Frameworks

NIST SP 800-171 — Protecting CUI

110 requirements every defense-supply-chain company must meet — and now prove, under CMMC.

Book a demo

NIST 800-171 protects Controlled Unclassified Information in non-federal systems — the security bar for anyone in the US defense supply chain. Its 110 requirements were long self-attested; CMMC now adds third-party assessment, and self-assessment scores are already contract-relevant.

From self-attestation to assessment

The 110 requirements across 14 families map closely to 800-53 Moderate. The operative artifacts are the System Security Plan, the POA&M for gaps, and the SPRS score your primes can see. With CMMC Level 2 assessments phasing into contracts, paper compliance is ending.

How Compriska helps

Compriska tracks the 110 requirements as evidenced controls, maintains the POA&M as treatment plans with owners and dates, and keeps assessment-ready documentation current instead of reconstructed before each contract.

Frequently asked questions

What's the difference between 800-171 and CMMC?

800-171 defines the requirements; CMMC is the DoD's verification program layered on top — Level 2 essentially assesses the same 110 requirements, but with a certifying assessor instead of your own signature.

Other frameworks

Automate NIST 800-171 with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo