Subcontractor CMMC Tracker

Does CIS Controls v8 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement

Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 73 are reuse candidates at high confidence, requirements CIS Controls v8 may supply evidence toward, and 12 more at medium confidence; 25 have no candidate and need CMMC-specific evidence. A reuse candidate means a CIS Controls v8 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.

reuse candidate, high 73reuse candidate, medium 12no candidate, CMMC-specific evidence needed 25

The 110, one by one

CIS Controls v8
RequirementReuseCIS Controls v8 requirements that may supply evidence
Access Control
AC.L2-3.1.1 Authorized Access Controlreuse candidate (high)CIS-5.1, CIS-6.1, CIS-6.7, CIS-6.8, CIS-3.3
AC.L2-3.1.10 Session Lockreuse candidate (high)CIS-4.10, CIS-4.3
AC.L2-3.1.11 Session Terminationreuse candidate (medium)CIS-4.3
AC.L2-3.1.12 Control Remote Accessreuse candidate (high)CIS-12.7, CIS-13.5, CIS-13.5
AC.L2-3.1.13 Remote Access Confidentialityreuse candidate (high)CIS-12.7, CIS-3.10
AC.L2-3.1.14 Remote Access Routingreuse candidate (high)CIS-12.7
AC.L2-3.1.15 Privileged Remote Accessreuse candidate (high)CIS-6.5, CIS-6.4
AC.L2-3.1.16 Wireless Access Authorizationreuse candidate (medium)CIS-13.9
AC.L2-3.1.17 Wireless Access Protectionreuse candidate (medium)CIS-12.6
AC.L2-3.1.18 Mobile Device Connectionreuse candidate (high)CIS-4.12, CIS-4.11
AC.L2-3.1.19 Encrypt CUI on Mobilereuse candidate (high)CIS-3.6
AC.L2-3.1.2 Transaction & Function Controlreuse candidate (high)CIS-3.3, CIS-6.8
AC.L2-3.1.20 External Connectionsreuse candidate (high)CIS-4.4, CIS-13.4
AC.L2-3.1.21 Portable Storage Usereuse candidate (medium)CIS-10.3
AC.L2-3.1.22 Control Public Informationno candidate: CMMC-specific evidence
AC.L2-3.1.3 Control CUI Flowreuse candidate (high)CIS-3.13, CIS-3.12, CIS-13.4, CIS-3.8
AC.L2-3.1.4 Separation of Dutiesreuse candidate (high)CIS-5.4
AC.L2-3.1.5 Least Privilegereuse candidate (high)CIS-6.8, CIS-5.4, CIS-3.3
AC.L2-3.1.6 Non-Privileged Account Usereuse candidate (high)CIS-12.8, CIS-5.4
AC.L2-3.1.7 Privileged Functionsreuse candidate (high)CIS-8.8, CIS-12.8
AC.L2-3.1.8 Unsuccessful Logon Attemptsreuse candidate (high)CIS-4.10
AC.L2-3.1.9 Privacy & Security Noticesno candidate: CMMC-specific evidence
Awareness and Training
AT.L2-3.2.1 Role-Based Risk Awarenessreuse candidate (high)CIS-14.2, CIS-14.1, CIS-14.7, CIS-14.8, CIS-14.3, CIS-14.4, CIS-14.2, CIS-14.5
AT.L2-3.2.2 Role-Based Trainingreuse candidate (high)CIS-14.9, CIS-16.9
AT.L2-3.2.3 Insider Threat Awarenessreuse candidate (high)CIS-14.5, CIS-14.6
Audit and Accountability
AU.L2-3.3.1 System Auditingreuse candidate (high)CIS-8.10, CIS-8.2, CIS-8.5, CIS-3.14, CIS-8.10, CIS-8.1
AU.L2-3.3.2 User Accountabilityreuse candidate (high)CIS-8.5, CIS-5.1
AU.L2-3.3.3 Event Reviewreuse candidate (high)CIS-8.1, CIS-13.11
AU.L2-3.3.4 Audit Failure Alertingreuse candidate (medium)CIS-8.3
AU.L2-3.3.5 Audit Correlationreuse candidate (high)CIS-8.9, CIS-13.1, CIS-8.9, CIS-8.11
AU.L2-3.3.6 Reduction & Reportingreuse candidate (high)CIS-8.9, CIS-8.11
AU.L2-3.3.7 Time Stamps & Synchronizationreuse candidate (high)CIS-8.4
