Skip to content

    Articles tagged: NIST 800-171

    15 articles on NIST 800-171 from the Top Floor insights library.

    • 2026-08-25

      How to Identify CUI in Your Environment: A Five-Step Procedure

      You do not decide what is CUI; the designating agency does. What you decide is where it landed. The procedure runs from the contract clause to the marking to the inbox to the file server, and it ends in three documents an assessor will ask for by name.

    • 2026-08-23

      What Is a System Security Plan (SSP)?

      The SSP is not paperwork produced for an assessment. It is the document the assessment is conducted against, and 32 CFR 170.17 requires its name, date and version to be filed with your results.

    • 2026-08-23

      Is CMMC Level 2 the Same as NIST 800-171?

      The regulation says the requirements are identical, in those words, and our own control crosswalk agrees control for control: both lenses reach the same 218 NIST 800-53 controls. Everything CMMC adds sits outside the standard, which is exactly where the cost is.

    • 2026-08-22

      Does Your MSP Need CMMC? External Service Provider Rules

      Your managed service provider almost certainly does not need its own CMMC certification, and neither does your cloud provider. Cloud carries a different obligation, and it lands on you: FedRAMP Moderate equivalency. What 32 CFR 170.19 and DFARS 252.204-7012 actually require of the vendors inside your boundary.

    • 2026-08-22

      NIST 800-171 Rev 2 or Rev 3: Which One You Actually Owe

      CMMC Level 2 is Revision 2, in the regulation's own words, and a DoD class deviation pins DFARS 7012 to Revision 2 until it is rescinded. Revision 3 is real, it is coming from a different direction, and rebuilding for it now is a mistake.

    • 2026-08-22

      CMMC Enclave or Full Scope: How to Decide

      The enclave decision is about people, not company size. If a minority of your staff touch CUI, a boundary pays. If most of them do, a boundary they cross daily will not survive an assessment. The asset categories, the crossover, and the hidden costs.

    • 2026-08-22

      How Long Does CMMC Level 2 Take?

      Six to eighteen months to assessment-ready, and nobody can currently tell you when an assessor will be available. The capacity arithmetic from DoD's own rule, why evidence maturity is the long pole, and what the suspension actually buys you.

    • 2026-08-22

      How to Choose a C3PAO, and When to Book One

      The regulation already guarantees more about a C3PAO than most buyers realize, which means the usual vetting questions are wasted. What 32 CFR 170.9 requires, what genuinely differs between assessors, and why most contractors should not book one right now.

    • 2026-08-16

      CMMC Phase 2 Is Suspended: What Still Applies in 2026?

      The Department of War suspended CMMC Phases 2 through 4 on July 13, 2026. Almost nothing a defense contractor already owed went away with them. What paused, what did not, and what to do with the gap.

    • 2026-08-16

      What CMMC Level Do You Need? A Decision Tree by Data Type

      Your CMMC level is set by the information you handle, not by your contract size, your headcount, or your prime's certification. The decision rule, the three levels, and the edge cases that trip up small subcontractors.

    • 2026-08-16

      FCI vs CUI: How to Tell What Your Company Actually Handles

      FCI is nearly universal among federal contractors. CUI is the narrower category that triggers CMMC Level 2. The definitions, the identification test that works when markings are missing, and the one email that expands your scope.

    • 2026-08-16

      How to Calculate Your SPRS Score (Negative Is Normal)

      The scoring rule is one paragraph: start at 110, subtract 5, 3, or 1 per unimplemented requirement, with partial credit in exactly two named cases. Negative first scores are ordinary. What the submission legally commits you to is the part nobody leads with.

    • 2026-08-16

      CMMC POA&M Rules: What You Can Defer, and for How Long

      The regulation is unusually specific: 80 percent to qualify, 1-point requirements only, six named exclusions, one 3-point exception, and 180 days to close. The practical translation is less generous than the headline.

    • 2026-08-16

      CMMC Flow-Down: What Primes Can and Cannot Require of Subs

      A prime cannot make you Level 2 by being Level 2. The level follows the data they share. How to answer the questionnaire on your desk without over-committing, and where regulation ends and contract begins.

    • 2026-02-14

      CMMC 2.0: What Changed and What to Do Now

      The CMMC 2.0 final rule took effect in December 2024, fundamentally restructuring how the Department of Defense evaluates contractor cybersecurity. This guide covers what changed from CMMC 1.0, the three-level model, C3PAO assessments, and what defense contractors should be doing right now to prepare.