Subcontractor CMMC Tracker

Does NIST CSF 2.0 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement

Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 61 are reuse candidates at high confidence, requirements NIST CSF 2.0 may supply evidence toward, and 32 more at medium confidence; 17 have no candidate and need CMMC-specific evidence. A reuse candidate means a NIST CSF 2.0 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.

reuse candidate, high 61reuse candidate, medium 32no candidate, CMMC-specific evidence needed 17

The 110, one by one

NIST CSF 2.0
RequirementReuseNIST CSF 2.0 requirements that may supply evidence
Access Control
AC.L2-3.1.1 Authorized Access Controlreuse candidate (high)NIST-CSF-PR.AA-05
AC.L2-3.1.10 Session Lockno candidate: CMMC-specific evidence
AC.L2-3.1.11 Session Terminationno candidate: CMMC-specific evidence
AC.L2-3.1.12 Control Remote Accessreuse candidate (medium)NIST-CSF-PR.IR-01
AC.L2-3.1.13 Remote Access Confidentialityreuse candidate (high)NIST-CSF-PR.DS-02
AC.L2-3.1.14 Remote Access Routingreuse candidate (medium)NIST-CSF-PR.IR-01
AC.L2-3.1.15 Privileged Remote Accessreuse candidate (medium)NIST-CSF-PR.AA-05
AC.L2-3.1.16 Wireless Access Authorizationreuse candidate (medium)NIST-CSF-PR.IR-01
AC.L2-3.1.17 Wireless Access Protectionreuse candidate (high)NIST-CSF-PR.DS-02
AC.L2-3.1.18 Mobile Device Connectionreuse candidate (medium)NIST-CSF-PR.IR-01
AC.L2-3.1.19 Encrypt CUI on Mobilereuse candidate (high)NIST-CSF-PR.DS-01
AC.L2-3.1.2 Transaction & Function Controlreuse candidate (high)NIST-CSF-PR.AA-05
AC.L2-3.1.20 External Connectionsreuse candidate (medium)NIST-CSF-PR.IR-01
AC.L2-3.1.21 Portable Storage Useno candidate: CMMC-specific evidence
AC.L2-3.1.22 Control Public Informationno candidate: CMMC-specific evidence
AC.L2-3.1.3 Control CUI Flowreuse candidate (medium)NIST-CSF-PR.IR-01, NIST-CSF-ID.AM-03
AC.L2-3.1.4 Separation of Dutiesreuse candidate (medium)NIST-CSF-PR.AA-05
AC.L2-3.1.5 Least Privilegereuse candidate (high)NIST-CSF-PR.AA-05
AC.L2-3.1.6 Non-Privileged Account Usereuse candidate (medium)NIST-CSF-PR.AA-05
AC.L2-3.1.7 Privileged Functionsreuse candidate (medium)NIST-CSF-PR.AA-05
AC.L2-3.1.8 Unsuccessful Logon Attemptsreuse candidate (medium)NIST-CSF-PR.AA-03
AC.L2-3.1.9 Privacy & Security Noticesno candidate: CMMC-specific evidence
Awareness and Training
AT.L2-3.2.1 Role-Based Risk Awarenessreuse candidate (high)NIST-CSF-PR.AT-01
AT.L2-3.2.2 Role-Based Trainingreuse candidate (high)NIST-CSF-PR.AT-02, NIST-CSF-GV.RR-02
AT.L2-3.2.3 Insider Threat Awarenessreuse candidate (medium)NIST-CSF-PR.AT-01
Audit and Accountability
AU.L2-3.3.1 System Auditingreuse candidate (high)NIST-CSF-PR.PS-04
AU.L2-3.3.2 User Accountabilityreuse candidate (high)NIST-CSF-PR.PS-04, NIST-CSF-DE.CM-03
AU.L2-3.3.3 Event Reviewreuse candidate (medium)NIST-CSF-PR.PS-04
AU.L2-3.3.4 Audit Failure Alertingno candidate: CMMC-specific evidence
AU.L2-3.3.5 Audit Correlationreuse candidate (high)NIST-CSF-DE.AE-03, NIST-CSF-RS.AN-03, NIST-CSF-DE.AE-02
AU.L2-3.3.6 Reduction & Reportingreuse candidate (medium)NIST-CSF-DE.AE-02
AU.L2-3.3.7 Time Stamps & Synchronizationno candidate: CMMC-specific evidence
AU.L2-3.3.8 Audit Protectionreuse candidate (high)NIST-CSF-PR.AA-05, NIST-CSF-RS.AN-07
AU.L2-3.3.9 Audit Managementreuse candidate (medium)NIST-CSF-PR.AA-05