AU.L2-3.3.8 Audit Protectionreuse candidate (high)CIS-8.9
AU.L2-3.3.9 Audit Managementno candidate: CMMC-specific evidence
Security Assessment
CA.L2-3.12.1 Security Control Assessmentreuse candidate (high)CIS-18.4, CIS-18.1, CIS-18.1, CIS-16.13
CA.L2-3.12.2 Plan of Actionreuse candidate (high)CIS-7.2, CIS-18.3
CA.L2-3.12.3 Security Control Monitoringreuse candidate (high)CIS-13.1, CIS-7.5, CIS-18.4
CA.L2-3.12.4 System Security Planreuse candidate (medium)CIS-12.4
Configuration Management
CM.L2-3.4.1 System Baseliningreuse candidate (high)CIS-1.1, CIS-2.1, CIS-4.1, CIS-16.4
CM.L2-3.4.2 Security Configuration Enforcementreuse candidate (high)CIS-16.7, CIS-4.6, CIS-16.7, CIS-4.1, CIS-4.7, CIS-4.2
CM.L2-3.4.3 System Change Managementno candidate: CMMC-specific evidence
CM.L2-3.4.4 Security Impact Analysisno candidate: CMMC-specific evidence
CM.L2-3.4.5 Access Restrictions for Changeno candidate: CMMC-specific evidence
CM.L2-3.4.6 Least Functionalityreuse candidate (high)CIS-4.8
CM.L2-3.4.7 Nonessential Functionalityreuse candidate (high)CIS-4.8, CIS-4.4
CM.L2-3.4.8 Application Execution Policyreuse candidate (high)CIS-2.6, CIS-2.7, CIS-9.4, CIS-2.7, CIS-2.5, CIS-2.3, CIS-2.6
CM.L2-3.4.9 User-Installed Softwarereuse candidate (high)CIS-2.5, CIS-2.3
Identification and Authentication
IA.L2-3.5.1 Identificationreuse candidate (high)CIS-5.1, CIS-5.6, CIS-5.5
IA.L2-3.5.10 Cryptographically-Protected Passwordsno candidate: CMMC-specific evidence
IA.L2-3.5.11 Obscure Feedbackno candidate: CMMC-specific evidence
IA.L2-3.5.2 Authenticationreuse candidate (high)CIS-5.2, CIS-6.7
IA.L2-3.5.3 Multifactor Authenticationreuse candidate (high)CIS-6.3, CIS-6.4, CIS-6.5
IA.L2-3.5.4 Replay-Resistant Authenticationreuse candidate (medium)CIS-12.6
IA.L2-3.5.5 Identifier Reuseno candidate: CMMC-specific evidence
IA.L2-3.5.6 Identifier Handlingreuse candidate (high)CIS-5.3
IA.L2-3.5.7 Password Complexityreuse candidate (high)CIS-5.2
IA.L2-3.5.8 Password Reusereuse candidate (high)CIS-5.2
IA.L2-3.5.9 Temporary Passwordsno candidate: CMMC-specific evidence
Incident Response
IR.L2-3.6.1 Incident Handlingreuse candidate (high)CIS-17.6, CIS-17.1, CIS-17.4, CIS-17.9, CIS-17.8, CIS-17.5
IR.L2-3.6.2 Incident Reportingreuse candidate (high)CIS-17.3, CIS-17.2, CIS-17.6
IR.L2-3.6.3 Incident Response Testingreuse candidate (high)CIS-17.7
Maintenance
MA.L2-3.7.1 Perform Maintenancereuse candidate (medium)CIS-7.3
MA.L2-3.7.2 System Maintenance Controlno candidate: CMMC-specific evidence
MA.L2-3.7.3 Equipment Sanitizationreuse candidate (high)CIS-3.5
MA.L2-3.7.4 Media Inspectionreuse candidate (high)CIS-10.4
MA.L2-3.7.5 Nonlocal Maintenancereuse candidate (high)CIS-4.6, CIS-12.3, CIS-6.4
MA.L2-3.7.6 Maintenance Personnelno candidate: CMMC-specific evidence
Media Protection
MP.L2-3.8.1 Media Protectionreuse candidate (high)CIS-3.11, CIS-3.1, CIS-3.9
MP.L2-3.8.2 Media Accessreuse candidate (high)CIS-3.3
MP.L2-3.8.3 Media Disposalreuse candidate (high)CIS-3.5
MP.L2-3.8.4 Media Markingsreuse candidate (medium)CIS-3.7
MP.L2-3.8.5 Media Accountabilityreuse candidate (medium)CIS-3.2
MP.L2-3.8.6 Portable Storage Encryptionreuse candidate (high)CIS-3.9
