Cybersecurity
NIST 800-171 Checklist: The 14 Control Families and How Scoring Works
A working NIST 800-171 checklist covering all 14 control families, the SPRS scoring formula, Rev 2 vs Rev 3 changes, and where NIST SP 800-172 fits. Built for Hampton Roads defense subcontractors.
The 60-second answer
A NIST 800-171 checklist is a working document that tracks all 110 security requirements across 14 control families, with a status, an evidence pointer, and an owner for each one. There is no official “NIST 800-171 checklist” PDF from NIST. The checklist is something you build from SP 800-171 (the requirements) and SP 800-171A (the assessment objectives an auditor actually scores). Rev 2 is still the version DoD contracts require. Your SPRS score starts at 110 and drops for each unimplemented requirement, down to as low as negative 203.
If you searched for an Excel version, that instinct is correct. A spreadsheet with columns for control family, requirement number, status, evidence, and owner is more useful day to day than the narrative PDF. This article gives you the structure to build one, plus the two things a spreadsheet alone won’t tell you: how the DoD’s scoring actually works, and where NIST 800-171 stops and CMMC picks up.
What NIST 800-171 actually is
NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” is the federal standard for safeguarding CUI outside government networks. The National Institute of Standards and Technology published it in 2015 and revised it in 2020. If your company touches CUI on a DoD contract, DFARS 252.204-7012 already requires you to implement it, whether or not CMMC has reached your contract yet.
Our CMMC vs NIST 800-171 comparison covers how the two programs relate end to end: NIST 800-171 is the control set, CMMC is the audit that certifies you actually met it. This article stays inside NIST 800-171 itself: what the 14 families require, how the checklist should be structured, how the DoD scores you, and what changes with Rev 3.
The 14 control families, checklist structure
Every NIST 800-171 requirement belongs to one of 14 families. A checklist organized by family, rather than as one flat list of 110 rows, makes it easier to assign ownership, since most of these map cleanly to a role in a small company: IT handles half the list, HR handles a few rows, and physical security or facilities handles a handful more.
| # | Family | Requirements | Typical owner |
|---|---|---|---|
| 1 | Access Control (AC) | 22 | IT / MSP |
| 2 | Awareness and Training (AT) | 3 | HR / compliance |
| 3 | Audit and Accountability (AU) | 9 | IT / MSP |
| 4 | Configuration Management (CM) | 9 | IT / MSP |
| 5 | Identification and Authentication (IA) | 11 | IT / MSP |
| 6 | Incident Response (IR) | 3 | IT / leadership |
| 7 | Maintenance (MA) | 6 | IT / MSP |
| 8 | Media Protection (MP) | 9 | IT / operations |
| 9 | Personnel Security (PS) | 2 | HR |
| 10 | Physical Protection (PE) | 6 | Facilities |
| 11 | Risk Assessment (RA) | 3 | IT / leadership |
| 12 | Security Assessment (CA) | 4 | IT / compliance |
| 13 | System and Communications Protection (SC) | 16 | IT / MSP |
| 14 | System and Information Integrity (SI) | 7 | IT / MSP |
That’s 110 requirements. Access Control and System and Communications Protection carry the heaviest load between them, nearly a third of the standard, which tracks with where most gap-review findings land in practice: who can reach CUI, and what protects it in transit and at rest.
For each row on your working checklist, track five things:
- Requirement number and text. Pull directly from SP 800-171 so you’re not paraphrasing your own obligation.
- Implementation status. Implemented, partially implemented, or not implemented. Resist a fourth “in progress” bucket; it hides how far along you actually are.
- Evidence. A screenshot, a policy document, a configuration export, a ticket. If you can’t point to something an assessor could look at, the status isn’t “implemented” yet.
- Owner. One person’s name, not a department.
- POA&M target date. For anything not fully implemented, the date you expect to close it. This becomes your Plan of Action and Milestones.
SPRS scoring, how the number actually gets built
The Supplier Performance Risk System score is not a percentage and it is not a simple count of requirements met. It starts at 110, the maximum possible score, and subtracts a fixed point value for every requirement you have not implemented. The point values, set by the DoD’s scoring methodology, run from 1 to 5 depending on the requirement’s assessed security impact. Multifactor authentication, for instance, carries a heavier deduction than a documentation-only requirement, because losing it does more damage.
Run the subtraction on a fully unimplemented environment and the floor is negative 203, not zero. That surprises people who assume the scale bottoms out at nothing. It doesn’t. A company that has implemented essentially none of NIST 800-171 posts a deeply negative number in SPRS, and a contracting officer sees that number before award or option-year renewal decisions.
