Does NIST CSF 2.0 cover NIST SP 800-171? What our crosswalk reaches, requirement by requirement
Of the 110 requirements of CMMC Level 2 (NIST SP 800-171 Rev 2), 61 are reuse candidates at high confidence, requirements NIST CSF 2.0 may supply evidence toward, and 32 more at medium confidence; 17 have no candidate and need CMMC-specific evidence. A reuse candidate means a NIST CSF 2.0 requirement points at the same thing; it is not evidence that anything is in place, and every one of the 110 is still assessed on its own evidence against NIST SP 800-171 Rev 2.
The 110, one by one
NIST CSF 2.0| Requirement | Reuse | NIST CSF 2.0 requirements that may supply evidence |
|---|---|---|
| Access Control | ||
| AC.L2-3.1.1 Authorized Access Control | reuse candidate (high) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.10 Session Lock | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.11 Session Termination | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.12 Control Remote Access | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| AC.L2-3.1.13 Remote Access Confidentiality | reuse candidate (high) | NIST-CSF-PR.DS-02 |
| AC.L2-3.1.14 Remote Access Routing | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| AC.L2-3.1.15 Privileged Remote Access | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.16 Wireless Access Authorization | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| AC.L2-3.1.17 Wireless Access Protection | reuse candidate (high) | NIST-CSF-PR.DS-02 |
| AC.L2-3.1.18 Mobile Device Connection | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| AC.L2-3.1.19 Encrypt CUI on Mobile | reuse candidate (high) | NIST-CSF-PR.DS-01 |
| AC.L2-3.1.2 Transaction & Function Control | reuse candidate (high) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.20 External Connections | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| AC.L2-3.1.21 Portable Storage Use | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.22 Control Public Information | no candidate: CMMC-specific evidence | |
| AC.L2-3.1.3 Control CUI Flow | reuse candidate (medium) | NIST-CSF-PR.IR-01, NIST-CSF-ID.AM-03 |
| AC.L2-3.1.4 Separation of Duties | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.5 Least Privilege | reuse candidate (high) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.6 Non-Privileged Account Use | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.7 Privileged Functions | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| AC.L2-3.1.8 Unsuccessful Logon Attempts | reuse candidate (medium) | NIST-CSF-PR.AA-03 |
| AC.L2-3.1.9 Privacy & Security Notices | no candidate: CMMC-specific evidence | |
| Awareness and Training | ||
| AT.L2-3.2.1 Role-Based Risk Awareness | reuse candidate (high) | NIST-CSF-PR.AT-01 |
| AT.L2-3.2.2 Role-Based Training | reuse candidate (high) | NIST-CSF-PR.AT-02, NIST-CSF-GV.RR-02 |
| AT.L2-3.2.3 Insider Threat Awareness | reuse candidate (medium) | NIST-CSF-PR.AT-01 |
| Audit and Accountability | ||
| AU.L2-3.3.1 System Auditing | reuse candidate (high) | NIST-CSF-PR.PS-04 |
| AU.L2-3.3.2 User Accountability | reuse candidate (high) | NIST-CSF-PR.PS-04, NIST-CSF-DE.CM-03 |
| AU.L2-3.3.3 Event Review | reuse candidate (medium) | NIST-CSF-PR.PS-04 |
| AU.L2-3.3.4 Audit Failure Alerting | no candidate: CMMC-specific evidence | |
| AU.L2-3.3.5 Audit Correlation | reuse candidate (high) | NIST-CSF-DE.AE-03, NIST-CSF-RS.AN-03, NIST-CSF-DE.AE-02 |
| AU.L2-3.3.6 Reduction & Reporting | reuse candidate (medium) | NIST-CSF-DE.AE-02 |
| AU.L2-3.3.7 Time Stamps & Synchronization | no candidate: CMMC-specific evidence | |
| AU.L2-3.3.8 Audit Protection | reuse candidate (high) | NIST-CSF-PR.AA-05, NIST-CSF-RS.AN-07 |
| AU.L2-3.3.9 Audit Management | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| Security Assessment | ||
