NIST 800-171 Compliance: Complete Guide [2026]

SaltyCloud Research Team

Updated Jul 27, 2026 Read Time 10 min

NIST 800-171 Compliance: A Step-by-Step Guide

NIST 800-171 compliance means implementing a specific set of security requirements for nonfederal organizations to protect Controlled Unclassified Information (CUI). It also involves documenting that work in a System Security Plan (SSP), creating a Plan of Action and Milestones (POA&M), and submitting a score to the Department of Defense Supplier Performance Risk System (SPRS).

Most organizations that seek NIST 800-171 compliance are legally obligated to do so under the Defense Federal Acquisition Regulation Supplement (DFARS). Among other things, the standard imposes strict cybersecurity rules for contractors and subcontractors that provide goods or services to the DoD.

To meet CMMC Level 2 requirements, federal contractors must conduct a self-assessment against the standard’s requirements and submit an SPRS score to the DoD. However, since SPRS scores are self-attested, the burden of proof sits with the organization, not the regulator. If that score doesn’t hold up under an independent audit, the consequences can be costly.

Notably, DFARS assessments still score against NIST 800-171 Rev 2, even though NIST published Rev 3 in 2024.

This guide explains what NIST 800-171 compliance is, why it’s important, and how to achieve it, with step-by-step instructions to comply. For more on NIST 800-171 is, who it applies to, and how it defines CUI, see our complete guide to NIST 800-171.

What Is NIST 800-171 Compliance?

NIST 800-171 compliance is the point at which a nonfederal organization can prove that it meets the standard’s requirements for protecting Controlled Unclassified Information (CUI). The primary driver of 800-171 compliance is the Cybersecurity Maturity Model Certification (CMMC), a defense program designed to protect federally classified information (FCI) received, processed, or stored by U.S. government contractors and subcontractors.

NIST 800-171 compliance is the cybersecurity baseline the Department of Defense requires of contractors that handle Controlled Unclassified Information (CUI). It maps to a Supplier Performance Risk System (SPRS) score, satisfies DFARS clause 252.204-7012, and serves as the technical foundation for CMMC Level 2 certification.

More specifically, covered organizations must adhere to DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. It requires federal contractors and subcontractors to:

  • Safeguard covered defense information that resides or transits through covered information systems.
  • Apply specified network security requirements
  • Report cyber incidents.

The severity of those requirements depends on a few factors. But for most organizations, it all comes down to the CMMC.

How to Become NIST 800-171 Compliant

NIST 800-171 compliance requires several deliverables, each proving a different part of the standard. At the highest level, that includes:

  • A scoped CUI environment
  • A current System Security Plan (SSP)
  • A self-assessment against the DoD methodology
  • A calculated SPRS score, posted to SPRS
  • A Plan of Action and Milestones (POA&M) for open gaps

The current published version, NIST SP 800-171 Revision 3 (97 requirements across 17 families, published May 2024), does not yet apply to DFARS assessments. Instead, the DoD still uses NIST 800-171 Rev 2 (110 requirements across 14 families).

Under DoD Class Deviation 2024-O0013, which has no stated end date, federal contractors should continue to scope their compliance work against Rev 2’s 110 requirements.

NIST 800-171 Compliance Checklist

Organizations can use the table below as a NIST 800-171 compliance checklist. Each row pairs a deliverable with what “done” looks like.

NIST 800-171 Deliverable How to Comply
Scope the CUI environment Every system that receives, processes, or stores CUI is mapped, and the boundary is documented
System Security Plan (SSP) A current SSP describes how each of the 110 Rev 2 requirements is implemented, with gaps noted for the POA&M
Self-assessment Each requirement is scored as met or unmet using the DoD Assessment Methodology
SPRS score The score is calculated, starting at 110 with deductions for unmet requirements, and can range from -203 to 110
Post to SPRS The score, assessment date, scope, and SSP name, version, and date are entered in SPRS
Plan of Action and Milestones (POA&M) Every unmet requirement has an owner, a milestone, and a completion date

For most organizations, those deliverables are what drives self-assessments as an ordered workflow. See our NIST 800-171 assessment guide to learn more about scoring.

How to Comply with NIST 800-171: Step-by-Step Guide

NIST 800-171 compliance typically follows an ordered set of steps. Most start with scope, then SSP, then self-assessment, then SPRS, then POA&M, then ongoing maintenance.

