What is on a NIST SP 800-171 compliance checklist?
A NIST SP 800-171 checklist for CMMC Level 2 covers all 110 requirements of Revision 2 across 14 families, from access control to system integrity, plus the work around them: scoping where CUI lives, writing a System Security Plan, scoring with the DoD methodology, tracking gaps in a POA&M, posting to SPRS and annual affirmation. Use Rev 2, not Rev 3, for CMMC.
Start with scope
Before touching controls, list every person, system, application, cloud service and outside provider that processes, stores or transmits CUI. That boundary determines what the checklist applies to. A smaller boundary means fewer systems to secure and evidence.
The 14 requirement families
NIST SP 800-171 Rev 2 organizes its 110 requirements into fourteen families:
- Access Control; Awareness and Training; Audit and Accountability
- Configuration Management; Identification and Authentication; Incident Response
- Maintenance; Media Protection; Personnel Security; Physical Protection
- Risk Assessment; Security Assessment
- System and Communications Protection; System and Information Integrity
The documentation checklist
- System Security Plan describing how each requirement is met. It cannot be deferred to a POA&M.
- Plan of Action and Milestones for remaining gaps, within the CMMC limits.
- Policies and procedures that match what your staff actually do.
- Evidence: configurations, logs, training records, visitor logs, access reviews.
- Customer responsibility matrices from your cloud and service providers.
- Incident response plan that supports 72-hour reporting under DFARS 252.204-7012.
Common gaps
The requirements that most often trip companies up are multifactor authentication, FIPS-validated encryption for CUI, centralized audit logging and review, controls over removable media, and physical access records. Under the CMMC POA&M rules, a non-FIPS encryption gap can be carried only if encryption is in place, and physical access items such as escorting visitors and access logs cannot be carried at all.
Finally, score honestly. Your SPRS score is affirmed by a senior official, and while Phase 2 is suspended, that self-assessment is what DoD relies on.
How to work the checklist
Assign every requirement an owner, a status of met, not met or not applicable, and a pointer to its evidence. Not applicable needs a written reason. Review the full list at least quarterly with your IT lead and compliance owner rather than once before an assessment, because the senior-official affirmation is annual and your environment changes between affirmations.
Treat the SSP as the master record: if a control changes, update the SSP and the evidence at the same time. Keep customer responsibility matrices from every cloud and service provider attached, so the shared requirements are clearly split between them and your company.
Common follow-up questions
Should I use NIST SP 800-171 Rev 2 or Rev 3?
For CMMC, use Rev 2. NIST published Rev 3 in May 2024 and withdrew Rev 2, but the CMMC rule states Rev 3 is not currently applicable and DoD's July 2026 memo describes Level 2 as aligned with Rev 2.
What score do I need?
Full compliance is 110 points. CMMC allows a conditional Level 2 status at 80 percent of the maximum, 88 of 110, if the open items are eligible for a POA&M and are closed within 180 days.
Is a checklist enough to pass?
No. A checklist shows what to address. Passing requires each requirement to be implemented and supported by evidence, documented in your SSP and kept current so a senior official can affirm it every year.
LAN Service Group's ISSO-led team runs NIST SP 800-171 gap assessments, writes the SSP and POA&M, and remediates the technical gaps for defense suppliers.
Talk to LAN Service Group (888) 281-7243