NIST 800-171 Compliance for Small Defense Businesses
Small defense businesses need a defined CUI environment, working safeguards, and records that support their contract-required assessments. Revision 2 remains the current defense baseline.

As of September 7, 2026, current defense guidance retains the 110 requirements in Revision 2. The suspension of CMMC Phase II has not suspended those safeguarding duties. A business handling covered defense information still needs a defined system boundary, working controls, accurate records, and the assessment status its contract requires. Current CMMC implementation guidance
On This Page
- Determine which information and contract terms apply
- Use the required revision and assessment path
- Define the boundary before buying tools
- Turn the requirements into operating records
- Check the gaps that paperwork can hide
- Prepare for the next contract decision
Determine which information and contract terms apply
Start with the solicitation, amendments, executed contract, and any prime-contractor flowdowns. Under DFARS 252.204-7012, a covered contractor information system is an unclassified system operated by or for a contractor that handles covered defense information. That information can include controlled technical information supplied for contract performance or information developed during the work. The clause also contains flowdown requirements for qualifying subcontracts, including commercial products and services. Small company size does not create an exemption in that clause. DFARS 252.204-7012
Three distinctions prevent an expensive false start:
- Public information is different from nonpublic federal contract information (FCI).
- FCI is broader than controlled unclassified information (CUI). CMMC Level 1 addresses FCI; Level 2 addresses CUI.
- CUI requires a safeguarding or dissemination basis in law, regulation, or government-wide policy. An internal label such as “confidential†does not, by itself, establish that basis. Official information definitions
Ask the contracting officer or the prime's contracts contact to resolve unclear information designations and flowdowns in writing. Give them the actual document category and intended business use. A generic question about whether the company “needs NIST†is too broad to settle which systems require protection.
For example, a hypothetical machine shop might receive a public part catalog for one order and controlled engineering drawings for another. Map the second job from receipt through engineering, production, inspection, delivery, and retention. Include copies created along the way. That exercise gives contracts and IT a shared description of the work before either commits to an implementation plan.
Use the required revision and assessment path
NIST published Revision 3 in May 2024 and withdrew Revision 2 as a NIST publication. That publication history does not automatically replace the revision incorporated into a defense obligation. NIST's newer small-business primer expressly covers Revision 3, so it should not be used as a substitute checklist for a Revision 2 assessment. NIST revision history; Revision 3 small-business primer
The July 2026 implementation memorandum preserves DFARS 252.204-7012 duties and directs requiring activities to use Level 1 (Self) or Level 2 (Self) during the CMMC suspension. It directs amendments to affected active solicitations and modifications to existing contracts containing the suspended assessment requirements. Confirm the amendment or modification applicable to your work; an announcement is not an executed contract change. CMMC suspension implementation memorandum
Also check clause numbers and dates. The February 2026 DFARS overhaul text introduced 252.240-7997, which provides for government Medium and High NIST assessments, including access to facilities, systems, and personnel. Older paperwork may refer to 252.204-7019 and 252.204-7020. Have contracts identify the incorporated assessment language and applicable deviation before recycling an old submission checklist. February 2026 Part 240 deviation and assessment clause
For a contract requiring CMMC Level 2 (Self), the company must achieve the required status and submit its affirmation in the Supplier Performance Risk System (SPRS) before award. Self-assessment recurs every three years, with affirmation at assessment and annually thereafter. The entry includes the scope, associated Commercial and Government Entity (CAGE) codes, score, and applicable remediation status. A general claim of NIST compliance does not replace that record. 32 CFR 170.16
Define the boundary before buying tools
A CUI environment can be a defined part of a business, but its boundary must match actual use. Under the Level 2 scoping rule, CUI assets and security-protection assets have different assessment treatment. Contractor risk-managed assets and specialized equipment also require appropriate documentation. Calling a production machine “legacy†does not make it disappear from the scoping exercise. 32 CFR 170.19, Level 2 asset categories
For the machine-shop example, walk one controlled drawing through the proposed environment. Can an employee download it to an ordinary laptop, attach it to an email, print it on a shared copier, or place it in a supplier portal? Where do backups and inspection results go? These are practical checks of the proposed boundary, not assertions that every device must receive identical treatment.
Outsourcing also needs explicit allocation of work. Section 170.19 requires the external service provider's relationship and services to be documented in the system security plan, service description, and customer responsibility matrix. Identify who handles account removal, logs, configuration changes, and incident escalation. A provider's own assessment does not establish the customer's configuration or employee practices.
Cloud storage adds a specific contractual check: DFARS 252.204-7012 requires the contractor to ensure an external provider handling covered defense information meets FedRAMP Moderate-equivalent requirements and the clause's applicable incident-related duties. Ask for documentation covering the exact service and customer responsibilities, rather than relying on a provider's general security claim. Cloud-provider requirements
Turn the requirements into operating records
Revision 2 organizes its requirements into 14 families. The table groups them by the business work involved; it does not replace the individual requirements or prescribe a mandatory document format.
| Requirement families | Practical records to connect to the work |
|---|---|
| Access Control; Identification and Authentication | Approved users, privileges, authentication settings, and account-removal records |
| Awareness and Training; Personnel Security | Role-specific training and staff onboarding, transfer, and departure records |
| Audit and Accountability | Logging configuration, review records, and investigated exceptions |
| Configuration Management; Maintenance | Asset baselines, authorized changes, and maintenance access records |
| Media Protection; Physical Protection | Media handling, disposal, facility access, and visitor records |
| Risk Assessment; System and Information Integrity | Risk reviews, vulnerability findings, remediation, and protective-system records |
| Incident Response | Response responsibilities, exercises, and incident records |
| Security Assessment; System and Communications Protection | System security plan, control reviews, boundary protections, and cryptographic implementation details |
Family names come from NIST SP 800-171 Revision 2. The record groupings are editorial implementation examples, informed by the examination, interview, and testing methods in NIST SP 800-171A, June 2018.
