NIST SP 800-171 is a set of security requirements, organized into control families, that protect Controlled Unclassified Information (CUI) when it lives on the systems of a contractor rather than the government. If your firm handles CUI for a federal agency or sits anywhere in the Department of Defense supply chain, these controls are the baseline you are measured against, and under CMMC 2.0 they are what a Level 2 assessment scores. Most small firms we work with can name the firewall and MFA requirements from memory. Where they lose points is the paperwork: the System Security Plan, the Plan of Action and Milestones, and a clear boundary around where CUI actually sits. This guide walks the controls the way an assessor reads them, and shows where a small team should spend its first ninety days.
The Five Things Small Firms Get Wrong
Before the control families, here is what our compliance team sees fail most often across small defense-supply-chain and federal-adjacent firms in 2026. Read these first, because they reframe how you should weigh the rest of this guide.
- The score is documentation-weighted. Your SPRS score starts at 110 and loses points for every unmet requirement, and some requirements are worth 5 points each. A missing System Security Plan is not a minor gap. It can zero out your eligibility entirely, and the score can go negative if enough high-weight controls are unmet.
- Scope is a control, not a preface. Firms that never draw a CUI boundary end up assessing their whole network, which multiplies cost and failure surface. Defining scope narrowly and honestly is the highest-leverage move you can make.
- A POA&M is not a free pass. You can close some gaps later with a Plan of Action and Milestones, but several controls must be fully met on day one. Knowing which is which changes your project plan.
- Shared responsibility gets misread. Moving CUI into a cloud tenant does not move the controls off your plate. You still own configuration, access, and evidence.
- Evidence ages. An assessor wants proof the control operated over time, not a screenshot from the week before the audit. Logging and review cadence are controls in their own right.
Which Version of the Standard Are You Being Measured Against?
Before diving into the families, confirm which revision your contract actually cites, because this trips up more firms than any individual control. Revision 2, the version most contracts and CMMC Level 2 assessments currently reference, organizes 110 requirements across 14 families. Revision 3 reorganizes the material into 97 requirements across 17 families, adding dedicated families for supply chain risk and for planning. The practices did not get easier under Revision 3, they got reorganized to line up more closely with the broader federal control catalog, and both revisions are still cited in contracts as this transition plays out. Check your contract language before you scope a project against the wrong count.
The rest of this guide walks through the Revision 2 structure, since that’s what most current CMMC Level 2 assessments still measure against, but confirm your specific contract before treating either number as fixed.
How the NIST SP 800-171 Control Families Fit Together
The 110 requirements in Revision 2 are grouped into 14 families, and reading them as a system rather than a checklist is what separates a passing firm from a scrambling one. Each family maps to a familiar security discipline: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. The families overlap by design. You cannot satisfy Access Control without solving Identification and Authentication first, and neither holds up without the logging that Audit and Accountability demands.
We tell clients to stop treating the families as separate projects. Treat them as three layers: the technical controls that tools enforce, the operational controls that people run on a cadence, and the documentation controls that prove the other two work. When you group the work this way, the sequence becomes obvious, and you avoid the trap of buying a tool for every family while the plan tying them together never gets written.
The Technical Controls Most Tools Already Cover
The technical layer of NIST SP 800-171 covers the controls your existing security stack can enforce with configuration rather than new spend. Access Control (family 3.1) and Identification and Authentication (family 3.5) are the anchors here. Together they require unique accounts for every user and device, multi-factor authentication for network and privileged access, and controls that block weak or reused credentials.
You are likely further along than you fear here. If you run Microsoft 365 or a similar business platform, you probably already have the building blocks: role-based permissions, conditional access, and multi-factor authentication. What’s often missing is not the feature but the specific configuration the framework names, such as limiting failed login attempts or enforcing session lock. Having the capability turned on is not the same as configuring it against the exact practice being assessed.
System and Communications Protection (3.13) and System and Information Integrity (3.14) round out the technical layer with encryption of CUI in transit and at rest, boundary protection, and timely patching. A firm running current endpoint protection, enforced disk encryption, and MFA is often 60 to 70 percent of the way through the technical controls without realizing it. The gap is rarely the tool. It is proving the tool is configured correctly and stays that way, which is where managed security services and continuous monitoring earn their keep.
The Operational Controls People Have to Run
The operational controls in NIST SP 800-171 are the ones no tool completes for you, because they depend on people doing something on a schedule. Awareness and Training (3.2), Incident Response (3.6), Audit and Accountability (3.3), and Risk Assessment (3.11) all require recurring human action. You need documented security training your staff actually completes, an incident response plan you have tested rather than filed, log review that happens on a defined cadence, and a periodic risk assessment that feeds your remediation list.
Assessors probe these hard, because they are the easiest to fake and the easiest to let lapse. We have watched firms with excellent tooling fail here because their incident response plan named an employee who left two years ago. The same discipline that stops a live attack is what carries the operational families: a plan, a rehearsal, and a record that both happened.
Audit, configuration, and system integrity as a governance habit. These families ask you to prove your environment behaves predictably over time. On one hand, this reads as routine IT hygiene: keep logs, patch systems, maintain a known-good baseline, scan for vulnerabilities. Many firms already do a version of this. On the other hand, the framework wants evidence that it happens on a schedule and that someone reviews the output, which is a governance habit smaller teams often skip. The practices are ordinary; the discipline of recording and reviewing them is what auditors actually check.
CUI does not only live in the cloud. Media protection, physical security, and personnel practices remind you that a printed report left on a desk, an unwiped hard drive, or an unscreened contractor with server-room access all sit outside your firewall entirely. A design shop that prints fabrication drawings has a genuinely different physical exposure than a software vendor that never puts CUI on paper, so weigh this layer against how your specific firm actually handles the data day to day rather than treating it as boilerplate.
