HIPAA Compliance Checklist for 2025
The U.S. Department of Defense relies on about 200,000 private companies across its defense industrial base. Many of these companies handle sensitive information in their systems, making cybersecurity requirements a practical concern, not just a contractual formality.
That is where NIST SP 800-171 comes in. It provides security requirements for protecting Controlled Unclassified Information (CUI) on nonfederal systems that process, store, or transmit it.
There is also an important version issue to understand. NIST finalized Revision 3 in May 2024, while organizations may still encounter Revision 2 requirements depending on their contractual and CMMC obligations.
This guide breaks down NIST SP 800-171, its requirements, the key differences between Rev. 2 and Rev. 3, its relationship with CMMC, and a practical compliance checklist.
1. What Is NIST SP 800-171?
NIST SP 800-171 is a set of cybersecurity requirements for protecting Controlled Unclassified Information (CUI) on nonfederal systems. It covers areas such as access control, authentication, incident response, and system integrity.
It is not a certification. NIST SP 800-171 defines what organizations need to implement, while NIST SP 800-171A provides procedures to assess those requirements.
In short: SP 800-171 defines the requirements; SP 800-171A assesses them.
2. Who Needs to Comply With NIST SP 800-171?
NIST SP 800-171 comes into play when a nonfederal organization handles Controlled Unclassified Information (CUI) in systems covered by the applicable requirements. This is common among defense contractors and subcontractors, but other organizations may also fall under it when their federal contracts require CUI protection.
A federal contract by itself does not mean the standard applies. What matters is what the contract requires, what CUI the organization handles, and where that information is stored or processed.
Before working through the requirements, map out:
- Where CUI enters, moves, and is stored
- Which systems, devices, and applications handle it
- Who can access it, including contractors and service providers
- Which contractual requirements apply
This scoping step can save a lot of unnecessary work. You may not need to bring every system in the company into scope, but leaving out a system that handles CUI can create a serious compliance gap.
Start with the CUI and its path through your environment. Then define the systems that need to protect it.
3. What Are the NIST SP 800-171 Requirements?
NIST SP 800-171 covers the security practices organizations use to protect Controlled Unclassified Information (CUI) on nonfederal systems. The requirements span access, authentication, system security, incident response, risk management, and other areas that affect how CUI is handled.
Under Rev. 2, the requirements are grouped into 14 families, including:
- Access Control: Limit access to CUI and system resources based on business need.
- Audit and Accountability: Record system activity and maintain enough detail to trace actions.
- Configuration Management: Control system changes and maintain secure configurations.
- Identification and Authentication: Verify users, devices, and other entities before granting access.
- Incident Response: Prepare for, detect, report, and respond to security incidents.
- Risk Assessment: Identify threats and vulnerabilities that could affect CUI.
- Security Assessment: Check whether required security measures are in place and working.
- System and Communications Protection: Protect CUI as it moves between systems and across networks.
- System and Information Integrity: Detects flaws, malicious activity, and other conditions that could compromise systems or information.
The remaining families address areas such as security awareness and training, media protection, personnel security, physical protection, and system maintenance.
One important detail: Rev. 2 and Rev. 3 do not use the same structure or requirement set. So organizations should first confirm which revision applies to their contract or assessment before building a compliance checklist.
4. NIST SP 800-171 Rev. 2 vs. Rev. 3: What’s Changed?
NIST finalized SP 800-171 Rev. 3 in May 2024, but Rev. 2 still matters for organizations whose contracts or assessments reference it. Rev. 3 changes the structure and several requirements, so the two versions should not be treated as interchangeable.
Here are the key differences:
- Control families: Rev. 2 has 14 families, while Rev. 3 has 17.
- Requirement structure: Rev. 3 reorganizes and revises the requirements instead of simply adding new ones.
- Organization-defined parameters: Rev. 3 introduces ODPs for certain requirements, allowing organizations to set values based on their environment.
- Tailoring: Rev. 3 uses an updated tailoring approach and removes the NFO tailoring category used in Rev. 2.
