Everything you need to know about the 110 security controls that form the foundation of CMMC Level 2. Automate your compliance with AI.
Check Your NIST 800-171 Score →NIST Special Publication 800-171 ("Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations") defines 110 security requirements across 14 families. Published by the National Institute of Standards and Technology, it's the backbone of CMMC Level 2 certification.
If your organization handles CUI (Controlled Unclassified Information) for the Department of Defense, you must implement all 110 controls and demonstrate compliance through a C3PAO assessment.
22 requirements covering system access, remote access, and access enforcement. Includes multi-factor authentication, least privilege, and session controls.
3 requirements ensuring all users understand security risks and their responsibilities for protecting CUI.
9 requirements for logging, monitoring, and retaining audit records of system activity.
9 requirements for establishing and maintaining secure configurations across all systems.
11 requirements for identifying users, devices, and processes, including MFA requirements.
3 requirements for preparing, detecting, analyzing, and recovering from security incidents.
6 requirements for performing timely and secure maintenance on organizational systems.
9 requirements for protecting, sanitizing, and disposing of media containing CUI.
2 requirements for screening individuals and protecting CUI during personnel changes.
6 requirements for controlling physical access to facilities, equipment, and systems.
3 requirements for assessing and managing risk to operations and assets.
4 requirements for assessing, monitoring, and improving security controls.
16 requirements for protecting communications and data at system boundaries.
7 requirements for identifying flaws, monitoring events, and ensuring system integrity.
| Aspect | NIST 800-171 | CMMC Level 2 |
|---|---|---|
| Controls | 110 security requirements | Same 110 requirements |
| Verification | Self-attestation (SPRS) | C3PAO third-party assessment |
| Documentation | SSP + POA&M required | SSP + POA&M + evidence packages |
| Enforcement | Contract clause | Certification required to bid |
| Scoring | SPRS score (-203 to 110) | Pass/fail per practice |
Hatty AI maps your existing security controls against all 110 NIST 800-171 requirements automatically. Our platform:
Free assessment against all 110 controls. Results in 15 minutes.