Reference · NIST 800-171 Rev 2 / CMMC Level 2
All 110 NIST 800-171 controls, explained
CMMC Level 2 maps to all 110 security requirements in NIST SP 800-171 Rev 2, organized into 14 families. Each control page below gives the official requirement, a plain-English explanation, the SPRS deduction if unmet, step-by-step remediation, the evidence a C3PAO assessor asks for — and an honest verdict on whether AI prompt monitoring helps with it.
AC — Access Control22 controls
Limit system access to authorized users, processes, and devices
Limit System Access to Authorized Users
Limit System Access to Authorized Transaction Types
Control CUI Flow per Authorizations
Separate Duties to Reduce Risk
Employ Least Privilege
Use Non-Privileged Accounts for Non-Security Functions
Prevent Non-Privileged Users from Executing Privileged Functions
Limit Unsuccessful Logon Attempts
Provide Privacy and Security Notices
Use Session Lock with Pattern-Hiding Displays
Terminate Sessions After Defined Conditions
Monitor and Control Remote Access Sessions
Employ Cryptographic Mechanisms for Remote Access
Route Remote Access via Managed Access Control Points
Authorize Remote Execution of Privileged Commands
Authorize Wireless Access Prior to Allowing Connections
Protect Wireless Access Using Authentication and Encryption
Control Connection of Mobile Devices
Encrypt CUI on Mobile Devices
Verify and Control Connections to External Systems
Limit Use of Portable Storage on External Systems
Control CUI Posted to Publicly Accessible Systems
AT — Awareness & Training3 controls
Ensure personnel are aware of security risks and trained in policies
AU — Audit & Accountability9 controls
Create, protect, and retain system audit records
Create and Retain System Audit Logs
Ensure User Accountability Through Unique Identifiers
Review and Update Logged Events
Alert on Audit Logging Process Failure
Correlate Audit Review, Analysis, and Reporting
Provide Audit Record Reduction and Report Generation
Provide System Clock Capability for Audit Timestamps
Protect Audit Information and Tools from Unauthorized Access
Limit Audit Log Management to Privileged Users
CM — Configuration Management9 controls
Establish and maintain baseline configurations and inventories
Establish and Maintain Baseline Configurations
Establish and Enforce Security Configuration Settings
Track, Review, Approve, and Log Changes to Systems
Analyze Security Impact of Changes Prior to Implementation
Define and Enforce Access Restrictions for Configuration Changes
Employ Principle of Least Functionality
Restrict, Disable, or Prevent Use of Nonessential Programs
Apply Deny-by-Exception Policy to Prevent Use of Unauthorized Software
Control and Monitor User-Installed Software
IA — Identification & Authentication11 controls
Identify and authenticate users, processes, and devices
Identify system users, processes, and devices
Authenticate identities of users, processes, and devices
Use multifactor authentication for local and network access
Employ replay-resistant authentication mechanisms
Prevent reuse of identifiers
Disable identifiers after defined period of inactivity
Enforce minimum password complexity and change of characters
Prohibit password reuse for a specified number of generations
Allow temporary password use with immediate change requirement
Store and transmit only cryptographically-protected passwords
Obscure feedback of authentication information
IR — Incident Response3 controls
Establish operational incident-handling capability
MA — Maintenance6 controls
Perform timely maintenance on organizational systems
Perform maintenance on organizational systems
Provide controls on tools and personnel for maintenance
Ensure equipment removed for offsite maintenance is sanitized
Check media containing diagnostic programs for malicious code
Require multifactor authentication for nonlocal maintenance
Supervise maintenance activities without required access authorization
MP — Media Protection9 controls
Protect, sanitize, and destroy media containing CUI
Protect system media containing CUI
Limit access to CUI on system media
Sanitize or destroy system media before disposal or reuse
Mark media with necessary CUI markings and distribution limitations
Control access to media containing CUI during transport
Implement cryptographic mechanisms to protect CUI during transport
Control use of removable media on system components
Prohibit use of portable storage without identifiable owner
Protect backups of CUI at storage locations
PS — Personnel Security2 controls
Screen individuals and protect CUI during personnel actions
PE — Physical Protection6 controls
Limit physical access to systems and protect physical plant
RA — Risk Assessment3 controls
Periodically assess risk to operations, assets, and individuals
CA — Security Assessment4 controls
Assess, monitor, and correct deficiencies in security controls
SC — System & Communications Protection16 controls
Monitor, control, and protect communications at boundaries
Monitor and Protect Communications at Boundaries
Implement Subnetworks for Public Components
Employ Effective Security Architecture
Separate User and System Management Functionality
Prevent Unauthorized Info Transfer via Shared Resources
Deny Network Traffic by Default
Prevent Remote Device Split Tunneling
Encrypt CUI in Transit
Terminate Sessions After Inactivity
Establish and Manage Cryptographic Keys
Employ FIPS-Validated Cryptography
Prohibit Remote Activation of Collaborative Devices
Control Mobile Code
Control VoIP Technologies
Protect Authenticity of Communication Sessions
Protect Confidentiality of CUI at Rest
SI — System & Information Integrity7 controls
Identify, report, and correct system flaws in a timely manner
Identify, Report, and Correct System Flaws
Provide Malicious Code Protection
Update Malicious Code Protection Mechanisms
Perform Periodic and Real-Time Malware Scans
Monitor Security Alerts and Advisories
Monitor Systems for Attacks
Identify Unauthorized System Use
Turn this list into your SPRS score
The free ShieldReady assessment walks all 110 controls and computes your score as you go.