- Alignment: Rev. 3 is more closely aligned with the controls and structure of NIST SP 800-53 Rev. 5.
- Assessment: Rev. 3 has corresponding assessment procedures in NIST SP 800-171A Rev. 3.
What Does This Mean for CMMC?
There is an important distinction here. Current CMMC Level 2 requirements are based on NIST SP 800-171 Rev. 2. The DoD has stated that Rev. 3 will be incorporated through future rulemaking.
So, before building your compliance checklist, confirm which revision your contract or assessment requires. Do not assume that a Rev. 3 checklist can simply replace a Rev. 2 checklist.
5. What Is NIST SP 800-171A?
NIST SP 800-171A helps organizations assess whether they have actually implemented the security requirements in NIST SP 800-171. While SP 800-171 tells you what needs to be protected, SP 800-171A provides the procedures for checking whether those requirements are being met.
An assessment can look at:
- Policies and documentation: What the organization says it does
- Technical mechanisms: How security controls are configured and enforced
- Activities: Whether required processes are actually being followed
- People: Whether responsible staff understand and perform their roles
This distinction matters because having a policy is not the same as having effective control. An assessor needs evidence that the requirement is implemented in the real environment.
For Rev. 3, organizations should use NIST SP 800-171A Rev. 3, which provides the corresponding assessment procedures.
In simple terms: SP 800-171 defines the requirements. SP 800-171A checks whether those requirements are actually in place.
6. What Is the Difference Between NIST SP 800-171 and CMMC?
NIST SP 800-171 and CMMC work together, but they are not the same. NIST SP 800-171 defines the security requirements for protecting CUI, while CMMC is the DoD framework for assessing whether applicable contractors have met their required cybersecurity practices
The practical distinction is simple:
- NIST SP 800-171 → What you need to implement
- SP 800-171A → How implementation can be assessed
- CMMC → How DoD verifies compliance for applicable contracts
So, following NIST SP 800-171 does not automatically mean an organization has CMMC certification. The contract requirements and applicable CMMC level still determine what an organization must demonstrate.
7. How Do You Become Compliant With NIST SP 800-171?
NIST SP 800-171 compliance is more than checking 110 requirements as complete. The real work is showing where CUI exists, how it is protected, and whether the required safeguards actually work. NIST’s requirements apply to the parts of a nonfederal environment that process, store, or transmit CUI, as well as components that protect those systems.
A practical approach looks like this:
- Scope the CUI environment: Identify the CUI, where it resides, how it moves, and which systems, applications, users, and external services are involved.
- Assess each requirement: Compare the current environment with the applicable NIST requirements. Record what is implemented, partially implemented, or missing rather than marking controls complete based only on policy documents.
- Build the SSP: Document the system boundary, security measures, and how the requirements are implemented. NIST does not prescribe a specific SSP format, but the required information must be covered.
- Track gaps and remediation: Assign an owner and target date to each gap. Where applicable, document planned remediation through a Plan of Action and Milestones (POA&M).
- Collect evidence: Keep configuration records, access reviews, logs, policies, training records, assessment results, and other evidence that shows the controls operate in practice.
- Assess and maintain: Use the applicable assessment procedures to test implementation, address findings, and reassess when the environment changes. NIST describes assessments as a way to produce evidence that supports risk-based decisions.
The important shift is from “Do we have a policy?” to “Can we prove the requirement is implemented in the CUI environment?” That is what makes a compliance program defensible rather than just checklist-driven
8. NIST SP 800-171 Compliance Checklist
A good checklist should help you answer one practical question: Where do we stand against each requirement?
Instead of keeping a simple yes/no list, track the details that help your team act on each requirement:
This structure makes the checklist more useful during an assessment. It also gives security and compliance teams a clear way to move from finding → action → verification, rather than repeatedly reviewing the same open issues.
A simple example:
This structure makes the checklist more useful during an assessment. It also gives security and compliance teams a clear way to move from finding → action → verification, rather than repeatedly reviewing the same open issues.
A Simple Example:
The goal is not to create another compliance spreadsheet. The checklist should show what is working, where the gaps are, and whether those gaps have actually been closed.