The Documentation Controls That Decide Your Score
The documentation controls are where small firms lose the most SPRS points, because two artifacts, the System Security Plan and the Plan of Action and Milestones, are effectively pass-or-fail. The System Security Plan (SSP) describes how each of the 110 requirements is met across your defined boundary. It is not optional, and it is not a template you fill in the night before. A current, accurate SSP is the single document an assessor reads first, and an absent or stale one signals that nothing underneath it can be trusted either.
The Plan of Action and Milestones (POA&M) records the requirements you have not fully met yet, with a dated plan to close each one. Used honestly, it buys you structured time on lower-weight controls. Used as a dumping ground for controls that must be met on day one, it fails you. Getting the SSP and POA&M right is unglamorous work, and it is exactly the work that determines whether the technical spend around it counts.
Reading Your Controls Against CMMC and SPRS
Your NIST SP 800-171 work is only useful if you connect it to the two systems that grade you: CMMC 2.0 and the Supplier Performance Risk System (SPRS). CMMC Level 2 maps almost directly to the 110 NIST SP 800-171 Revision 2 requirements, so the work you do here is the same work a Level 2 assessment scores. The relationship is not identical, though, and the differences matter for scoping and infrastructure decisions.
SPRS is where the controls turn into a number. You self-assess against all 110 requirements, start at a perfect score of 110, and subtract the point value of every gap, and the result can land negative if enough high-weight controls are unmet. Because the weighting is uneven, a firm can close 90 controls and still post a low score if the remaining gaps are the high-value ones. This is why we push clients to sequence remediation by point value, not by whichever control is easiest to knock out. A partial score submitted alongside a credible System Security Plan and Plan of Action and Milestones is a normal, reportable state, not an automatic disqualifier.
We often pair the technical work with a zero-trust architecture so the score improves structurally rather than through one-off fixes. And if your firm also carries other frameworks, note that many of the same controls and much of the same evidence carry over to HIPAA and SOC 2 work, so building the evidence once and reusing it saves real time.
A Ninety-Day Starting Sequence for Small Teams
A small firm meets NIST SP 800-171 fastest by fixing scope and documentation before buying anything new. In our cybersecurity compliance engagements we run the same opening sequence.
First, hold a scoping workshop. Map where CUI is created, stored, and transmitted, then draw the smallest defensible boundary around it. Everything outside that boundary drops out of assessment, which cuts both cost and risk.
Second, run a gap assessment against all 110 requirements and record the result honestly. A self-assessment you inflate only defers the failure.
Third, draft the SSP for the scoped environment and start the POA&M for anything not yet met, sorting the remediation list by SPRS point value.
Only then do you spend on tools, and only for the gaps the assessment actually found. The order is the point: scope, assess, document, then remediate.
Frequently Asked Questions
How many controls are in NIST SP 800-171?
NIST SP 800-171 Revision 2 contains 110 security requirements organized into 14 control families. Revision 3 reorganizes the material into 97 requirements across 17 families. The count difference reflects restructuring, not a reduction in effort, and both are still cited in contracts as of 2026, so confirm which one applies to yours.
Is NIST SP 800-171 the same as CMMC?
They are closely related but not identical. CMMC Level 2 maps almost directly to the 110 NIST SP 800-171 Revision 2 requirements, so meeting the controls is the core of a Level 2 assessment. CMMC adds the assessment and certification process on top, which for many contracts means a third-party assessment rather than a self-assessment.
What is a System Security Plan and do I really need one?
A System Security Plan (SSP) is a document describing how your firm meets each of the required practices across your defined boundary, and yes, it is mandatory. An absent SSP can make your firm ineligible regardless of how strong your technical controls are, because assessors treat it as the foundation for every other claim.
Can a small business realistically meet NIST SP 800-171 without a large IT team?
Yes. Most of the confusion for smaller firms is scope and documentation, not raw technical difficulty, and a tight CUI boundary keeps the number of systems in scope small. Small firms with the right scoping and documentation support commonly reach readiness in six to twelve months. Working with a compliance partner lets a lean team meet the requirements without hiring dedicated security staff.
What is a POA&M and which controls can it cover?
A Plan of Action and Milestones (POA&M) lists requirements you have not fully met, each with a dated plan to close it. It buys structured time on lower-weight controls, but several requirements must be fully met before you can claim compliance and cannot sit on a POA&M, so knowing which is which shapes your project plan.
Do I need to meet every control to win a contract?
Not always at first. The DoD self-assessment produces a score from a 110-point baseline, and you can report a partial score, even a negative one, alongside a Plan of Action and Milestones that commits to closing the gaps on a timeline. Many contracts allow a documented remediation path, though the acceptable score and deadline depend on the specific award.
Talk to a Strategist Before You Buy a Single Tool
NIST SP 800-171 rewards firms that get the boring parts right: confirming which revision applies, an honest scope, a real System Security Plan, and a remediation list sequenced by what actually moves your SPRS score. The controls themselves are well within reach for a small team, and much of your existing security stack likely already covers the technical layer. The firms that struggle are the ones that buy tools before they draw their CUI boundary or write their documentation, then discover at assessment time that the paperwork carrying the most weight was never done.
Start with scope, confirm your revision, assess against the requirements without flattering yourself, and let the point values tell you where to spend. If you want a compliance team that has run this sequence with other small defense-supply-chain and federal-adjacent firms, we can help you plan it before the clock on a contract starts. Book a free strategy call and we will map your fastest path to a defensible score.