Running the steps out of order is the most common reason 800-171 programs stall. Working through them in sequence is key for the most success.

Step 1: Scope the CUI Boundary

Map where FCI and CUI is received, processed, and stored across the organization. Remember, scope fails in both directions. Usually, the root cause is a missing CUI data-flow analysis.

Isolating CUI in a technically-enforced enclave right-sizes the boundary and cuts remediation effort. For a repeatable way to map that boundary, see our scoping guide.

Step 2: Write the System Security Plan (SSP)

Document how each requirement is implemented, and note any unimplemented requirement for the POA&M.

A credible SSP is current, operational, and backed by evidence. Use NIST’s CUI SSP template for a solid starting point.

Step 3: Self-assess Against the DoD Assessment Methodology

Score the environment starting at 110 points, then deduct for each unmet requirement. The result can be negative, with a floor of -203. Assess honestly — the score and its evidence must hold up to a DoD review.

Step 4: Submit the Score to SPRS

Enter the assessment date, score, scope, and SSP name, version, and date. The assessment itself happens outside SPRS. Still, a current score, no more than three years old, is required to be eligible for award under DFARS 252.204-7019.

Step 5: Build the POA&M

Log every gap with an owner, milestones, and a completion date using the NIST CUI POA&M template.

Step 6: Remediate and Maintain

Work the POA&M down, keep the SSP current, and refresh the SPRS score within the three-year window. Compliance is continuous, and posture decays when reassessment stops. Reassess as the environment changes.

Challenges with NIST 800-171 Compliance

Most compliance gaps concentrate in a handful of high-weight technical controls. DoD (DIBCAC) field assessments show the same failures again and again. Fixing those first usually improves an SPRS score the fastest.

But self-reported scores often overstate real posture. The table below lists the top offenders and how to close each one.

Control DIBCAC Failure Rate (%) How to Comply
3.13.11 FIPS-validated cryptography 52% Deploy a CMVP-validated module and confirm it runs in FIPS mode, since a FIPS-capable product ships with that mode off by default
3.5.3 Multi-factor authentication 73% Cover privileged local access, privileged network access, and non-privileged network access to CUI
3.3 Audit and accountability Top Failure Enable and retain audit logging that ties actions to individual users

Under 32 CFR 170.21, a POA&M is allowed only above an 80% score and must close within 180 days. Yet six requirements cannot go on a POA&M at all. These requirements are excluded entirely:

  • External Connections (AC.L2-3.1.20)
  • Control Public Information (AC.L2-3.1.22)
  • System Security Plan (CA.L2-3.12.4)
  • Escort Visitors (PE.L2-3.10.3)
  • Physical Access Logs (PE.L2-3.10.4)
  • Manage Physical Access (PE.L2-3.10.5)

Meanwhile, the timeline often runs longer than most teams expect. A gap or self-assessment usually takes four to eight weeks, and modest gaps close in roughly four months. Full end-to-end compliance for a mid-size contractor with real gaps typically runs 12 to 24 months. Most of that time goes to writing the SSP, gathering evidence, and fixing the high-weight technical controls.

The fastest moves are deploying MFA, rolling out endpoint detection and response, running security-awareness training, blocking USB and removable media, and tightening account hygiene. These quick wins buy time while the longer remediation work proceeds.

How to Simplify NIST 800-171 Compliance

Organizations running NIST 800-171 across multiple systems and business units need one place to manage the assessment, evidence, and remediation work.

Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, collect evidence, track risks, and prove compliance. It replaces the spreadsheets and stalled enterprise GRC tools that scatter a compliance program across files and inboxes.

Assessment Management

Run the complete 800-171 self-assessment lifecycle in one place, with campaign targeting, live progress, and scoring. Isora’s prebuilt NIST questionnaire library lets teams launch assessments directly, without building the questionnaire first.

Questionnaires and Evidence

Questionnaires and evidence collection let control owners across the organization attach documentation inline, next to the question it supports, in an interface designed for non-technical users.

Risk Register and Remediation

Capture every finding and assign ownership, milestones, and statuses in a risk register with remediation tracking.

Reports and Scorecards

Generate scorecards and drill-down reports from live assessment data so teams can see the gaps across units of work. Isora GRC reports the gaps and posture, but it does not implement controls, calculate or guarantee the official SPRS score, or issue a certification.