9. What Documentation Do You Need for NIST SP 800-171?
NIST SP 800-171 compliance needs more than a checklist. You need documentation that shows how your security program works and how the requirements apply to your environment.
The main documents include:
- System Security Plan (SSP): Describes the system, its boundaries, the CUI environment, and how the security requirements are implemented.
- Plan of Action and Milestones (POA&M): Tracks gaps that still need to be addressed, including planned actions and milestones where applicable.
- Policies and procedures: Explain how security processes such as access management, incident response, configuration management, and media protection are handled.
- Assessment records: Document testing, findings, and the results of checking whether controls are actually implemented.
- Supporting evidence: Includes relevant logs, access reviews, configurations, training records, incident records, and other material used to demonstrate implementation.
The important part is keeping these documents consistent with the real environment. If the SSP says one system handles CUI but the environment has changed, the documentation can no longer support the assessment.
Treat the documentation as a living record of your CUI environment, not paperwork created only when an assessment is approaching.
10. What Are the Common NIST SP 800-171 Compliance Challenges and How Can You Address Them?
Even organizations with a mature security program can run into gaps when applying NIST SP 800-171. The difficult part is often not understanding the requirements. It is keeping them aligned with the systems, access, and services that handle CUI
The common thread is keeping compliance connected to the environment as it actually exists. A checklist shows what was reviewed. Ongoing visibility shows whether those controls still hold up.
11. How Can CloudEagle.ai Help With NIST SP 800-171 Compliance?
CloudEagle.ai does not replace NIST SP 800-171, SP 800-171A, or a CMMC assessment. It can support the operational side of compliance by giving teams visibility into the SaaS, AI, identity, and access layers that can affect their security controls.
Teams can use CloudEaglea.ai to:
- Discover SaaS and AI: Find approved, unapproved, and shadow applications across the organization.
- Map access and identities: See users, privileged accounts, service accounts, API keys, tokens, and AI agents connected to applications.
- Spot changes: Detect new applications, integrations, permissions, or access paths that may need review.
- Connect risk to action: Give security teams the context to investigate an issue and route remediation to the right owner.
Armorcode used CloudEagle.ai to raise NHI visibility from 40% to 95%, remediate 480 unmanaged identities, and optimize 220+ over-privileged identities.
The case highlights an important compliance gap: service accounts, tokens, and other non-human identities can also create access paths to applications and data. CloudEagle.ai helps bring these identities into the same visibility and governance process.
12. Conclusion
NIST SP 800-171 compliance is not a one-time checklist. It requires a clear view of where CUI exists, how it is protected, and whether those controls still work as the environment changes.
Organizations that connect requirements with real systems, access, evidence, and remediation can keep compliance practical and assessment-ready.
13. FAQs
1. How many requirements are in NIST SP 800-171?
A. The answer depends on the revision. Rev. 2 contains 110 requirements across 14 families, while Rev. 3 reorganized the requirements into 17 families. Always confirm which revision applies to your contract or assessment.
2. Is NIST SP 800-171 required for CMMC?
A. For CMMC Level 2, the current assessment requirements are based on NIST SP 800-171 Rev. 2. NIST SP 800-171 itself is not the CMMC certification program.
3. What is the difference between NIST SP 800-171 and 800-171A?
A. SP 800-171 defines the security requirements for protecting CUI. SP 800-171A provides the assessment procedures used to evaluate whether those requirements have been implemented.
4. Does NIST SP 800-171 require a System Security Plan (SSP)?
A. Yes. The SSP documents how the applicable security requirements are implemented, including the system boundary and connections to other systems. NIST does not prescribe one fixed SSP format.
5. Does NIST SP 800-171 apply to every government contractor?
A. No. Applicability depends on the contract or agreement, the CUI involved, and the systems handling or protecting that CUI. Having a federal contract alone does not automatically mean every part of an organization's environment falls under SP 800-171.





.avif)




.avif)
.avif)




.png)




.avif)
.avif)
.avif)