The scoring methodology itself, DoD’s “NIST SP 800-171 DoD Assessment Methodology,” is a public document (see sources below). It defines three assessment types: Basic (a contractor self-assessment, the version most subcontractors post), Medium, and High (both requiring DoD-conducted review of your Basic score and supporting SSP). Basic is a self-assessment. The score you post under Basic still has to survive a later Medium, High, or CMMC third-party assessment, so scoring yourself generously on paper and scoring differently under an assessor’s eye is the exact gap that creates False Claims Act exposure.
Where to register: SPRS access runs through PIEE (Procurement Integrated Enterprise Environment), which requires a CAGE code from SAM.gov. Most defense subcontractors already have both if they’ve been awarded a contract.
Rev 2 vs Rev 3, what actually changed
NIST SP 800-171 Revision 2 is the version currently in force. It’s what DFARS 7012 requires and what CMMC Level 2 is built on. Revision 3, published as SP 800-171r3 in May 2024, is a real update, not a formatting pass, but it is not yet what your DoD contract requires.
The headline changes in Rev 3:
- Organization-defined parameters (ODPs). Several requirements now include parameters the organization sets itself, such as password rotation windows or session timeout values, rather than a single fixed rule for every contractor.
- Requirement reorganization. Some requirements moved between families or were consolidated; the total count and structure shifted from the Rev 2 baseline.
- New requirements added, others dropped. Rev 3 adds coverage in areas like supply chain risk that Rev 2 handled thinly, and removes a few requirements judged redundant with other federal controls.
- Tighter alignment with NIST 800-53. Rev 3 pulls its requirement language more directly from the broader NIST 800-53 control catalog, which should make crosswalking with other federal frameworks more consistent going forward.
The practical read for a Hampton Roads subcontractor: don’t rebuild your checklist against Rev 3 yet. DoD contracts, DFARS 7012, and CMMC Level 2 all still cite Rev 2. When the DoD formally transitions CMMC and its contract clauses to Rev 3, that will happen on its own rulemaking timeline, not on NIST’s publication date. Track it, but build your working checklist against Rev 2 today.
Where NIST SP 800-172 fits
NIST SP 800-172, “Enhanced Security Requirements for Protecting Controlled Unclassified Information,” is not a NIST 800-171 checklist item. It’s a separate, smaller document that adds requirements on top of 800-171 for systems facing an advanced persistent threat, the kind of adversary the DoD’s highest-priority programs are built to resist.
SP 800-172 maps to CMMC Level 3, which the DoD applies only to a narrow slice of programs and which DIBCAC, not a commercial C3PAO, assesses directly. If your contract hasn’t told you Level 3 applies, it almost certainly doesn’t. Most Hampton Roads defense subcontractors handling standard CUI on a typical DoD program will stop at NIST 800-171 and CMMC Level 2. Confirm with your prime or contracting officer before assuming otherwise, since Level 3 scoping is program-specific and not something to guess at from the outside.
How this connects to CMMC Level 2
NIST 800-171 compliance is necessary for CMMC Level 2, not sufficient. CMMC Level 2 assesses the same 110 requirements plus the assessment objectives published in SP 800-171A, and for prioritized contracts, a C3PAO reviews the evidence rather than taking your self-assessment at face value. Our CMMC Level 2 requirements guide walks through the full assessment path, including when self-assessment is still allowed and when a third-party review is required. If you’re earlier in the process and unsure whether your contract even touches CUI, What Is CUI? covers how to identify it, and CMMC Level 1 Requirements covers the smaller FCI-only bar for contractors who don’t handle CUI at all.
Building your checklist, the practical version
Start with a spreadsheet, not a narrative document. One row per requirement, 110 rows, grouped by the 14 families above. Pull the requirement text from SP 800-171 and the assessment objectives from SP 800-171A so your evidence column has something concrete to satisfy, not just the requirement’s one-sentence summary.
A few things that tend to trip up a first pass:
- Policy documents alone don’t close a requirement. A written access control policy is evidence of intent. An assessor wants the configuration that enforces it.
- “Partially implemented” needs a real target date. A POA&M line without a date is a requirement you’ve decided not to think about yet.
- Evidence goes stale. A screenshot from eight months ago proves what was true eight months ago. Set a review cadence, quarterly at minimum, so your checklist reflects the current environment when someone actually asks.
- The SSP and the checklist should be the same source of truth. Requirement 3.12.4 requires a System Security Plan. If your SSP and your working checklist disagree about a control’s status, an assessor will find the disagreement before you do.
