Does CIS Controls v8 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement
Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 73 are reuse candidates at high confidence, requirements CIS Controls v8 may supply evidence toward, and 12 more at medium confidence; 25 have no candidate and need CMMC-specific evidence. A reuse candidate means a CIS Controls v8 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.
The 110, one by one
CIS Controls v8| Requirement | Reuse | CIS Controls v8 requirements that may supply evidence |
|---|---|---|
| Access Control | ||
| AC.L2-3.1.1 Authorized Access Control | reuse candidate (high) | CIS-5.1, CIS-6.1, CIS-6.7, CIS-6.8, CIS-3.3 |
| AC.L2-3.1.10 Session Lock | reuse candidate (high) | CIS-4.10, CIS-4.3 |
| AC.L2-3.1.11 Session Termination | reuse candidate (medium) | CIS-4.3 |
| AC.L2-3.1.12 Control Remote Access | reuse candidate (high) | CIS-12.7, CIS-13.5, CIS-13.5 |
| AC.L2-3.1.13 Remote Access Confidentiality | reuse candidate (high) | CIS-12.7, CIS-3.10 |
| AC.L2-3.1.14 Remote Access Routing | reuse candidate (high) | CIS-12.7 |
| AC.L2-3.1.15 Privileged Remote Access | reuse candidate (high) | CIS-6.5, CIS-6.4 |
| AC.L2-3.1.16 Wireless Access Authorization | reuse candidate (medium) | CIS-13.9 |
| AC.L2-3.1.17 Wireless Access Protection | reuse candidate (medium) | CIS-12.6 |
| AC.L2-3.1.18 Mobile Device Connection | reuse candidate (high) | CIS-4.12, CIS-4.11 |
| AC.L2-3.1.19 Encrypt CUI on Mobile | reuse candidate (high) | CIS-3.6 |
| AC.L2-3.1.2 Transaction & Function Control | reuse candidate (high) | CIS-3.3, CIS-6.8 |
| AC.L2-3.1.20 External Connections | reuse candidate (high) | CIS-4.4, CIS-13.4 |
| AC.L2-3.1.21 Portable Storage Use | reuse candidate (medium) | CIS-10.3 |
| AC.L2-3.1.22 Control Public Information | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.3 Control CUI Flow | reuse candidate (high) | CIS-3.13, CIS-3.12, CIS-13.4, CIS-3.8 |
| AC.L2-3.1.4 Separation of Duties | reuse candidate (high) | CIS-5.4 |
| AC.L2-3.1.5 Least Privilege | reuse candidate (high) | CIS-6.8, CIS-5.4, CIS-3.3 |
| AC.L2-3.1.6 Non-Privileged Account Use | reuse candidate (high) | CIS-12.8, CIS-5.4 |
| AC.L2-3.1.7 Privileged Functions | reuse candidate (high) | CIS-8.8, CIS-12.8 |
| AC.L2-3.1.8 Unsuccessful Logon Attempts | reuse candidate (high) | CIS-4.10 |
| AC.L2-3.1.9 Privacy & Security Notices | no candidate: CMMC-specific evidence | |
| Awareness and Training | ||
| AT.L2-3.2.1 Role-Based Risk Awareness | reuse candidate (high) | CIS-14.2, CIS-14.1, CIS-14.7, CIS-14.8, CIS-14.3, CIS-14.4, CIS-14.2, CIS-14.5 |
| AT.L2-3.2.2 Role-Based Training | reuse candidate (high) | CIS-14.9, CIS-16.9 |
| AT.L2-3.2.3 Insider Threat Awareness | reuse candidate (high) | CIS-14.5, CIS-14.6 |
| Audit and Accountability | ||
| AU.L2-3.3.1 System Auditing | reuse candidate (high) | CIS-8.10, CIS-8.2, CIS-8.5, CIS-3.14, CIS-8.10, CIS-8.1 |
| AU.L2-3.3.2 User Accountability | reuse candidate (high) | CIS-8.5, CIS-5.1 |
| AU.L2-3.3.3 Event Review | reuse candidate (high) | CIS-8.1, CIS-13.11 |
| AU.L2-3.3.4 Audit Failure Alerting | reuse candidate (medium) | CIS-8.3 |
| AU.L2-3.3.5 Audit Correlation | reuse candidate (high) | CIS-8.9, CIS-13.1, CIS-8.9, CIS-8.11 |
| AU.L2-3.3.6 Reduction & Reporting | reuse candidate (high) | CIS-8.9, CIS-8.11 |
| AU.L2-3.3.7 Time Stamps & Synchronization | reuse candidate (high) | CIS-8.4 |
| AU.L2-3.3.8 Audit Protection | reuse candidate (high) | CIS-8.9 |
