Compliance NIST

NIST SP 800-171 Guide for Defense Contractors

Complete NIST SP 800-171 guide for defense contractors. Learn what NIST is, how it relates to JCP certification, and how we make compliance simple and affordable.

What this guide covers

  • What NIST SP 800-171 is
  • How it relates to JCP certification
  • The 110 control families
  • What DLA actually checks
  • How to handle gaps and SPRS

Overview Requirements

What NIST SP 800-171 means for JCP

NIST SP 800-171 is the cybersecurity baseline the Defense Logistics Agency expects before it approves a JCP application. It covers protecting Controlled Unclassified Information in non-federal systems, and it ties directly to your SPRS score, System Security Plan, and Plan of Action & Milestones.

For defense contractors seeking DLA JCP certification, NIST compliance is mandatory under DFARS 252.204-7012.

Families 110 controls

Understanding the 110 NIST controls

NIST SP 800-171 contains 110 security requirements organized into 14 control families. Here's what they cover:

Access Control (AC)

22 requirements covering who can access your systems, how they authenticate, and what permissions they have.

Awareness and Training (AT)

3 requirements ensuring employees understand cybersecurity responsibilities and receive ongoing training.

Audit and Accountability (AU)

9 requirements for logging system activities, monitoring events, and maintaining audit records.

Configuration Management (CM)

9 requirements for establishing baseline configurations and controlling system changes.

Identification and Authentication (IA)

11 requirements for verifying user identities and managing authentication mechanisms.

Incident Response (IR)

5 requirements for detecting, reporting, and responding to security incidents.

Maintenance (MA)

6 requirements for performing system maintenance while maintaining security.

Media Protection (MP)

7 requirements for protecting, transporting, and sanitizing physical and digital media.

Personnel Security (PS)

2 requirements for screening and terminating personnel access appropriately.

Physical Protection (PE)

6 requirements for securing physical access to facilities and equipment.

Risk Assessment (RA)

5 requirements for identifying, assessing, and responding to security risks.

Security Assessment (CA)

9 requirements for testing and evaluating security controls effectiveness.

System and Communications Protection (SC)

10 requirements for protecting system boundaries, encrypting data, and securing communications.

System and Information Integrity (SI)

7 requirements for identifying, reporting, and correcting system flaws.

Assessment Process

The NIST assessment process

Here's what the NIST self-assessment involves and what you need to produce:

  1. Gap analysis

    Review each of the 110 controls and determine which ones your organization currently meets, partially meets, or does not meet.

  2. Control implementation

    Address gaps by implementing missing controls through technical changes and administrative controls.

  3. Documentation

    Create your SSP, document your assessment methodology, and develop a POA&M for any remaining gaps.

  4. SPRS score calculation

    Calculate your assessment score based on the NIST scoring methodology and upload it to SPRS in SAM.gov.

  5. Evidence collection

    Gather supporting evidence for your assessment: screenshots, policy documents, training records, audit logs, and technical configurations.

Critical NIST requirements

  • SPRS score submission
  • System Security Plan (SSP)
  • Plan of Action & Milestones (POA&M)
  • Assessment methodology
  • Evidence collection and documentation

Myths Common mistakes

Common NIST compliance mistakes

Missing or incorrect SPRS score

Your SPRS score must be uploaded to SAM.gov and must accurately reflect your assessment.

Incomplete System Security Plan

Your SSP must be specific to your systems, including network diagrams, hardware inventories, and detailed control implementations.

Unrealistic POA&Ms

If you have unimplemented controls, your POA&M must include realistic timelines and resource allocations.

Insufficient evidence

Simply claiming compliance isn't enough. You need documentation: policy documents, screenshots, training records, and logs.

Read the related blog post →

Need help with NIST compliance?

NIST compliance is just one piece of the JCP certification puzzle. We can handle the assessment and the documentation.