Get a second read on your NIST 800-171 posture
A free IT assessment covers where your environment actually stands against the 14 families above, in person if you’re in Hampton Roads. You leave with a directional score and the top gaps written down, not a sales pitch.
Helix Stax scores CMMC and NIST 800-171 readiness on the Controls pillar of the CTGA framework. We are not a C3PAO and we don’t perform certification assessments; your C3PAO and RPO partner handle that. What we do is walk your environment against the 14 families, name the gaps in plain language, and hand you a checklist that matches what an assessor will actually look for.
We cover all seven Hampton Roads cities, Newport News, Norfolk, Virginia Beach, Chesapeake, Portsmouth, Hampton, Suffolk, in person where the geography fits, and the rest of the United States by Zoom.
Book Your Free IT Assessment →
Sources
- NIST SP 800-171 Rev. 2, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”, published by the NIST Computer Security Resource Center
- NIST SP 800-171 Rev. 3, published by the NIST Computer Security Resource Center
- NIST SP 800-172, “Enhanced Security Requirements for Protecting Controlled Unclassified Information”, published by the NIST Computer Security Resource Center
- NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1, published by the Office of the Under Secretary of Defense for Acquisition and Sustainment
- 32 CFR Part 170, Cybersecurity Maturity Model Certification Program, from the Electronic Code of Federal Regulations
Related reading on Helix Stax: CMMC vs NIST 800-171 → · CMMC Level 2 Requirements → · What Is CUI? → · CMMC Level 1 Requirements → · Government Contracting IT Services → · Cybersecurity Compliance → · Contact →
Read more
Cybersecurity
IT Disaster Recovery Plan Template (With RTO/RPO and Site Comparison)
A free IT disaster recovery plan template covering RTO, RPO, hot vs. warm vs. cold site recovery, testing cadence, and how it maps to NIST SP 800-34. Copy it and fill in your own numbers.
Cybersecurity
6 Phishing Email Examples Your Staff Will Actually See (And How to Train Against Them)
Real-world phishing email examples: fake invoices, MFA fatigue, payroll redirects, vendor bank-change scams, and more. What gives each one away, plus how to run simulation training.
Cybersecurity
CMMC Level 1 Requirements: The 15 Controls Small Contractors Need for FCI
CMMC Level 1 requires 15 basic safeguarding practices from FAR 52.204-21 and an annual self-assessment. Here is what Hampton Roads contractors handling Federal Contract Information actually need to do.
Frequently asked questions about Helix Stax managed IT services
A working checklist covers all 110 security requirements from NIST SP 800-171, organized into 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Each line needs an implementation status and a piece of evidence, not just a checkmark.
Rev 2 (2020) is the version currently required on DoD contracts and the version CMMC Level 2 is built on. Rev 3, published as SP 800-171r3 in May 2024, reorganizes some requirements, drops a handful, and adds new ones tied to organization-defined parameters. DoD contracts still cite Rev 2 as of this writing, so Rev 3 does not replace your current obligation until the DoD formally transitions CMMC to it.
The SPRS score starts at 110, the maximum, and subtracts points for each unimplemented requirement. Point values range from 1 to 5 depending on the requirement's security impact. A perfect implementation scores 110. A supplier who has implemented nothing meaningful can score as low as negative 203. The score gets posted in the Supplier Performance Risk System under DFARS 252.204-7019.
NIST SP 800-172 is a set of enhanced security requirements that sit on top of NIST 800-171, built for systems facing an advanced persistent threat. It maps to CMMC Level 3, which applies only to the DoD's highest-priority programs. Most Hampton Roads subcontractors handling standard CUI will stop at NIST 800-171 and CMMC Level 2. Check your contract and prime guidance before assuming 800-172 applies.
NIST publishes the full requirement list inside SP 800-171 itself, and the companion SP 800-171A adds the assessment objectives assessors actually score against. Both are free PDF downloads from the NIST Computer Security Resource Center. A spreadsheet built from those two documents, with columns for status, evidence, and owner, is what most contractors use as a working checklist.
CMMC Level 2 assesses compliance with the 110 NIST 800-171 requirements, plus the assessment objectives from NIST SP 800-171A. NIST 800-171 is the control standard; CMMC is the certification program that checks whether you actually implemented it. See our full comparison for the enforcement timeline and the assessment differences.
Yes. A System Security Plan documenting your environment, your CUI boundary, and the implementation status of each of the 110 requirements is itself one of the requirements (3.12.4). It is also the document a C3PAO assessor reads first during a CMMC Level 2 assessment, so it needs to match what they find on the network, not what you hoped to have finished.