Access Control (AC)
22 requirements covering who can access your systems, how they authenticate, and what permissions they have.
Compliance NIST
Complete NIST SP 800-171 guide for defense contractors. Learn what NIST is, how it relates to JCP certification, and how we make compliance simple and affordable.
Overview Requirements
NIST SP 800-171 is the cybersecurity baseline the Defense Logistics Agency expects before it approves a JCP application. It covers protecting Controlled Unclassified Information in non-federal systems, and it ties directly to your SPRS score, System Security Plan, and Plan of Action & Milestones.
For defense contractors seeking DLA JCP certification, NIST compliance is mandatory under DFARS 252.204-7012.
Families 110 controls
NIST SP 800-171 contains 110 security requirements organized into 14 control families. Here's what they cover:
22 requirements covering who can access your systems, how they authenticate, and what permissions they have.
3 requirements ensuring employees understand cybersecurity responsibilities and receive ongoing training.
9 requirements for logging system activities, monitoring events, and maintaining audit records.
9 requirements for establishing baseline configurations and controlling system changes.
11 requirements for verifying user identities and managing authentication mechanisms.
5 requirements for detecting, reporting, and responding to security incidents.
6 requirements for performing system maintenance while maintaining security.
7 requirements for protecting, transporting, and sanitizing physical and digital media.
2 requirements for screening and terminating personnel access appropriately.
6 requirements for securing physical access to facilities and equipment.
5 requirements for identifying, assessing, and responding to security risks.
9 requirements for testing and evaluating security controls effectiveness.
10 requirements for protecting system boundaries, encrypting data, and securing communications.
7 requirements for identifying, reporting, and correcting system flaws.
Assessment Process
Here's what the NIST self-assessment involves and what you need to produce:
Review each of the 110 controls and determine which ones your organization currently meets, partially meets, or does not meet.
Address gaps by implementing missing controls through technical changes and administrative controls.
Create your SSP, document your assessment methodology, and develop a POA&M for any remaining gaps.
Calculate your assessment score based on the NIST scoring methodology and upload it to SPRS in SAM.gov.
Gather supporting evidence for your assessment: screenshots, policy documents, training records, audit logs, and technical configurations.
Myths Common mistakes
Your SPRS score must be uploaded to SAM.gov and must accurately reflect your assessment.
Your SSP must be specific to your systems, including network diagrams, hardware inventories, and detailed control implementations.
If you have unimplemented controls, your POA&M must include realistic timelines and resource allocations.
Simply claiming compliance isn't enough. You need documentation: policy documents, screenshots, training records, and logs.
NIST compliance is just one piece of the JCP certification puzzle. We can handle the assessment and the documentation.