Security Assessment
CA.L2-3.12.1 Security Control Assessmentreuse candidate (high)NIST-CSF-ID.IM-02
CA.L2-3.12.2 Plan of Actionreuse candidate (high)NIST-CSF-ID.RA-06, NIST-CSF-ID.IM-02
CA.L2-3.12.3 Security Control Monitoringreuse candidate (medium)NIST-CSF-ID.IM-03
CA.L2-3.12.4 System Security Planreuse candidate (medium)NIST-CSF-GV.PO-01, NIST-CSF-GV.PO-02
Configuration Management
CM.L2-3.4.1 System Baseliningreuse candidate (high)NIST-CSF-PR.PS-01, NIST-CSF-ID.AM-02, NIST-CSF-ID.AM-01
CM.L2-3.4.2 Security Configuration Enforcementreuse candidate (high)NIST-CSF-PR.PS-01
CM.L2-3.4.3 System Change Managementreuse candidate (high)NIST-CSF-ID.RA-07, NIST-CSF-ID.AM-08
CM.L2-3.4.4 Security Impact Analysisreuse candidate (high)NIST-CSF-ID.RA-07
CM.L2-3.4.5 Access Restrictions for Changereuse candidate (medium)NIST-CSF-ID.RA-07
CM.L2-3.4.6 Least Functionalityreuse candidate (high)NIST-CSF-PR.PS-01
CM.L2-3.4.7 Nonessential Functionalityreuse candidate (medium)NIST-CSF-PR.PS-01
CM.L2-3.4.8 Application Execution Policyreuse candidate (high)NIST-CSF-PR.PS-05
CM.L2-3.4.9 User-Installed Softwarereuse candidate (high)NIST-CSF-PR.PS-05
Identification and Authentication
IA.L2-3.5.1 Identificationreuse candidate (high)NIST-CSF-PR.AA-01, NIST-CSF-PR.AA-02
IA.L2-3.5.10 Cryptographically-Protected Passwordsreuse candidate (high)NIST-CSF-PR.AA-04, NIST-CSF-PR.AA-04
IA.L2-3.5.11 Obscure Feedbackno candidate: CMMC-specific evidence
IA.L2-3.5.2 Authenticationreuse candidate (high)NIST-CSF-PR.AA-03
IA.L2-3.5.3 Multifactor Authenticationreuse candidate (high)NIST-CSF-PR.AA-03
IA.L2-3.5.4 Replay-Resistant Authenticationreuse candidate (high)NIST-CSF-PR.AA-03, NIST-CSF-PR.AA-04, NIST-CSF-PR.AA-04
IA.L2-3.5.5 Identifier Reusereuse candidate (high)NIST-CSF-PR.AA-01, NIST-CSF-PR.AA-01
IA.L2-3.5.6 Identifier Handlingreuse candidate (high)NIST-CSF-PR.AA-01
IA.L2-3.5.7 Password Complexityreuse candidate (medium)NIST-CSF-PR.AA-01
IA.L2-3.5.8 Password Reusereuse candidate (medium)NIST-CSF-PR.AA-01
IA.L2-3.5.9 Temporary Passwordsreuse candidate (medium)NIST-CSF-PR.AA-01
Incident Response
IR.L2-3.6.1 Incident Handlingreuse candidate (high)NIST-CSF-ID.IM-04, NIST-CSF-RS.MI-01, NIST-CSF-RS.MA-03, NIST-CSF-RS.MA-04, NIST-CSF-DE.AE-04, NIST-CSF-RS.MI-02, NIST-CSF-RS.MA-02, NIST-CSF-RS.MA-01, NIST-CSF-DE.AE-08, NIST-CSF-RC.RP-01
IR.L2-3.6.2 Incident Reportingreuse candidate (high)NIST-CSF-RS.CO-02, NIST-CSF-DE.AE-06, NIST-CSF-RS.CO-03, NIST-CSF-RS.AN-06, NIST-CSF-RC.CO-03
IR.L2-3.6.3 Incident Response Testingreuse candidate (high)NIST-CSF-ID.IM-01
Maintenance
MA.L2-3.7.1 Perform Maintenancereuse candidate (high)NIST-CSF-PR.PS-03
MA.L2-3.7.2 System Maintenance Controlreuse candidate (high)NIST-CSF-PR.PS-03, NIST-CSF-PR.PS-03
MA.L2-3.7.3 Equipment Sanitizationreuse candidate (high)NIST-CSF-PR.PS-03
MA.L2-3.7.4 Media Inspectionno candidate: CMMC-specific evidence
MA.L2-3.7.5 Nonlocal Maintenancereuse candidate (high)NIST-CSF-PR.AA-03
MA.L2-3.7.6 Maintenance Personnelno candidate: CMMC-specific evidence
Media Protection
MP.L2-3.8.1 Media Protectionreuse candidate (medium)NIST-CSF-PR.DS-01
MP.L2-3.8.2 Media Accessreuse candidate (medium)NIST-CSF-PR.AA-05
MP.L2-3.8.3 Media Disposalreuse candidate (high)NIST-CSF-PR.PS-03
MP.L2-3.8.4 Media Markingsreuse candidate (medium)NIST-CSF-ID.AM-05