| AU.L2-3.3.9 Audit Management | no candidate: CMMC-specific evidence | |
| Security Assessment | ||
| CA.L2-3.12.1 Security Control Assessment | reuse candidate (high) | CIS-18.4, CIS-18.1, CIS-18.1, CIS-16.13 |
| CA.L2-3.12.2 Plan of Action | reuse candidate (high) | CIS-7.2, CIS-18.3 |
| CA.L2-3.12.3 Security Control Monitoring | reuse candidate (high) | CIS-13.1, CIS-7.5, CIS-18.4 |
| CA.L2-3.12.4 System Security Plan | reuse candidate (medium) | CIS-12.4 |
| Configuration Management | ||
| CM.L2-3.4.1 System Baselining | reuse candidate (high) | CIS-1.1, CIS-2.1, CIS-4.1, CIS-16.4 |
| CM.L2-3.4.2 Security Configuration Enforcement | reuse candidate (high) | CIS-16.7, CIS-4.6, CIS-16.7, CIS-4.1, CIS-4.7, CIS-4.2 |
| CM.L2-3.4.3 System Change Management | no candidate: CMMC-specific evidence | |
| CM.L2-3.4.4 Security Impact Analysis | no candidate: CMMC-specific evidence | |
| CM.L2-3.4.5 Access Restrictions for Change | no candidate: CMMC-specific evidence | |
| CM.L2-3.4.6 Least Functionality | reuse candidate (high) | CIS-4.8 |
| CM.L2-3.4.7 Nonessential Functionality | reuse candidate (high) | CIS-4.8, CIS-4.4 |
| CM.L2-3.4.8 Application Execution Policy | reuse candidate (high) | CIS-2.6, CIS-2.7, CIS-9.4, CIS-2.7, CIS-2.5, CIS-2.3, CIS-2.6 |
| CM.L2-3.4.9 User-Installed Software | reuse candidate (high) | CIS-2.5, CIS-2.3 |
| Identification and Authentication | ||
| IA.L2-3.5.1 Identification | reuse candidate (high) | CIS-5.1, CIS-5.6, CIS-5.5 |
| IA.L2-3.5.10 Cryptographically-Protected Passwords | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.11 Obscure Feedback | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.2 Authentication | reuse candidate (high) | CIS-5.2, CIS-6.7 |
| IA.L2-3.5.3 Multifactor Authentication | reuse candidate (high) | CIS-6.3, CIS-6.4, CIS-6.5 |
| IA.L2-3.5.4 Replay-Resistant Authentication | reuse candidate (medium) | CIS-12.6 |
| IA.L2-3.5.5 Identifier Reuse | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.6 Identifier Handling | reuse candidate (high) | CIS-5.3 |
| IA.L2-3.5.7 Password Complexity | reuse candidate (high) | CIS-5.2 |
| IA.L2-3.5.8 Password Reuse | reuse candidate (high) | CIS-5.2 |
| IA.L2-3.5.9 Temporary Passwords | no candidate: CMMC-specific evidence | |
| Incident Response | ||
| IR.L2-3.6.1 Incident Handling | reuse candidate (high) | CIS-17.6, CIS-17.1, CIS-17.4, CIS-17.9, CIS-17.8, CIS-17.5 |
| IR.L2-3.6.2 Incident Reporting | reuse candidate (high) | CIS-17.3, CIS-17.2, CIS-17.6 |
| IR.L2-3.6.3 Incident Response Testing | reuse candidate (high) | CIS-17.7 |
| Maintenance | ||
| MA.L2-3.7.1 Perform Maintenance | reuse candidate (medium) | CIS-7.3 |
| MA.L2-3.7.2 System Maintenance Control | no candidate: CMMC-specific evidence | |
| MA.L2-3.7.3 Equipment Sanitization | reuse candidate (high) | CIS-3.5 |
| MA.L2-3.7.4 Media Inspection | reuse candidate (high) | CIS-10.4 |
| MA.L2-3.7.5 Nonlocal Maintenance | reuse candidate (high) | CIS-4.6, CIS-12.3, CIS-6.4 |
| MA.L2-3.7.6 Maintenance Personnel | no candidate: CMMC-specific evidence | |
| Media Protection | ||
| MP.L2-3.8.1 Media Protection | reuse candidate (high) | CIS-3.11, CIS-3.1, CIS-3.9 |
| MP.L2-3.8.2 Media Access | reuse candidate (high) | CIS-3.3 |
| MP.L2-3.8.3 Media Disposal | reuse candidate (high) | CIS-3.5 |
| MP.L2-3.8.4 Media Markings | reuse candidate (medium) | CIS-3.7 |
| MP.L2-3.8.5 Media Accountability | reuse candidate (medium) | CIS-3.2 |
| MP.L2-3.8.6 Portable Storage Encryption | reuse candidate (high) | CIS-3.9 |
