AnalysisAnalysis

NIST 800-171 Compliance for Small Defense Businesses

Small defense businesses need a defined CUI environment, working safeguards, and records that support their contract-required assessments. Revision 2 remains the current defense baseline.

ByMilitary Contractor Editorial
PublishedSeptember 7, 2026
Last checkedSeptember 7, 2026
Reading time10 minutes
A uniformed technician inspects equipment between server racks and bundles of network cables.
A Joint Interoperability Test Command technician inspects server equipment at Fort Huachuca, Arizona, in September 2024. The photograph illustrates system maintenance, not evidence of a small business's NIST compliance. The appearance of U.S. Department of War (DoW) visual information does not imply or constitute DoW endorsement.

As of September 7, 2026, current defense guidance retains the 110 requirements in Revision 2. The suspension of CMMC Phase II has not suspended those safeguarding duties. A business handling covered defense information still needs a defined system boundary, working controls, accurate records, and the assessment status its contract requires. Current CMMC implementation guidance

On This Page

Determine which information and contract terms apply

Start with the solicitation, amendments, executed contract, and any prime-contractor flowdowns. Under DFARS 252.204-7012, a covered contractor information system is an unclassified system operated by or for a contractor that handles covered defense information. That information can include controlled technical information supplied for contract performance or information developed during the work. The clause also contains flowdown requirements for qualifying subcontracts, including commercial products and services. Small company size does not create an exemption in that clause. DFARS 252.204-7012

Three distinctions prevent an expensive false start:

  • Public information is different from nonpublic federal contract information (FCI).
  • FCI is broader than controlled unclassified information (CUI). CMMC Level 1 addresses FCI; Level 2 addresses CUI.
  • CUI requires a safeguarding or dissemination basis in law, regulation, or government-wide policy. An internal label such as “confidential” does not, by itself, establish that basis. Official information definitions

Ask the contracting officer or the prime's contracts contact to resolve unclear information designations and flowdowns in writing. Give them the actual document category and intended business use. A generic question about whether the company “needs NIST” is too broad to settle which systems require protection.

For example, a hypothetical machine shop might receive a public part catalog for one order and controlled engineering drawings for another. Map the second job from receipt through engineering, production, inspection, delivery, and retention. Include copies created along the way. That exercise gives contracts and IT a shared description of the work before either commits to an implementation plan.

Use the required revision and assessment path

NIST published Revision 3 in May 2024 and withdrew Revision 2 as a NIST publication. That publication history does not automatically replace the revision incorporated into a defense obligation. NIST's newer small-business primer expressly covers Revision 3, so it should not be used as a substitute checklist for a Revision 2 assessment. NIST revision history; Revision 3 small-business primer

The July 2026 implementation memorandum preserves DFARS 252.204-7012 duties and directs requiring activities to use Level 1 (Self) or Level 2 (Self) during the CMMC suspension. It directs amendments to affected active solicitations and modifications to existing contracts containing the suspended assessment requirements. Confirm the amendment or modification applicable to your work; an announcement is not an executed contract change. CMMC suspension implementation memorandum

Also check clause numbers and dates. The February 2026 DFARS overhaul text introduced 252.240-7997, which provides for government Medium and High NIST assessments, including access to facilities, systems, and personnel. Older paperwork may refer to 252.204-7019 and 252.204-7020. Have contracts identify the incorporated assessment language and applicable deviation before recycling an old submission checklist. February 2026 Part 240 deviation and assessment clause

For a contract requiring CMMC Level 2 (Self), the company must achieve the required status and submit its affirmation in the Supplier Performance Risk System (SPRS) before award. Self-assessment recurs every three years, with affirmation at assessment and annually thereafter. The entry includes the scope, associated Commercial and Government Entity (CAGE) codes, score, and applicable remediation status. A general claim of NIST compliance does not replace that record. 32 CFR 170.16

Define the boundary before buying tools

A CUI environment can be a defined part of a business, but its boundary must match actual use. Under the Level 2 scoping rule, CUI assets and security-protection assets have different assessment treatment. Contractor risk-managed assets and specialized equipment also require appropriate documentation. Calling a production machine “legacy” does not make it disappear from the scoping exercise. 32 CFR 170.19, Level 2 asset categories

For the machine-shop example, walk one controlled drawing through the proposed environment. Can an employee download it to an ordinary laptop, attach it to an email, print it on a shared copier, or place it in a supplier portal? Where do backups and inspection results go? These are practical checks of the proposed boundary, not assertions that every device must receive identical treatment.

Outsourcing also needs explicit allocation of work. Section 170.19 requires the external service provider's relationship and services to be documented in the system security plan, service description, and customer responsibility matrix. Identify who handles account removal, logs, configuration changes, and incident escalation. A provider's own assessment does not establish the customer's configuration or employee practices.

Cloud storage adds a specific contractual check: DFARS 252.204-7012 requires the contractor to ensure an external provider handling covered defense information meets FedRAMP Moderate-equivalent requirements and the clause's applicable incident-related duties. Ask for documentation covering the exact service and customer responsibilities, rather than relying on a provider's general security claim. Cloud-provider requirements

Turn the requirements into operating records

Revision 2 organizes its requirements into 14 families. The table groups them by the business work involved; it does not replace the individual requirements or prescribe a mandatory document format.