| CA.L2-3.12.1 Security Control Assessment | reuse candidate (high) | NIST-CSF-ID.IM-02 |
| CA.L2-3.12.2 Plan of Action | reuse candidate (high) | NIST-CSF-ID.RA-06, NIST-CSF-ID.IM-02 |
| CA.L2-3.12.3 Security Control Monitoring | reuse candidate (medium) | NIST-CSF-ID.IM-03 |
| CA.L2-3.12.4 System Security Plan | reuse candidate (medium) | NIST-CSF-GV.PO-01, NIST-CSF-GV.PO-02 |
| Configuration Management | ||
| CM.L2-3.4.1 System Baselining | reuse candidate (high) | NIST-CSF-PR.PS-01, NIST-CSF-ID.AM-02, NIST-CSF-ID.AM-01 |
| CM.L2-3.4.2 Security Configuration Enforcement | reuse candidate (high) | NIST-CSF-PR.PS-01 |
| CM.L2-3.4.3 System Change Management | reuse candidate (high) | NIST-CSF-ID.RA-07, NIST-CSF-ID.AM-08 |
| CM.L2-3.4.4 Security Impact Analysis | reuse candidate (high) | NIST-CSF-ID.RA-07 |
| CM.L2-3.4.5 Access Restrictions for Change | reuse candidate (medium) | NIST-CSF-ID.RA-07 |
| CM.L2-3.4.6 Least Functionality | reuse candidate (high) | NIST-CSF-PR.PS-01 |
| CM.L2-3.4.7 Nonessential Functionality | reuse candidate (medium) | NIST-CSF-PR.PS-01 |
| CM.L2-3.4.8 Application Execution Policy | reuse candidate (high) | NIST-CSF-PR.PS-05 |
| CM.L2-3.4.9 User-Installed Software | reuse candidate (high) | NIST-CSF-PR.PS-05 |
| Identification and Authentication | ||
| IA.L2-3.5.1 Identification | reuse candidate (high) | NIST-CSF-PR.AA-01, NIST-CSF-PR.AA-02 |
| IA.L2-3.5.10 Cryptographically-Protected Passwords | reuse candidate (high) | NIST-CSF-PR.AA-04, NIST-CSF-PR.AA-04 |
| IA.L2-3.5.11 Obscure Feedback | no candidate: CMMC-specific evidence | |
| IA.L2-3.5.2 Authentication | reuse candidate (high) | NIST-CSF-PR.AA-03 |
| IA.L2-3.5.3 Multifactor Authentication | reuse candidate (high) | NIST-CSF-PR.AA-03 |
| IA.L2-3.5.4 Replay-Resistant Authentication | reuse candidate (high) | NIST-CSF-PR.AA-03, NIST-CSF-PR.AA-04, NIST-CSF-PR.AA-04 |
| IA.L2-3.5.5 Identifier Reuse | reuse candidate (high) | NIST-CSF-PR.AA-01, NIST-CSF-PR.AA-01 |
| IA.L2-3.5.6 Identifier Handling | reuse candidate (high) | NIST-CSF-PR.AA-01 |
| IA.L2-3.5.7 Password Complexity | reuse candidate (medium) | NIST-CSF-PR.AA-01 |
| IA.L2-3.5.8 Password Reuse | reuse candidate (medium) | NIST-CSF-PR.AA-01 |
| IA.L2-3.5.9 Temporary Passwords | reuse candidate (medium) | NIST-CSF-PR.AA-01 |
| Incident Response | ||
| IR.L2-3.6.1 Incident Handling | reuse candidate (high) | NIST-CSF-ID.IM-04, NIST-CSF-RS.MI-01, NIST-CSF-RS.MA-03, NIST-CSF-RS.MA-04, NIST-CSF-DE.AE-04, NIST-CSF-RS.MI-02, NIST-CSF-RS.MA-02, NIST-CSF-RS.MA-01, NIST-CSF-DE.AE-08, NIST-CSF-RC.RP-01 |
| IR.L2-3.6.2 Incident Reporting | reuse candidate (high) | NIST-CSF-RS.CO-02, NIST-CSF-DE.AE-06, NIST-CSF-RS.CO-03, NIST-CSF-RS.AN-06, NIST-CSF-RC.CO-03 |
| IR.L2-3.6.3 Incident Response Testing | reuse candidate (high) | NIST-CSF-ID.IM-01 |
| Maintenance | ||
| MA.L2-3.7.1 Perform Maintenance | reuse candidate (high) | NIST-CSF-PR.PS-03 |
| MA.L2-3.7.2 System Maintenance Control | reuse candidate (high) | NIST-CSF-PR.PS-03, NIST-CSF-PR.PS-03 |
| MA.L2-3.7.3 Equipment Sanitization | reuse candidate (high) | NIST-CSF-PR.PS-03 |
| MA.L2-3.7.4 Media Inspection | no candidate: CMMC-specific evidence | |
| MA.L2-3.7.5 Nonlocal Maintenance | reuse candidate (high) | NIST-CSF-PR.AA-03 |
| MA.L2-3.7.6 Maintenance Personnel | no candidate: CMMC-specific evidence | |
| Media Protection | ||
| MP.L2-3.8.1 Media Protection | reuse candidate (medium) | NIST-CSF-PR.DS-01 |
| MP.L2-3.8.2 Media Access | reuse candidate (medium) | NIST-CSF-PR.AA-05 |
| MP.L2-3.8.3 Media Disposal | reuse candidate (high) | NIST-CSF-PR.PS-03 |
| MP.L2-3.8.4 Media Markings | reuse candidate (medium) | NIST-CSF-ID.AM-05 |
| MP.L2-3.8.5 Media Accountability | reuse candidate (medium) | NIST-CSF-PR.AA-06 |
| MP.L2-3.8.6 Portable Storage Encryption | reuse candidate (high) | NIST-CSF-PR.DS-01 |
