Frameworks
NIST SP 800-171 — Protecting CUI
110 requirements every defense-supply-chain company must meet — and now prove, under CMMC.
Book a demoNIST 800-171 protects Controlled Unclassified Information in non-federal systems — the security bar for anyone in the US defense supply chain. Its 110 requirements were long self-attested; CMMC now adds third-party assessment, and self-assessment scores are already contract-relevant.
From self-attestation to assessment
The 110 requirements across 14 families map closely to 800-53 Moderate. The operative artifacts are the System Security Plan, the POA&M for gaps, and the SPRS score your primes can see. With CMMC Level 2 assessments phasing into contracts, paper compliance is ending.
How Compriska helps
Compriska tracks the 110 requirements as evidenced controls, maintains the POA&M as treatment plans with owners and dates, and keeps assessment-ready documentation current instead of reconstructed before each contract.
Frequently asked questions
What's the difference between 800-171 and CMMC?
800-171 defines the requirements; CMMC is the DoD's verification program layered on top — Level 2 essentially assesses the same 110 requirements, but with a certifying assessor instead of your own signature.
Other frameworks
Automate NIST 800-171 with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo