Subcontractor CMMC Tracker

Does ISO 27001 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement

Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 93 are reuse candidates at high confidence, requirements ISO/IEC 27001:2022 may supply evidence toward, and 10 more at medium confidence; 7 have no candidate and need CMMC-specific evidence. A reuse candidate means a ISO/IEC 27001:2022 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.

reuse candidate, high 93reuse candidate, medium 10no candidate, CMMC-specific evidence needed 7

The 110, one by one

ISO/IEC 27001:2022
RequirementReuseISO 27001 requirements that may supply evidence
Access Control
AC.L2-3.1.1 Authorized Access Controlreuse candidate (high)8.3, 5.15
AC.L2-3.1.10 Session Lockreuse candidate (high)8.1, 7.7, 7.7
AC.L2-3.1.11 Session Terminationreuse candidate (high)7.7
AC.L2-3.1.12 Control Remote Accessreuse candidate (high)6.7, 8.20
AC.L2-3.1.13 Remote Access Confidentialityreuse candidate (high)6.7
AC.L2-3.1.14 Remote Access Routingreuse candidate (high)8.20
AC.L2-3.1.15 Privileged Remote Accessreuse candidate (high)8.5
AC.L2-3.1.16 Wireless Access Authorizationreuse candidate (medium)8.20
AC.L2-3.1.17 Wireless Access Protectionreuse candidate (high)8.21
AC.L2-3.1.18 Mobile Device Connectionreuse candidate (high)8.1
AC.L2-3.1.19 Encrypt CUI on Mobilereuse candidate (high)8.1
AC.L2-3.1.2 Transaction & Function Controlreuse candidate (high)5.15, 8.3
AC.L2-3.1.20 External Connectionsreuse candidate (high)8.21, 5.23, 5.23
AC.L2-3.1.21 Portable Storage Usereuse candidate (high)7.10
AC.L2-3.1.22 Control Public Informationreuse candidate (medium)5.12
AC.L2-3.1.3 Control CUI Flowreuse candidate (high)5.14, 8.22, 8.12, 5.14, 8.12
AC.L2-3.1.4 Separation of Dutiesreuse candidate (high)5.3
AC.L2-3.1.5 Least Privilegereuse candidate (high)5.18, 8.2
AC.L2-3.1.6 Non-Privileged Account Usereuse candidate (high)8.2
AC.L2-3.1.7 Privileged Functionsreuse candidate (high)8.2, 8.18
AC.L2-3.1.8 Unsuccessful Logon Attemptsreuse candidate (medium)8.5
AC.L2-3.1.9 Privacy & Security Noticesreuse candidate (medium)5.10
Awareness and Training
AT.L2-3.2.1 Role-Based Risk Awarenessreuse candidate (high)6.3, 5.10
AT.L2-3.2.2 Role-Based Trainingreuse candidate (high)6.3
AT.L2-3.2.3 Insider Threat Awarenessreuse candidate (high)6.8, 6.3
Audit and Accountability
AU.L2-3.3.1 System Auditingreuse candidate (high)8.15
AU.L2-3.3.2 User Accountabilityreuse candidate (high)5.16, 8.15
AU.L2-3.3.3 Event Reviewreuse candidate (high)8.16
AU.L2-3.3.4 Audit Failure Alertingreuse candidate (medium)8.16
AU.L2-3.3.5 Audit Correlationreuse candidate (high)8.16
AU.L2-3.3.6 Reduction & Reportingreuse candidate (high)8.15
AU.L2-3.3.7 Time Stamps & Synchronizationreuse candidate (high)8.17
AU.L2-3.3.8 Audit Protectionreuse candidate (high)5.33, 5.33, 5.28
AU.L2-3.3.9 Audit Managementreuse candidate (high)8.18
Security Assessment
CA.L2-3.12.1 Security Control Assessmentreuse candidate (high)5.35, 5.36, 5.35, 8.29
CA.L2-3.12.2 Plan of Actionreuse candidate (high)5.36
CA.L2-3.12.3 Security Control Monitoringreuse candidate (high)7.4, 5.36, 5.36
CA.L2-3.12.4 System Security Planreuse candidate (medium)5.2, 5.37, 5.1
Configuration Management
CM.L2-3.4.1 System Baseliningreuse candidate (high)5.9, 8.9
CM.L2-3.4.2 Security Configuration Enforcementreuse candidate (high)8.9
CM.L2-3.4.3 System Change Managementreuse candidate (high)8.32
CM.L2-3.4.4 Security Impact Analysisreuse candidate (high)8.32
CM.L2-3.4.5 Access Restrictions for Changereuse candidate (high)8.4, 8.32
CM.L2-3.4.6 Least Functionalityreuse candidate (medium)8.27
CM.L2-3.4.7 Nonessential Functionalityreuse candidate (high)8.9
CM.L2-3.4.8 Application Execution Policyreuse candidate (high)8.19
CM.L2-3.4.9 User-Installed Softwarereuse candidate (high)8.19
Identification and Authentication
IA.L2-3.5.1 Identificationreuse candidate (high)5.16
IA.L2-3.5.10 Cryptographically-Protected Passwordsreuse candidate (high)5.17
IA.L2-3.5.11 Obscure Feedbackno candidate: CMMC-specific evidence
IA.L2-3.5.2 Authenticationreuse candidate (high)5.17, 8.5
IA.L2-3.5.3 Multifactor Authenticationreuse candidate (high)8.5
IA.L2-3.5.4 Replay-Resistant Authenticationreuse candidate (high)8.21, 8.5
IA.L2-3.5.5 Identifier Reusereuse candidate (high)5.16
IA.L2-3.5.6 Identifier Handlingreuse candidate (high)5.18
IA.L2-3.5.7 Password Complexityreuse candidate (high)5.17
IA.L2-3.5.8 Password Reusereuse candidate (high)5.17
IA.L2-3.5.9 Temporary Passwordsno candidate: CMMC-specific evidence
Incident Response
IR.L2-3.6.1 Incident Handlingreuse candidate (high)5.24, 5.26, 5.25
IR.L2-3.6.2 Incident Reportingreuse candidate (high)5.5, 6.8
IR.L2-3.6.3 Incident Response Testingreuse candidate (high)5.24, 5.27
Maintenance
MA.L2-3.7.1 Perform Maintenancereuse candidate (high)7.13
MA.L2-3.7.2 System Maintenance Controlreuse candidate (high)7.13
MA.L2-3.7.3 Equipment Sanitizationreuse candidate (high)7.14
MA.L2-3.7.4 Media Inspectionreuse candidate (high)8.7
MA.L2-3.7.5 Nonlocal Maintenancereuse candidate (high)6.7
MA.L2-3.7.6 Maintenance Personnelreuse candidate (medium)7.6
Media Protection
MP.L2-3.8.1 Media Protectionreuse candidate (high)7.10
MP.L2-3.8.2 Media Accessreuse candidate (high)8.3, 7.10
MP.L2-3.8.3 Media Disposalreuse candidate (high)7.14, 8.10, 7.10
MP.L2-3.8.4 Media Markingsreuse candidate (high)5.13, 5.12
MP.L2-3.8.5 Media Accountabilityreuse candidate (high)7.10
MP.L2-3.8.6 Portable Storage Encryptionreuse candidate (medium)8.24
MP.L2-3.8.7 Removable Mediareuse candidate (high)5.10
MP.L2-3.8.8 Shared Mediano candidate: CMMC-specific evidence
MP.L2-3.8.9 Protect Backupsreuse candidate (high)8.13, 8.13
Physical Protection
PE.L2-3.10.1 Limit Physical Accessreuse candidate (high)7.1, 7.2, 7.3, 7.8
PE.L2-3.10.2 Monitor Facilityreuse candidate (high)7.4, 7.5
PE.L2-3.10.3 Escort Visitorsreuse candidate (high)7.2, 7.6
PE.L2-3.10.4 Physical Access Logsreuse candidate (high)7.2, 7.4
PE.L2-3.10.5 Manage Physical Accessreuse candidate (high)7.1, 7.3, 7.2
PE.L2-3.10.6 Alternative Work Sitesreuse candidate (high)7.9, 6.7
Personnel Security
PS.L2-3.9.1 Screen Individualsreuse candidate (high)6.1
PS.L2-3.9.2 Personnel Actionsreuse candidate (high)5.11, 6.5, 5.18
Risk Assessment
RA.L2-3.11.1 Risk Assessmentsreuse candidate (medium)5.7
RA.L2-3.11.2 Vulnerability Scanreuse candidate (high)8.8
RA.L2-3.11.3 Vulnerability Remediationreuse candidate (high)8.8
System and Communications Protection
SC.L2-3.13.1 Boundary Protectionreuse candidate (high)8.22, 8.21, 8.20
SC.L2-3.13.10 Key Managementreuse candidate (high)8.24
SC.L2-3.13.11 CUI Encryptionreuse candidate (high)8.24
SC.L2-3.13.12 Collaborative Device Controlno candidate: CMMC-specific evidence
SC.L2-3.13.13 Mobile Codereuse candidate (high)8.19
SC.L2-3.13.14 Voice over Internet Protocolno candidate: CMMC-specific evidence
SC.L2-3.13.15 Communications Authenticityreuse candidate (high)8.21
SC.L2-3.13.16 Data at Restreuse candidate (high)8.24
SC.L2-3.13.2 Security Engineeringreuse candidate (high)8.25, 8.27, 8.28
SC.L2-3.13.3 Role Separationreuse candidate (high)5.3
SC.L2-3.13.4 Shared Resource Controlno candidate: CMMC-specific evidence
SC.L2-3.13.5 Public-Access System Separationreuse candidate (high)8.22
SC.L2-3.13.6 Network Communication by Exceptionreuse candidate (high)8.20, 8.20
SC.L2-3.13.7 Split Tunnelingno candidate: CMMC-specific evidence
SC.L2-3.13.8 Data in Transitreuse candidate (high)5.14
SC.L2-3.13.9 Connections Terminationreuse candidate (high)7.7
System and Information Integrity
SI.L2-3.14.1 Flaw Remediationreuse candidate (high)8.8
SI.L2-3.14.2 Malicious Code Protectionreuse candidate (high)8.7
SI.L2-3.14.3 Security Alerts & Advisoriesreuse candidate (high)5.7, 5.6
SI.L2-3.14.4 Update Malicious Code Protectionreuse candidate (high)8.7
SI.L2-3.14.5 System & File Scanningreuse candidate (high)8.7, 8.7
SI.L2-3.14.6 Monitor Communications for Attacksreuse candidate (high)8.16
SI.L2-3.14.7 Identify Unauthorized Usereuse candidate (high)8.15, 8.16

A subcontractor that ticks ISO/IEC 27001:2022 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; ISO/IEC 27001:2022 itself: ISO/IEC 27001:2022.