MP.L2-3.8.7 Removable Mediareuse candidate (high)CIS-10.3, CIS-10.4, CIS-10.3
MP.L2-3.8.8 Shared Mediano candidate: CMMC-specific evidence
MP.L2-3.8.9 Protect Backupsreuse candidate (high)CIS-11.3, CIS-11.4
Physical Protection
PE.L2-3.10.1 Limit Physical Accessno candidate: CMMC-specific evidence
PE.L2-3.10.2 Monitor Facilityno candidate: CMMC-specific evidence
PE.L2-3.10.3 Escort Visitorsno candidate: CMMC-specific evidence
PE.L2-3.10.4 Physical Access Logsno candidate: CMMC-specific evidence
PE.L2-3.10.5 Manage Physical Accessno candidate: CMMC-specific evidence
PE.L2-3.10.6 Alternative Work Sitesreuse candidate (high)CIS-13.5
Personnel Security
PS.L2-3.9.1 Screen Individualsno candidate: CMMC-specific evidence
PS.L2-3.9.2 Personnel Actionsreuse candidate (high)CIS-6.2
Risk Assessment
RA.L2-3.11.1 Risk Assessmentsreuse candidate (medium)CIS-16.14
RA.L2-3.11.2 Vulnerability Scanreuse candidate (high)CIS-7.5, CIS-7.6, CIS-7.1
RA.L2-3.11.3 Vulnerability Remediationreuse candidate (high)CIS-7.2, CIS-7.7, CIS-16.6
System and Communications Protection
SC.L2-3.13.1 Boundary Protectionreuse candidate (high)CIS-4.4, CIS-13.8, CIS-13.4, CIS-12.2, CIS-13.10
SC.L2-3.13.10 Key Managementno candidate: CMMC-specific evidence
SC.L2-3.13.11 CUI Encryptionreuse candidate (high)CIS-3.11, CIS-3.10
SC.L2-3.13.12 Collaborative Device Controlno candidate: CMMC-specific evidence
SC.L2-3.13.13 Mobile Codereuse candidate (high)CIS-9.4, CIS-2.7
SC.L2-3.13.14 Voice over Internet Protocolno candidate: CMMC-specific evidence
SC.L2-3.13.15 Communications Authenticityreuse candidate (high)CIS-9.5, CIS-12.6
SC.L2-3.13.16 Data at Restreuse candidate (high)CIS-3.6, CIS-3.11
SC.L2-3.13.2 Security Engineeringreuse candidate (high)CIS-12.2, CIS-16.10, CIS-16.1
SC.L2-3.13.3 Role Separationreuse candidate (high)CIS-12.8
SC.L2-3.13.4 Shared Resource Controlno candidate: CMMC-specific evidence
SC.L2-3.13.5 Public-Access System Separationreuse candidate (high)CIS-3.12, CIS-12.2, CIS-3.12
SC.L2-3.13.6 Network Communication by Exceptionreuse candidate (high)CIS-4.5, CIS-13.9, CIS-13.9, CIS-4.4, CIS-13.4
SC.L2-3.13.7 Split Tunnelingno candidate: CMMC-specific evidence
SC.L2-3.13.8 Data in Transitreuse candidate (high)CIS-3.10, CIS-12.6
SC.L2-3.13.9 Connections Terminationno candidate: CMMC-specific evidence
System and Information Integrity
SI.L2-3.14.1 Flaw Remediationreuse candidate (high)CIS-7.3, CIS-7.4, CIS-7.7, CIS-7.4, CIS-12.1, CIS-16.2, CIS-7.3
SI.L2-3.14.2 Malicious Code Protectionreuse candidate (high)CIS-10.1, CIS-10.7, CIS-10.5, CIS-10.6, CIS-10.7, CIS-9.6, CIS-9.7
SI.L2-3.14.3 Security Alerts & Advisoriesreuse candidate (medium)CIS-7.1
SI.L2-3.14.4 Update Malicious Code Protectionreuse candidate (high)CIS-10.2
SI.L2-3.14.5 System & File Scanningreuse candidate (high)CIS-10.4, CIS-10.6
SI.L2-3.14.6 Monitor Communications for Attacksreuse candidate (high)CIS-13.3, CIS-13.6, CIS-13.2, CIS-13.6, CIS-13.7, CIS-13.8
SI.L2-3.14.7 Identify Unauthorized Usereuse candidate (high)CIS-8.11, CIS-13.2

A subcontractor that ticks CIS Controls v8 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; CIS Controls v8 itself: CIS Controls v8.