Requirement familiesPractical records to connect to the work
Access Control; Identification and AuthenticationApproved users, privileges, authentication settings, and account-removal records
Awareness and Training; Personnel SecurityRole-specific training and staff onboarding, transfer, and departure records
Audit and AccountabilityLogging configuration, review records, and investigated exceptions
Configuration Management; MaintenanceAsset baselines, authorized changes, and maintenance access records
Media Protection; Physical ProtectionMedia handling, disposal, facility access, and visitor records
Risk Assessment; System and Information IntegrityRisk reviews, vulnerability findings, remediation, and protective-system records
Incident ResponseResponse responsibilities, exercises, and incident records
Security Assessment; System and Communications ProtectionSystem security plan, control reviews, boundary protections, and cryptographic implementation details

Family names come from NIST SP 800-171 Revision 2. The record groupings are editorial implementation examples, informed by the examination, interview, and testing methods in NIST SP 800-171A, June 2018.

The system security plan (SSP) describes the system boundary, operating environment, implementation of requirements, and connections to other systems. Requirement 3.12.4 calls for periodic updates. Use the SSP to describe what exists, and a plan of action to identify deficiencies and their correction. A future installation belongs in remediation planning, not in a statement that the requirement is already implemented.

Assign each requirement an owner who can explain the implementation and produce its supporting records. One person may own several requirements in a small business. The useful distinction is between responsibility for doing the work and responsibility for confirming that the work happened.

Under CMMC Level 2 self-assessment procedures, assessment artifacts must be retained for six years from the CMMC Status Date. Keep a dated assessment set even as operational records and the SSP continue to change. That preserves the basis for the reported result. Level 2 assessment and retention procedures

Check the gaps that paperwork can hide

The following are failure modes to test, rather than a ranking of measured industry failures.

Authentication coverage stops at email. NIST's June 2018 assessment procedure for requirement 3.5.3 checks privileged-account identification and multifactor authentication for local and network access to privileged accounts, plus network access to nonprivileged accounts. Test the relevant access paths. An email administrator's screenshot cannot establish coverage of every path. Assessment objective 3.5.3

Encryption is enabled without checking its validation. Revision 2 requirement 3.13.11 calls for FIPS-validated cryptography when cryptography protects CUI confidentiality. FIPS refers to Federal Information Processing Standards. Ask the implementer to identify the cryptographic implementation and its validation basis; a product's use of the word “encrypted” does not settle that requirement. Requirement 3.13.11

A tool is installed, but nobody performs the recurring work. Select an actual recent event, such as a departing employee or a vulnerability finding, and follow it to closure. Ask who approved the action, who performed it, and what record remains. This is an application of NIST's examination, interview, and testing approach: policy text, staff understanding, and system behavior must support the assessment result.

The remediation list is treated as a passing score. Conditional CMMC Level 2 requires at least 88 out of 110 and restrictions on which unmet requirements may enter a plan of action and milestones (POA&M). The SSP requirement itself cannot be deferred through that conditional path. Closeout must occur within 180 days of the conditional status date; otherwise, the status expires. A score alone therefore does not establish eligibility for conditional status. 32 CFR 170.21

The incident procedure ends with calling IT. DFARS 252.204-7012 requires qualifying cyber incidents to be reported within 72 hours of discovery and affected system images and relevant monitoring data to be preserved for at least 90 days after reporting. Name the reporting lead and backup in advance. These incident records serve a different purpose from the six-year assessment artifacts. Incident reporting and preservation duties

Prepare for the next contract decision

Before accepting a new CUI workflow or representing readiness for an award, bring contracts, the system owner, and the business leader together around five questions:

  1. Which contract language and information designations establish the obligation?
  2. Does the documented boundary match how employees and providers actually handle the information?
  3. Can the responsible staff demonstrate implementation and retrieve the supporting records?
  4. Are open deficiencies accurately described, funded, and assigned for correction?
  5. Does the required assessment status and affirmation cover the systems used for this work?

For a small defense business, that review should drive the spending decision. Fund the unresolved access path, missing operating process, or unsupported implementation claim identified in the review. Expand the protected environment only with a clear understanding of the additional systems and responsibilities it brings.

Source notes

Last checked: September 7, 2026.

Sources

These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.

  1. CIO CMMC overviewDepartment of War CIO · Publication date not recorded · checked September 7, 2026
  2. DFARS 252.204-7012Acquisition.gov · Publication date not recorded · checked September 7, 2026
  3. NIST Revision 2 publication recordNIST · Publication date not recorded · checked September 7, 2026
  4. NIST Revision 3 small-business primerNIST · Publication date not recorded · checked September 7, 2026
  5. CMMC suspension implementation memorandumDepartment of War CIO · Publication date not recorded · checked September 7, 2026
  6. February 2026 Part 240 deviationDefense Acquisition Regulations System · Publication date not recorded · checked September 7, 2026
  7. 32 CFR 170.16eCFR · Publication date not recorded · checked September 7, 2026
  8. 32 CFR 170.19eCFR · Publication date not recorded · checked September 7, 2026
  9. NIST SP 800-171 Revision 2NIST · Publication date not recorded · checked September 7, 2026
  10. NIST SP 800-171A, June 2018NIST · Publication date not recorded · checked September 7, 2026
  11. 32 CFR 170.21eCFR · Publication date not recorded · checked September 7, 2026