ZenGRC

NIST 800-171 Compliance Checklist

NIST SP 800-171 is a cybersecurity framework designed to help nonfederal organizations, especially defense contractors, protect Controlled Unclassified Information (CUI), and to prepare for compliance audits—now often self-certified under the related CMMC program—organizations should scope their systems, document architectures and controls, perform gap analyses, develop security plans and remediation strategies, and gather audit evidence addressing the 14 specific NIST 800-171 requirements such as access control.

The National Institute of Standards and Technology’s (NIST) Special Publication 800-171 (NIST SP 800-171), Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, is a cybersecurity framework designed to help organizations outside the U.S. federal government protect sensitive information. It is particularly relevant for defense contractors and their subcontractors who handle “controlled, unclassified information” (CUI) as part of government contracts.

Initially, NIST 800-171 was the standard for compliance, but many businesses—especially small and medium-sized subcontractors—found the process confusing and challenging due to limited resources. To address this, the government developed the Cybersecurity Maturity Model Certification (CMMC), which is largely based on NIST 800-171 and incorporates elements from other standards. As of 2021, contractors and subcontractors self-certify their compliance, as third-party CMMC certifications are not yet available.

Your NIST 800-171/CMMC Audit Preparation Checklist

To prepare for a NIST 800-171 (or CMMC) audit, consider the following steps:

  • Identify and confirm your compliance scope. Adjust system boundaries to limit the scope where possible.
  • Gather or create supporting documentation, including:
    • System and network architecture
    • System boundaries
    • Data flows
    • People, processes, and procedures
    • Anticipated changes
  • Perform a gap analysis.
  • Review and document existing controls, noting any design flaws or gaps.
  • Document a system security plan.
  • Develop a Plan of Action & Milestones (POA&M) for tracking remediation.
  • Develop your remediation plan.
  • Monitor, maintain, test, and improve controls.
  • Identify audit requirements (using the 14 requirements listed below).
  • Gather your audit-trail evidence.

What Are the NIST 800-171 Requirements?

NIST 800-171 Rev. 2 contains 14 audit requirements:

  1. 1.Access control: Addresses access controls for IT environments, including configuration, security policies, role-based access, and privileged access controls.
  2. 2.Awareness and training: Examines internal training for security and privacy awareness.
  3. 3.Audit and accountability: Involves collecting and reviewing audit records and audit processing details.
  4. 4.Configuration management: Reviews how networks and cybersecurity protocols are configured and managed, including documentation.
  5. 5.Identification and authentication: Ensures all users, processes, and devices are identified and authenticated before accessing CUI.
  6. 6.Incident response: Requires a response plan for breaches or attacks, including testing the plan.
  7. 7.Maintenance: Involves regular, timely maintenance of systems containing CUI, with documentation of plans and procedures.
  8. 8.Media protection: Addresses protection, maintenance, decommissioning, and destruction of IT media (servers, databases, drives, etc.).
  9. 9.Personnel security: Covers policies and procedures for vetting, monitoring, and terminating personnel to safeguard systems and CUI.
  10. 10.Physical protection: Ensures buildings, rooms, and environments are secure.
  11. 11.Risk assessment: Involves risk assessment and management policies, information classification, vulnerability scans, and mitigation.
  12. 12.Security assessment: Requires periodic assessment, monitoring, and correction of security controls.
  13. 13.System and communications protection: Policies and procedures for monitoring, controlling, and protecting communications containing CUI.
  14. 14.System and information integrity: Covers practices for quick detection, identification, reporting, and mitigation of security risks and threats.

Why Comply With NIST 800-171 Requirements?

Compliance is required for entities doing business with the U.S. Department of Defense (DoD). The framework emphasizes the importance of protecting sensitive federal information, which is often shared with contractors, state and local governments, educational institutions, and research organizations. Protecting this information is crucial for federal agencies to fulfill their missions.

NIST recommends that all U.S. government agencies require NIST 800-171 compliance in their contracts. The recommended security controls should be implemented when:

  • A nonfederal system or organization possesses controlled unclassified information (CUI);
  • The organization is not collecting or maintaining CUI or operating federal information systems on behalf of an agency;
  • Requirements don’t exist for protecting the CUI in the U.S. government’s CUI Registry.

In summary, NIST 800-171 compliance is advisable for any business that may interact with the U.S. government.

The Easy Way to NIST Compliance

NIST 800-171 compliance can be complex. Automated tools, such as those offered by ZenGRC, can help check controls, identify gaps, and provide dashboards to guide organizations toward compliance. Integration with business applications and centralized documentation can streamline the audit process and help maintain compliance.