CMMC Compliance Checkby Agent Trust Cloud

NIST SP 800-171 compliance: the 110 requirements behind CMMC Level 2

CMMC Level 2 assesses the 110 security requirements of NIST SP 800-171 Rev 2, in 14 families. DFARS 252.204-7012 already required them for contractors holding CUI; CMMC adds the assessment, the SPRS score and the affirmation. Each requirement below shows the points it costs when not met (32 CFR 170.24, CMMC Scoring Methodology).

Families

"Basic" requirements come from FIPS 200 and "derived" ones from NIST SP 800-53 controls. Rev 3 of SP 800-171 exists, but DFARS 7012 and CMMC Level 2 still assess Rev 2.

3.1 Access Control

3.2 Awareness and Training

3.3 Audit and Accountability

3.4 Configuration Management

3.5 Identification and Authentication

3.6 Incident Response

3.7 Maintenance

3.8 Media Protection

3.9 Personnel Security

3.10 Physical Protection

3.11 Risk Assessment

3.12 Security Assessment

3.13 System and Communications Protection

3.14 System and Information Integrity

Check your answers for all 110

Sources