The system security plan (SSP) describes the system boundary, operating environment, implementation of requirements, and connections to other systems. Requirement 3.12.4 calls for periodic updates. Use the SSP to describe what exists, and a plan of action to identify deficiencies and their correction. A future installation belongs in remediation planning, not in a statement that the requirement is already implemented.
Assign each requirement an owner who can explain the implementation and produce its supporting records. One person may own several requirements in a small business. The useful distinction is between responsibility for doing the work and responsibility for confirming that the work happened.
Under CMMC Level 2 self-assessment procedures, assessment artifacts must be retained for six years from the CMMC Status Date. Keep a dated assessment set even as operational records and the SSP continue to change. That preserves the basis for the reported result. Level 2 assessment and retention procedures
Check the gaps that paperwork can hide
The following are failure modes to test, rather than a ranking of measured industry failures.
Authentication coverage stops at email. NIST's June 2018 assessment procedure for requirement 3.5.3 checks privileged-account identification and multifactor authentication for local and network access to privileged accounts, plus network access to nonprivileged accounts. Test the relevant access paths. An email administrator's screenshot cannot establish coverage of every path. Assessment objective 3.5.3
Encryption is enabled without checking its validation. Revision 2 requirement 3.13.11 calls for FIPS-validated cryptography when cryptography protects CUI confidentiality. FIPS refers to Federal Information Processing Standards. Ask the implementer to identify the cryptographic implementation and its validation basis; a product's use of the word “encrypted†does not settle that requirement. Requirement 3.13.11
A tool is installed, but nobody performs the recurring work. Select an actual recent event, such as a departing employee or a vulnerability finding, and follow it to closure. Ask who approved the action, who performed it, and what record remains. This is an application of NIST's examination, interview, and testing approach: policy text, staff understanding, and system behavior must support the assessment result.
The remediation list is treated as a passing score. Conditional CMMC Level 2 requires at least 88 out of 110 and restrictions on which unmet requirements may enter a plan of action and milestones (POA&M). The SSP requirement itself cannot be deferred through that conditional path. Closeout must occur within 180 days of the conditional status date; otherwise, the status expires. A score alone therefore does not establish eligibility for conditional status. 32 CFR 170.21
The incident procedure ends with calling IT. DFARS 252.204-7012 requires qualifying cyber incidents to be reported within 72 hours of discovery and affected system images and relevant monitoring data to be preserved for at least 90 days after reporting. Name the reporting lead and backup in advance. These incident records serve a different purpose from the six-year assessment artifacts. Incident reporting and preservation duties
Prepare for the next contract decision
Before accepting a new CUI workflow or representing readiness for an award, bring contracts, the system owner, and the business leader together around five questions:
- Which contract language and information designations establish the obligation?
- Does the documented boundary match how employees and providers actually handle the information?
- Can the responsible staff demonstrate implementation and retrieve the supporting records?
- Are open deficiencies accurately described, funded, and assigned for correction?
- Does the required assessment status and affirmation cover the systems used for this work?
For a small defense business, that review should drive the spending decision. Fund the unresolved access path, missing operating process, or unsupported implementation claim identified in the review. Expand the protected environment only with a clear understanding of the additional systems and responsibilities it brings.
Source notes
- CIO CMMC overview: current implementation guidance, protected information, and Revision 2 baseline.
- DFARS 252.204-7012: contract clause covering information, cloud providers, incidents, preservation, and flowdowns.
- NIST Revision 2 publication record: withdrawal and superseding publication history.
- NIST small-business primer: introductory guidance explicitly written for Revision 3.
- CMMC suspension implementation memorandum: procurement instructions and continuing safeguarding duties.
- February 2026 Part 240 deviation: assessment clause 252.240-7997; check the deviation incorporated in the individual procurement.
- 32 CFR 170.16: Level 2 self-assessment, affirmation, SPRS, and artifact retention.
- 32 CFR 170.19: assessment scope, asset categories, and provider responsibilities.
- NIST SP 800-171 Revision 2: the security requirements, families, and system security plan.
- NIST SP 800-171A, June 2018: assessment methods and authentication objectives used with the Level 2 baseline.
- 32 CFR 170.21: conditional-status limitations and POA&M closeout.
Last checked: September 7, 2026.
Documentation
Sources
These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.
- CIO CMMC overviewDepartment of War CIO · Publication date not recorded · checked September 7, 2026
- DFARS 252.204-7012Acquisition.gov · Publication date not recorded · checked September 7, 2026
- NIST Revision 2 publication recordNIST · Publication date not recorded · checked September 7, 2026
- NIST Revision 3 small-business primerNIST · Publication date not recorded · checked September 7, 2026
- CMMC suspension implementation memorandumDepartment of War CIO · Publication date not recorded · checked September 7, 2026
- February 2026 Part 240 deviationDefense Acquisition Regulations System · Publication date not recorded · checked September 7, 2026
- 32 CFR 170.16eCFR · Publication date not recorded · checked September 7, 2026
- 32 CFR 170.19eCFR · Publication date not recorded · checked September 7, 2026
- NIST SP 800-171 Revision 2NIST · Publication date not recorded · checked September 7, 2026
- NIST SP 800-171A, June 2018NIST · Publication date not recorded · checked September 7, 2026
- 32 CFR 170.21eCFR · Publication date not recorded · checked September 7, 2026