Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch

Free Download · NIST 800-171 Rev 3 + CMMC 2.0

The complete NIST 800-171 + CMMC 2.0 checklist.

All 14 control families, all 110 controls, mapped to NIST 800-171 Rev 3 (May 2024) and CMMC 2.0 Level 2. Includes the DFARS 252.204-7012 flow-down tracker, the SPRS scoring methodology, and the CUI scope determination worksheet your prime keeps asking about. Download immediately, no credit card.

  • 14 control families
  • 110 controls (Rev 3)
  • 320 assessment objectives
  • DFARS 7012 / 7019 / 7020 / 7021

Trusted by DoD contractors and CUI handlers across the Defence Industrial Base, aerospace primes, federal contractors, and Tier 2 suppliers running NIST 800-171 + CMMC 2.0 readiness on the same control library.

BoseIberdrola USAJohnson & JohnsonPfizerPuma North AmericaSeaWorld Entertainment

What's Inside · 14 Families · 110 Controls

Every control family the C3PAO will grade you against.

NIST 800-171 Rev 3 was published May 2024 with tightened scoping language, clearer assessor-facing requirements, and explicit alignment to NIST 800-53 r5 parent controls. CMMC 2.0 Level 2 reuses all 110 controls with a third-party C3PAO assessment layered on top. The checklist groups every control + sub-objective by family so you can self-assess in the order an assessor walks them.

22
3.1

Access Control

  • Least privilege, MFA for privileged + remote access (3.5.3)
  • Mobile device + remote-access encryption
  • Wireless access authorisation
3
3.2

Awareness + Training

  • Security awareness for all CUI handlers
  • Role-based training for privileged users
  • Insider-threat awareness
9
3.3

Audit + Accountability

  • Audit logging on CUI systems
  • Time stamps + audit log protection
  • Audit reduction + report generation
9
3.4

Configuration Management

  • Baseline configurations + change control
  • Least functionality + restricted software
  • User-installed software policy
11
3.5

Identification + Authentication

  • Unique user identifiers + MFA (3.5.3)
  • FIPS-validated cryptography for authenticators
  • Replay-resistant auth + lockout
3
3.6

Incident Response

  • IR capability across detect / contain / recover
  • DFARS 252.204-7012(c) 72-hour reporting via DIBNet
  • IR plan testing + tracking
6
3.7

Maintenance

  • Controlled maintenance on CUI systems
  • Maintenance personnel authorisation
  • Off-site maintenance media handling
9
3.8

Media Protection

  • Marking + storage + transport of CUI media
  • Sanitisation before disposal
  • Encryption on portable media
2
3.9

Personnel Security

  • Personnel screening before CUI access
  • Termination + transfer access revocation
6
3.10

Physical Protection

  • Physical access controls + visitor logs
  • Alternate work-site protections (remote staff)
  • Monitoring physical access to CUI systems
3
3.11

Risk Assessment

  • Periodic risk assessments
  • Vulnerability scanning + remediation
  • Risk ranking + treatment decisions
4
3.12

Security Assessment

  • System Security Plan (SSP) per 800-171A
  • Plan of Action + Milestones (POA&M)
  • Continuous monitoring + reassessment
16
3.13

System + Communications Protection

  • Network boundary protection
  • FIPS-validated cryptography in transit + at rest
  • Subnet separation + DNS protections
7
3.14

System + Information Integrity

  • Flaw remediation timelines
  • Malicious-code protection
  • Security alert handling + system monitoring

Rev 3 (May 2024) tightens scoping, clarifies assessor language, and aligns explicitly to NIST 800-53 r5 parent controls. CMMC 2.0 Level 2 reuses all 110 controls; Level 3 adds 24 enhanced controls from NIST 800-172.

Why use it

DoD primes are asking for SPRS scores. Phase 2 starts soon.

NIST 800-171 Rev 3 changed the bar (May 2024)

Rev 3 introduced tightened scoping language, four reorganised control families, and explicit mapping to NIST 800-53 r5 parents. If you handle Controlled Unclassified Information (CUI) under any DFARS-flowed contract, aerospace prime, federal civilian agency, or sub-tier supplier, you are required to implement all 110 Rev 3 controls and produce a defensible System Security Plan.

Source · NIST SP 800-171 Rev 3 (csrc.nist.gov)

CMMC 2.0 layers a C3PAO assessment on top

CMMC 2.0 Level 1 (Foundational) covers 15 practices from FAR 52.204-21. Level 2 (Advanced) reuses all 110 NIST 800-171 controls plus the 320 assessment objectives a C3PAO grades against. Level 3 (Expert) adds 24 enhanced controls from NIST 800-172. DFARS clauses 252.204-7012, -7019, -7020, and -7021 are the legal hooks that make these requirements binding on the contract.

Source · DoD CIO · CMMC programme (dodcio.defense.gov)

SPRS reporting + Phase 2 timing is now

Today, contractors self-attest a Supplier Performance Risk System (SPRS) score per DFARS 252.204-7019. Source-selection officials read the score on award decisions. Phase 2 of the CMMC rollout is enforceable November 10, 2026, at that point Level 2 contracts handling CUI require third-party C3PAO certification, not self-attestation. The realistic timeline from gap analysis to a clean assessment is 9–12 months, so the team that starts in 2026 is the team that lands the 2027 contract.

Source · DFARS 252.204-7012 (eCFR)

Who it's for

Built for the three teams running point on CUI handling.

Primary

DoD Compliance Lead / CMMC Lead

You own the SSP, the POA&M, the SPRS submission, and the C3PAO scheduling decision. You need a checklist that maps to the 320 assessment objectives, not just the 110 practices.

Secondary 1

CISO at a federal contractor

Your contracts touch CUI through DFARS flow-down. The SPRS score is now a board-level metric and an audit-committee question. You need a defensible self-assessment with evidence, not a spreadsheet.

Secondary 2

Subcontractor preparing for prime flow-down

Your prime is asking for proof of NIST 800-171 implementation before contract execution. You need the same checklist your prime is grading you against, plus the DFARS 7012(m) flow-down language for any of your own subs.

Trusted by DoD contractors and CUI handlers across the Defence Industrial Base, aerospace primes, federal contractors, and Tier 2 suppliers running NIST 800-171 + CMMC 2.0 readiness on the same control library.

BoseIberdrola USAJohnson & JohnsonPfizerPuma North AmericaSeaWorld EntertainmentTE Connectivity

Related platform pages

If you've outgrown a static PDF and need continuous scoring, SSP/POA&M automation, or DFARS flow-down across subcontractors, these are the three platform pages most lead-magnet downloaders open next.

FAQ

Frequently asked questions

Past the checklist?

CMMC + NIST 800-53 + ATO on one platform?

If you're running NIST 800-171, CMMC 2.0, and a NIST 800-53 ATO at the same time, you don't need three control libraries, you need one. Book a 30-minute walkthrough and we'll show you the cross-framework scoring, the SPRS auto-calculation, and the C3PAO-ready evidence vault on a real DIB tenant.

Or call US: +1 (888) 388-9242

Request a Demo