| MP.L2-3.8.7 Removable Media | reuse candidate (high) | CIS-10.3, CIS-10.4, CIS-10.3 |
| MP.L2-3.8.8 Shared Media | no candidate: CMMC-specific evidence | |
| MP.L2-3.8.9 Protect Backups | reuse candidate (high) | CIS-11.3, CIS-11.4 |
| Physical Protection | ||
| PE.L2-3.10.1 Limit Physical Access | no candidate: CMMC-specific evidence | |
| PE.L2-3.10.2 Monitor Facility | no candidate: CMMC-specific evidence | |
| PE.L2-3.10.3 Escort Visitors | no candidate: CMMC-specific evidence | |
| PE.L2-3.10.4 Physical Access Logs | no candidate: CMMC-specific evidence | |
| PE.L2-3.10.5 Manage Physical Access | no candidate: CMMC-specific evidence | |
| PE.L2-3.10.6 Alternative Work Sites | reuse candidate (high) | CIS-13.5 |
| Personnel Security | ||
| PS.L2-3.9.1 Screen Individuals | no candidate: CMMC-specific evidence | |
| PS.L2-3.9.2 Personnel Actions | reuse candidate (high) | CIS-6.2 |
| Risk Assessment | ||
| RA.L2-3.11.1 Risk Assessments | reuse candidate (medium) | CIS-16.14 |
| RA.L2-3.11.2 Vulnerability Scan | reuse candidate (high) | CIS-7.5, CIS-7.6, CIS-7.1 |
| RA.L2-3.11.3 Vulnerability Remediation | reuse candidate (high) | CIS-7.2, CIS-7.7, CIS-16.6 |
| System and Communications Protection | ||
| SC.L2-3.13.1 Boundary Protection | reuse candidate (high) | CIS-4.4, CIS-13.8, CIS-13.4, CIS-12.2, CIS-13.10 |
| SC.L2-3.13.10 Key Management | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.11 CUI Encryption | reuse candidate (high) | CIS-3.11, CIS-3.10 |
| SC.L2-3.13.12 Collaborative Device Control | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.13 Mobile Code | reuse candidate (high) | CIS-9.4, CIS-2.7 |
| SC.L2-3.13.14 Voice over Internet Protocol | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.15 Communications Authenticity | reuse candidate (high) | CIS-9.5, CIS-12.6 |
| SC.L2-3.13.16 Data at Rest | reuse candidate (high) | CIS-3.6, CIS-3.11 |
| SC.L2-3.13.2 Security Engineering | reuse candidate (high) | CIS-12.2, CIS-16.10, CIS-16.1 |
| SC.L2-3.13.3 Role Separation | reuse candidate (high) | CIS-12.8 |
| SC.L2-3.13.4 Shared Resource Control | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.5 Public-Access System Separation | reuse candidate (high) | CIS-3.12, CIS-12.2, CIS-3.12 |
| SC.L2-3.13.6 Network Communication by Exception | reuse candidate (high) | CIS-4.5, CIS-13.9, CIS-13.9, CIS-4.4, CIS-13.4 |
| SC.L2-3.13.7 Split Tunneling | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.8 Data in Transit | reuse candidate (high) | CIS-3.10, CIS-12.6 |
| SC.L2-3.13.9 Connections Termination | no candidate: CMMC-specific evidence | |
| System and Information Integrity | ||
| SI.L2-3.14.1 Flaw Remediation | reuse candidate (high) | CIS-7.3, CIS-7.4, CIS-7.7, CIS-7.4, CIS-12.1, CIS-16.2, CIS-7.3 |
| SI.L2-3.14.2 Malicious Code Protection | reuse candidate (high) | CIS-10.1, CIS-10.7, CIS-10.5, CIS-10.6, CIS-10.7, CIS-9.6, CIS-9.7 |
| SI.L2-3.14.3 Security Alerts & Advisories | reuse candidate (medium) | CIS-7.1 |
| SI.L2-3.14.4 Update Malicious Code Protection | reuse candidate (high) | CIS-10.2 |
| SI.L2-3.14.5 System & File Scanning | reuse candidate (high) | CIS-10.4, CIS-10.6 |
| SI.L2-3.14.6 Monitor Communications for Attacks | reuse candidate (high) | CIS-13.3, CIS-13.6, CIS-13.2, CIS-13.6, CIS-13.7, CIS-13.8 |
| SI.L2-3.14.7 Identify Unauthorized Use | reuse candidate (high) | CIS-8.11, CIS-13.2 |
A subcontractor that ticks CIS Controls v8 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; CIS Controls v8 itself: CIS Controls v8.