MP.L2-3.8.5 Media Accountabilityreuse candidate (medium)NIST-CSF-PR.AA-06
MP.L2-3.8.6 Portable Storage Encryptionreuse candidate (high)NIST-CSF-PR.DS-01
MP.L2-3.8.7 Removable Mediano candidate: CMMC-specific evidence
MP.L2-3.8.8 Shared Mediano candidate: CMMC-specific evidence
MP.L2-3.8.9 Protect Backupsreuse candidate (high)NIST-CSF-PR.DS-11, NIST-CSF-PR.DS-11
Physical Protection
PE.L2-3.10.1 Limit Physical Accessreuse candidate (high)NIST-CSF-PR.AA-06
PE.L2-3.10.2 Monitor Facilityreuse candidate (high)NIST-CSF-DE.CM-02, NIST-CSF-PR.IR-02
PE.L2-3.10.3 Escort Visitorsreuse candidate (high)NIST-CSF-PR.AA-06
PE.L2-3.10.4 Physical Access Logsreuse candidate (high)NIST-CSF-DE.CM-02, NIST-CSF-PR.AA-06
PE.L2-3.10.5 Manage Physical Accessreuse candidate (high)NIST-CSF-PR.AA-06, NIST-CSF-PR.AA-06
PE.L2-3.10.6 Alternative Work Sitesno candidate: CMMC-specific evidence
Personnel Security
PS.L2-3.9.1 Screen Individualsreuse candidate (high)NIST-CSF-GV.RR-04
PS.L2-3.9.2 Personnel Actionsreuse candidate (high)NIST-CSF-GV.RR-04
Risk Assessment
RA.L2-3.11.1 Risk Assessmentsreuse candidate (high)NIST-CSF-ID.RA-05, NIST-CSF-ID.RA-03, NIST-CSF-ID.RA-04
RA.L2-3.11.2 Vulnerability Scanreuse candidate (high)NIST-CSF-ID.RA-01
RA.L2-3.11.3 Vulnerability Remediationreuse candidate (high)NIST-CSF-ID.RA-06
System and Communications Protection
SC.L2-3.13.1 Boundary Protectionreuse candidate (high)NIST-CSF-PR.IR-01
SC.L2-3.13.10 Key Managementreuse candidate (medium)NIST-CSF-PR.DS-02
SC.L2-3.13.11 CUI Encryptionreuse candidate (high)NIST-CSF-PR.DS-02
SC.L2-3.13.12 Collaborative Device Controlno candidate: CMMC-specific evidence
SC.L2-3.13.13 Mobile Codereuse candidate (medium)NIST-CSF-PR.PS-05
SC.L2-3.13.14 Voice over Internet Protocolno candidate: CMMC-specific evidence
SC.L2-3.13.15 Communications Authenticityreuse candidate (medium)NIST-CSF-PR.AA-04
SC.L2-3.13.16 Data at Restreuse candidate (high)NIST-CSF-PR.DS-01
SC.L2-3.13.2 Security Engineeringreuse candidate (high)NIST-CSF-PR.PS-06
SC.L2-3.13.3 Role Separationreuse candidate (medium)NIST-CSF-PR.IR-01
SC.L2-3.13.4 Shared Resource Controlreuse candidate (medium)NIST-CSF-PR.DS-10
SC.L2-3.13.5 Public-Access System Separationreuse candidate (high)NIST-CSF-PR.IR-01
SC.L2-3.13.6 Network Communication by Exceptionreuse candidate (high)NIST-CSF-PR.IR-01
SC.L2-3.13.7 Split Tunnelingno candidate: CMMC-specific evidence
SC.L2-3.13.8 Data in Transitreuse candidate (high)NIST-CSF-PR.DS-02
SC.L2-3.13.9 Connections Terminationno candidate: CMMC-specific evidence
System and Information Integrity
SI.L2-3.14.1 Flaw Remediationreuse candidate (high)NIST-CSF-ID.RA-01, NIST-CSF-PR.PS-02
SI.L2-3.14.2 Malicious Code Protectionreuse candidate (high)NIST-CSF-DE.CM-09
SI.L2-3.14.3 Security Alerts & Advisoriesreuse candidate (high)NIST-CSF-ID.RA-02, NIST-CSF-DE.AE-07
SI.L2-3.14.4 Update Malicious Code Protectionreuse candidate (medium)NIST-CSF-DE.CM-09
SI.L2-3.14.5 System & File Scanningreuse candidate (high)NIST-CSF-DE.CM-09
SI.L2-3.14.6 Monitor Communications for Attacksreuse candidate (high)NIST-CSF-DE.CM-01, NIST-CSF-DE.AE-02, NIST-CSF-DE.CM-09
SI.L2-3.14.7 Identify Unauthorized Usereuse candidate (high)NIST-CSF-DE.CM-03

A subcontractor that ticks NIST CSF 2.0 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; NIST CSF 2.0 itself: NIST CSF 2.0.