Frameworks

Winning DoD contracts: NIST 800-171 and the road to CMMC

What NIST SP 800-171 Rev. 2 actually requires (its 110 requirements across 14 families), how it maps to CMMC Level 2, and how to get to compliance if you want to work with the Department of Defense.

If you want to sell to the U.S. Department of Defense, or to a prime contractor that does, sooner or later you'll be asked about NIST SP 800-171 and CMMC. They sound like alphabet soup, but the story is simple: the government wants its sensitive-but-unclassified information protected when it lives on your systems, and these are the rules for doing it.

Here's what the requirements actually are, how the two fit together, and how to get compliant without hiring a defense-industry consultant to translate it.

What NIST 800-171 protects

The standard exists to protect Controlled Unclassified Information (CUI), things like technical drawings, specifications, and other sensitive data the DoD shares with contractors, when it's stored or processed on nonfederal systems. If you handle CUI, the requirement flows down to you through your contract (specifically DFARS clause 252.204-7012).

Revision 2 (the version CMMC currently references) contains 110 security requirements organized into 14 families:

# Family What it covers
3.1 Access Control Who can reach what, MFA, least privilege
3.2 Awareness and Training Security training for staff
3.3 Audit and Accountability Logging and traceability
3.4 Configuration Management Hardened, controlled baselines
3.5 Identification and Authentication Proving who users and devices are
3.6 Incident Response Detect, report, and recover
3.7 Maintenance Controlled system maintenance
3.8 Media Protection Protect and sanitize storage media
3.9 Personnel Security Screening and access on departure
3.10 Physical Protection Physical access to systems
3.11 Risk Assessment Find and rank your risks
3.12 Security Assessment Test your controls, track your gaps
3.13 System and Communications Protection Encryption, boundary defense
3.14 System and Information Integrity Patching, malware defense, monitoring

If you've worked with SOC 2 or the CIS Controls, this list will feel familiar. It's the same security fundamentals, written for a government audience.

How CMMC fits in

NIST 800-171 is the requirements. CMMC (Cybersecurity Maturity Model Certification) is the DoD's program for verifying you actually meet them, so that "we're compliant" is no longer just a self-attestation on trust.

  • CMMC Level 1 covers basic safeguarding of federal contract information, a smaller set of practices.
  • CMMC Level 2 maps directly to the 110 requirements of NIST 800-171. This is the level most contractors handling CUI need. Depending on the contract, you'll either self-assess or undergo a third-party assessment (C3PAO).
  • Level 3 adds enhanced requirements for the highest-priority programs.

So the practical path is: implement the 110 NIST 800-171 requirements → document them → and you're positioned for CMMC Level 2.

Two artifacts you'll need

NIST 800-171 compliance hinges on two documents assessors will ask for:

  1. System Security Plan (SSP): describes your environment and how you meet each of the 110 requirements.
  2. Plan of Action and Milestones (POA&M): an honest list of the requirements you don't fully meet yet, with dates for closing them.

You'll also compute an SPRS score (a self-assessment score out of 110, with weighted deductions for gaps) that gets reported into the government's supplier system. Being able to show your current score, your gaps, and your remediation plan at any moment is most of the battle.

Getting to compliance

  1. Scope your CUI. Figure out exactly where CUI lives. The smaller and more isolated that boundary (an enclave), the fewer systems fall in scope.
  2. Assess against all 110 requirements. Mark each met / partial / not met. This is the raw material for both your SSP and your POA&M.
  3. Close the high-impact gaps first. MFA, encryption of CUI, access control, and audit logging carry the most weight.
  4. Document as you go. For 800-171, undocumented is the same as undone. The assessor scores evidence, not intentions.
  5. Keep the SSP and POA&M living. They're not one-time deliverables; they're the running record of your program.

Where it overlaps with everything else

The reason this is achievable for a small company: you are not building a separate security program for the DoD. Access control, encryption, incident response, vulnerability management. The 110 requirements share the vast majority of their DNA with SOC 2, ISO 27001, and CIS. Implement the control once, and let it count toward each framework that asks for it.


Keel now ships NIST SP 800-171 Rev. 2 as a framework, all 110 requirements across the 14 families, crosswalked so the controls you build for SOC 2 or CIS count toward your 800-171 (and CMMC Level 2) readiness, with your gaps tracked for the POA&M automatically. Start free at keelgrc.com.

This article is general information, not legal or audit advice. Framework names (SOC 2, ISO 27001, PCI DSS, etc.) are referenced factually; Keel is not affiliated with or endorsed by their owners.

Put this into practice with Keel

Keel gives growing teams a self-serve path to SOC 2, ISO 27001, and more, controls, evidence, policies, access reviews, and a trust center on one graph.