NIST SP 800-171, requirement by requirement.
If you handle Controlled Unclassified Information for the U.S. government, SP 800-171 defines how you protect it. TruOps keeps each requirement, its evidence, and its gaps in one place.
Mappings are typed exact, partial, or inferred, each with a citation.
NIST Special Publication 800-171 sets security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. Revision 2 contains 110 requirements in 14 families and is the basis of CMMC Level 2; Revision 3, published in May 2024, restructured them into 97 requirements across 17 families. Defense contractors under DFARS 252.204-7012 must implement these requirements.
- You handle CUI and need an SPRS score you can defend
- CMMC Level 2 is in a contract or about to be
- Your POA&M is a spreadsheet that does not match the assessment
- Published by
- NIST
- Revision 2
- 110 requirements, 14 families
- Revision 3
- 97 requirements, 17 families (May 2024)
- Assessment guide
- SP 800-171A
Who needs 800-171
Contractors and subcontractors that process, store, or transmit CUI, most commonly in the U.S. defense industrial base. DoD contractors self-assess against the DoD Assessment Methodology and report a score (up to 110) in the Supplier Performance Risk System (SPRS).
The actual challenge
800-171 is 110 requirements that each need a status, an owner, and proof. A single stale self-assessment is how SPRS scores become fiction.
- Rev. 2 is what CMMC uses; Rev. 3 is what NIST published; teams track neither cleanly.
- Gaps are known but not dated, owned, or closed within the windows CMMC allows.
- Subcontractors have the same obligation and no shared evidence.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts NIST SP 800-171 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
Rev. 2 and Rev. 3
Revision 3 aligned requirements more closely with SP 800-53 Rev. 5 and introduced organization-defined parameters. CMMC Level 2 currently references Revision 2's 110 requirements, so many contractors track both.
How TruOps helps with NIST SP 800-171
Pick NIST SP 800-171 as your anchor, or map it to the framework you already run. TruOps keeps NIST SP 800-171's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your NIST SP 800-171 assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
Gaps become findings with owners and dates, which gives you the data for a plan of action and milestones (POA&M).
If this is your situation
Bring your last SPRS self-assessment or 800-171 workbook. TruOps will score each requirement, turn gaps into owned findings (the data a POA&M needs), and keep technical checks current.
How TruOps helps
- Anchor or map
- Run 800-171 as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your 800-171 assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
How many requirements are in NIST 800-171?
Revision 2 has 110 requirements in 14 families. Revision 3 (May 2024) has 97 requirements in 17 families.
Which revision does CMMC use?
CMMC Level 2 references NIST SP 800-171 Revision 2.
What is an SPRS score?
A self-assessment score, up to 110, calculated with the DoD Assessment Methodology and reported in the Supplier Performance Risk System.
Can TruOps produce a POA&M?
TruOps tracks each gap as a finding with owner, plan, and due date, which is the information a POA&M needs. See What is a POA&M?
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.