Government / NIST

Available now

NIST SP 800-171 · Rev. 2

NIST SP 800-171 Rev. 2 protects Controlled Unclassified Information (CUI) on nonfederal systems. Its 110 requirements across 14 families are the scope of CMMC Level 2 and the price of admission for DoD supply-chain work.

110

requirements tracked

Premium

Access

Add-on from $49/mo

Scope

How much of the standard Keel models

Models its declared scope in full

Keel authors every leaf requirement in the scope declared below, all 110 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.

Authored in Keel
110 requirements
In Keel’s scored scope
110 leaf requirements

Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework

Who it is for

Who needs NIST SP 800-171?

  • Contractors and subcontractors handling CUI for the Department of Defense
  • Companies preparing for CMMC Level 2 assessment
  • Teams that need an SSP, a POA&M, and an SPRS score they can defend

What Keel does

How Keel helps with NIST SP 800-171

  • All 110 requirements across the 14 families as a trackable framework
  • Gaps surfaced for your POA&M, and coverage shared with SOC 2 and CIS
  • A living readiness view so your SSP and score stay current

Collect once, comply everywhere

NIST SP 800-171 shares canonical controls with NIST SP 800-53, FedRAMP Rev5 Class C and FedRAMP Rev5 Class D and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding NIST SP 800-171 rarely means starting from scratch.

Shares canonical controls with

  • ISO/IEC 27001 shares canonical controls
  • CIS Critical Security Controls shares canonical controls
  • PCI DSS shares canonical controls
  • SOC 2 shares canonical controls
  • SOX (Sarbanes-Oxley) Section 404 shares canonical controls
  • NIST Cybersecurity Framework shares canonical controls
  • NIST SP 800-53 shares canonical controls
  • FedRAMP Rev5 Class B shares canonical controls
  • FedRAMP Rev5 Class C shares canonical controls
  • FedRAMP Rev5 Class D shares canonical controls
  • FedRAMP 20x shares canonical controls
  • FedRAMP Consolidated Rules shares canonical controls
  • HIPAA shares canonical controls
  • GDPR shares canonical controls
  • COPPA shares canonical controls
  • Google Play Families no shared canonical controls
  • Amazon Appstore Child-Directed Apps no shared canonical controls
  • Apple App Store Kids Category no shared canonical controls
  • PIPEDA shares canonical controls
  • ISO 9001 shares canonical controls
  • AI Governance Essentials no shared canonical controls
  • ISO/IEC 42001 shares canonical controls
  • NIST AI Risk Management Framework no shared canonical controls
  • EU AI Act no shared canonical controls
  • ESG Essentials shares canonical controls
  • US Employment Law - Federal Baseline shares canonical controls

A framework is lit when at least one canonical control satisfies both NIST SP 800-171 and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 20 of 26 are lit here.