See the GRC Assessment Platform in action

Key Takeaways

NIST 800-171 compliance can be challenging, especially for multi-framework GRC programs.

The steps to CMMC might sound simple — scope the CUI boundary, write the SSP, self-assess against the DoD methodology, post the score to SPRS, track every gap in a POA&M, then remediate and reassess within the three-year window. But getting scope and version right at the start is key to prevent rework.

Isora GRC is the GRC Assessment Platform™ that simplifies NIST 800-171 compliance for complex organizations.

See Isora GRC in action

NIST 800-171 Compliance FAQs

How long does it take to become NIST 800-171 compliant?

A gap or self-assessment usually takes four to eight weeks, and organizations with modest gaps can close them in roughly four months. Full end-to-end compliance for a mid-size contractor with real gaps typically runs 12–24 months, because most of the time goes to writing the SSP, gathering evidence, and fixing high-weight technical controls. (VSO/practitioner field data, 2025)

How do you become NIST 800-171 compliant?

Compliance follows six steps: scope the CUI boundary, write the System Security Plan, self-assess against the DoD Assessment Methodology, post the resulting score to SPRS, build a POA&M for every gap, then remediate and reassess. Compliance is self-attested under DFARS 252.204-7012, so the SPRS score and its supporting evidence must hold up to a DoD audit.

Is there a NIST 800-171 compliance checklist?

Yes. At minimum, compliance requires a scoped CUI environment, a current System Security Plan, a self-assessment against all 110 Rev 2 requirements, an SPRS score, and a Plan of Action and Milestones (POA&M) covering open gaps. DFARS assessments still use Rev 2 (110 requirements across 14 families) under DoD Class Deviation 2024-O0013 (Crowell, 2024).

What is an SSP and a POA&M in NIST 800-171?

The System Security Plan (SSP) documents how the organization implements each 800-171 requirement and the boundary it applies to. The Plan of Action and Milestones (POA&M) lists every unmet requirement with an owner, remediation steps, and a completion date. NIST publishes official CUI templates for both (NIST, 2021).

How much does NIST 800-171 compliance cost?

There is no published fixed cost; it scales with scope size, the number of high-weight technical gaps (FIPS-validated cryptography and MFA are the most common), and whether the organization builds a dedicated enclave. A technically-enforced enclave that right-sizes scope can materially cut remediation effort (practitioner field data, 2025). Any specific dollar figure should be treated as unverified.

What are the most-failed NIST 800-171 requirements?

DoD (DIBCAC) assessments find the most common failures are FIPS-validated cryptography (3.13.11), failed by roughly half of assessed contractors, multi-factor authentication (3.5.3), failed by about three-quarters, and audit and accountability controls (CyberSheath/DIBCAC data, 2025). FIPS requires a CMVP-validated module running in FIPS mode, and MFA must cover privileged and non-privileged network access to CUI.

Which NIST 800-171 requirements cannot be covered by a POA&M?

Under the CMMC rule (32 CFR 170.21), six requirements cannot be deferred with a POA&M: External Connections, Control Public Information, System Security Plan, Escort Visitors, Physical Access Logs, and Manage Physical Access. A POA&M is only permitted above an 80% score and must be closed within 180 days (32 CFR 170.21, 2024).

Is NIST 800-171 compliance the same as CMMC certification?

No. NIST 800-171 compliance is self-attested through an SPRS score under DFARS, while CMMC Level 2 is the DoD certification program built on the same 110 requirements, adding an independent assessment on top of that self-assessment. Being “800-171 compliant” is the technical baseline for CMMC Level 2, not a certification in itself (practitioner analysis, 2025).

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Learn More
Our GRC Resources

Dive into our research-backed resources–from product one pagers and whitepapers, to webinars and more–and unlock the transformative potential of powerfully simple GRC.

Learn More
Other Relevant Content

CMMC Assessment & Audit: Types, Process, and How to Prepare A CMMC audit is the common name for a CMMC assessment, the formal evaluation that...

CMMC Certification: How to Get Your Organization Certified CMMC certification is the formal determination that a U.S. Department of Defense (DoD)...

CMMC Compliance: How to Achieve and Maintain It CMMC compliance means a Department of Defense (DoD) contractor has implemented the cybersecurity...

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Book a Demo