| MP.L2-3.8.7 Removable Media | no candidate: CMMC-specific evidence | |
| MP.L2-3.8.8 Shared Media | no candidate: CMMC-specific evidence | |
| MP.L2-3.8.9 Protect Backups | reuse candidate (high) | NIST-CSF-PR.DS-11, NIST-CSF-PR.DS-11 |
| Physical Protection | ||
| PE.L2-3.10.1 Limit Physical Access | reuse candidate (high) | NIST-CSF-PR.AA-06 |
| PE.L2-3.10.2 Monitor Facility | reuse candidate (high) | NIST-CSF-DE.CM-02, NIST-CSF-PR.IR-02 |
| PE.L2-3.10.3 Escort Visitors | reuse candidate (high) | NIST-CSF-PR.AA-06 |
| PE.L2-3.10.4 Physical Access Logs | reuse candidate (high) | NIST-CSF-DE.CM-02, NIST-CSF-PR.AA-06 |
| PE.L2-3.10.5 Manage Physical Access | reuse candidate (high) | NIST-CSF-PR.AA-06, NIST-CSF-PR.AA-06 |
| PE.L2-3.10.6 Alternative Work Sites | no candidate: CMMC-specific evidence | |
| Personnel Security | ||
| PS.L2-3.9.1 Screen Individuals | reuse candidate (high) | NIST-CSF-GV.RR-04 |
| PS.L2-3.9.2 Personnel Actions | reuse candidate (high) | NIST-CSF-GV.RR-04 |
| Risk Assessment | ||
| RA.L2-3.11.1 Risk Assessments | reuse candidate (high) | NIST-CSF-ID.RA-05, NIST-CSF-ID.RA-03, NIST-CSF-ID.RA-04 |
| RA.L2-3.11.2 Vulnerability Scan | reuse candidate (high) | NIST-CSF-ID.RA-01 |
| RA.L2-3.11.3 Vulnerability Remediation | reuse candidate (high) | NIST-CSF-ID.RA-06 |
| System and Communications Protection | ||
| SC.L2-3.13.1 Boundary Protection | reuse candidate (high) | NIST-CSF-PR.IR-01 |
| SC.L2-3.13.10 Key Management | reuse candidate (medium) | NIST-CSF-PR.DS-02 |
| SC.L2-3.13.11 CUI Encryption | reuse candidate (high) | NIST-CSF-PR.DS-02 |
| SC.L2-3.13.12 Collaborative Device Control | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.13 Mobile Code | reuse candidate (medium) | NIST-CSF-PR.PS-05 |
| SC.L2-3.13.14 Voice over Internet Protocol | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.15 Communications Authenticity | reuse candidate (medium) | NIST-CSF-PR.AA-04 |
| SC.L2-3.13.16 Data at Rest | reuse candidate (high) | NIST-CSF-PR.DS-01 |
| SC.L2-3.13.2 Security Engineering | reuse candidate (high) | NIST-CSF-PR.PS-06 |
| SC.L2-3.13.3 Role Separation | reuse candidate (medium) | NIST-CSF-PR.IR-01 |
| SC.L2-3.13.4 Shared Resource Control | reuse candidate (medium) | NIST-CSF-PR.DS-10 |
| SC.L2-3.13.5 Public-Access System Separation | reuse candidate (high) | NIST-CSF-PR.IR-01 |
| SC.L2-3.13.6 Network Communication by Exception | reuse candidate (high) | NIST-CSF-PR.IR-01 |
| SC.L2-3.13.7 Split Tunneling | no candidate: CMMC-specific evidence | |
| SC.L2-3.13.8 Data in Transit | reuse candidate (high) | NIST-CSF-PR.DS-02 |
| SC.L2-3.13.9 Connections Termination | no candidate: CMMC-specific evidence | |
| System and Information Integrity | ||
| SI.L2-3.14.1 Flaw Remediation | reuse candidate (high) | NIST-CSF-ID.RA-01, NIST-CSF-PR.PS-02 |
| SI.L2-3.14.2 Malicious Code Protection | reuse candidate (high) | NIST-CSF-DE.CM-09 |
| SI.L2-3.14.3 Security Alerts & Advisories | reuse candidate (high) | NIST-CSF-ID.RA-02, NIST-CSF-DE.AE-07 |
| SI.L2-3.14.4 Update Malicious Code Protection | reuse candidate (medium) | NIST-CSF-DE.CM-09 |
| SI.L2-3.14.5 System & File Scanning | reuse candidate (high) | NIST-CSF-DE.CM-09 |
| SI.L2-3.14.6 Monitor Communications for Attacks | reuse candidate (high) | NIST-CSF-DE.CM-01, NIST-CSF-DE.AE-02, NIST-CSF-DE.CM-09 |
| SI.L2-3.14.7 Identify Unauthorized Use | reuse candidate (high) | NIST-CSF-DE.CM-03 |
A subcontractor that ticks NIST CSF 2.0 on the collection form sees these counts back as a courtesy, and the prime's Solo plan exports them as a starting sheet with the evidence an assessor asks for. High and medium confidence are shown apart and never added into one figure, and the count with no candidate is always shown beside them. Compare the two frameworks in full on compliance.theartofservice.com; NIST CSF 2.0 itself: NIST CSF 2.0.