01 Security Assessment; 03.12.02 Plan of Action and Milestones; 03.12.03 Continuous Monitoring; 03.12.05 Information Exchange | Assessment results, the plan of action, the monitoring strategy, exchange agreements |
| 03.13 System and Communications Protection (10) | 03.13.01 Boundary Protection; 03.13.04 Information in Shared System Resources; 03.13.06 Network Communications, Deny by Default, Allow by Exception; 03.13.08 Transmission and Storage Confidentiality; 03.13.09 Network Disconnect; 03.13.10 Cryptographic Key Establishment and Management; 03.13.11 Cryptographic Protection; 03.13.12 Collaborative Computing Devices and Applications; 03.13.13 Mobile Code; 03.13.15 Session Authenticity | Firewall rules, network diagram, encryption settings for CUI in transit and at rest, key management records |
| 03.14 System and Information Integrity (5) | 03.14.01 Flaw Remediation; 03.14.02 Malicious Code Protection; 03.14.03 Security Alerts, Advisories, and Directives; 03.14.06 System Monitoring; 03.14.08 Information Management and Retention | Patch reports against your set time period, endpoint protection coverage, alert reviews, a retention schedule |
| 03.15 Planning (3) | 03.15.01 Policy and Procedures; 03.15.02 System Security Plan; 03.15.03 Rules of Behavior | Approved policies, the System Security Plan, signed rules of behavior |
| 03.16 System and Services Acquisition (3) | 03.16.01 Security Engineering Principles; 03.16.02 Unsupported System Components; 03.16.03 External System Services | Design notes, a list of unsupported components with replacement plans, provider agreements |
| 03.17 Supply Chain Risk Management (3) | 03.17.01 Supply Chain Risk Management Plan; 03.17.02 Acquisition Strategies, Tools, and Methods; 03.17.03 Supply Chain Requirements and Processes | The supply chain risk plan, supplier security requirements, purchasing records |
What changed from Rev. 2 to Rev. 3?
- Structure. Seventeen families instead of fourteen, with Planning, System and Services Acquisition, and Supply Chain Risk Management added, and some Revision 2 requirements withdrawn or merged. The old System Security Plan requirement, for example, is now part of 03.15.02.
- Parameters. Many requirements now contain organization-defined parameters, such as how quickly security updates must be installed (03.14.01). NIST says that if an agency does not set a value, the organization must.
- Precision. Some requirements now say exactly what is expected. 03.05.03, for example, requires multifactor authentication for access to both privileged and non-privileged accounts.
NIST publishes a change analysis spreadsheet that compares the two revisions line by line, and an August 2025 small business primer, SP 1318, that introduces Revision 3 for owners.
How do you assess NIST 800-171 compliance?
SP 800-171A sets out the assessment procedures. Its assessment methods are examine (reviewing documents and configurations), interview (talking with the people involved) and test (exercising a mechanism to compare actual with expected behavior). Each requirement is broken into assessment objectives, and each objective is found satisfied or other than satisfied, so your evidence has to cover every objective, not only the headline requirement.
For a CMMC Level 2 self-assessment, the rule specifies the June 2018 SP 800-171A and the scoring method in 32 CFR 170.24: start at 110, subtract 5, 3 or 1 points for each requirement not met, and the total can fall below zero. Results go into SPRS, a senior official affirms them, and the evidence must be kept for six years.
Who maintains the checklist, and how often?
The system owner keeps it, with named owners for each family. Update it whenever the boundary, a system or a provider changes, and on the review frequencies you set for your organization-defined parameters. For CMMC, the rhythm is fixed: an affirmation every year and a Level 2 self-assessment every three years.
How does NetSys help with NIST 800-171?
We start from the data: where CUI arrives, who opens it, where it is stored and where it goes next. From there we draw an enclave boundary, run a gap assessment with a scored, prioritized remediation plan, and implement the requirements inside the boundary, from identity and MFA to logging and incident response. The System Security Plan is written from the configuration we deployed, open items go on a plan of action within the limits the CMMC rule allows, and evidence is organized by requirement. Cloud services that hold CUI must be FedRAMP Moderate authorized or equivalent, so we help you choose between commercial Microsoft 365, GCC and GCC High based on the data you hold. Agreements run month to month.
Not sure what your contracts require? Book a call and we will review the clauses and your CUI flow with you.
Frequently asked questions
What is NIST SP 800-171 compliance?
Meeting the security requirements in NIST Special Publication 800-171 on every system that processes, stores or transmits CUI, and keeping the evidence to prove it. Defense contracts require it through DFARS 252.204-7012, and CMMC Level 2 checks it against the 110 requirements of Revision 2.
Is NIST 800-171 the same as CMMC?
No. NIST SP 800-171 is the set of requirements; CMMC is the Defense Department program that verifies them. During the Phase II suspension, contracts may require only CMMC Level 1 or Level 2 self-assessments, while DFARS 252.204-7012 continues to require the security requirements themselves.
How many controls are in NIST 800-171?
Revision 3 has 97 requirements in 17 families. Revision 2 has 110 in 14 families, and those 110 are the ones CMMC Level 2 scores. NIST calls them security requirements; each is derived from controls in NIST SP 800-53.
Is there a NIST 800-171 checklist in Excel?
NIST publishes the Revision 3 requirements as a dataset in its Cybersecurity and Privacy Reference Tool, and the Revision 2 requirements as a downloadable spreadsheet. The family table above also copies cleanly into a spreadsheet, one row per requirement.
Does NIST 800-171 apply to small businesses?
Yes, when a contract requires it; company size is no exemption. NIST's SP 1318 primer is written for small businesses starting with Revision 3, and an enclave keeps the scope, and the cost, proportional to the CUI you actually hold.
Sources and further reading
- NIST SP 800-171 Rev. 3, May 2024: the 17 families, requirement numbers and titles, organization-defined parameters and the change analysis, checked October 2026.
- NIST SP 800-171A Rev. 3, May 2024: assessment methods and objectives, checked October 2026.
- NIST SP 800-171 Rev. 2: withdrawn May 14, 2024, still the CMMC Level 2 baseline, checked October 2026.
- NIST SP 1318, Small Business Primer for SP 800-171 Rev. 3, August 2025, checked October 2026.
- Department of War CIO: About CMMC: Revision 2 enforced during the Phase II suspension, checked October 10, 2026.
- CMMC Program FAQs, revised July 13, 2026 (PDF): Revision 3 organization-defined parameters and the Revision 2 class deviation, checked October 2026.
- 32 CFR Part 170, CMMC Program, eCFR: scoping, scoring and evidence retention, checked October 2026.
Related reading
ComplianceCMMC vs NIST 800-171: The Requirements and the Program That Checks Them
Read Article
ComplianceCMMC Level 2 Requirements: The 110 Controls Explained
Read Article
CompliancePOA&M Template and System Security Plan Template, With Examples
Read ArticleAlso on this topic: CMMC Level 1 Checklist: The 15 Requirements Explained
Discuss cmmc 2.0 compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
