Published by Capital Cyber | Leesburg, VA | (571) 410 3066

When a CMMC Level 2 self-assessment lands on your calendar, the most common mistake is reviewing controls in isolation rather than working through them as a structured set. NIST SP 800-171 organizes its 110 requirements into 14 control families. Work through each family before your assessment and you know exactly where you stand. Skip any and you leave gaps that surface at the worst possible time - in an official assessment or in a DCAA audit.

This article walks through each of the 14 families: what it covers, how many requirements it contains, and the gap that most subcontractors overlook. It is not a substitute for a formal gap assessment, but it will orient your team and help you prioritize remediation before the clock starts.

The 14 families at a glance

Abbr.FamilyRequirements
ACAccess Control22
ATAwareness and Training3
AUAudit and Accountability9
CMConfiguration Management9
IAIdentification and Authentication11
IRIncident Response3
MAMaintenance6
MPMedia Protection9
PSPersonnel Security2
PEPhysical Protection6
RARisk Assessment5
CASecurity Assessment4
SCSystem and Communications Protection16
SISystem and Information Integrity7

What to look for in each family

AC Access Control 22 requirements

Governs who can access CUI, on what systems, under what conditions, and through which pathways - including remote access and mobile devices. This is the most scrutinized family in any assessment because it touches almost every other control area.

Common gap

Least-privilege is documented on paper but not enforced in practice. Users accumulate permissions over time without periodic review, and remote access policies exist but are not technically enforced.

AT Awareness and Training 3 requirements

Requires that personnel with CUI access receive security awareness training and that individuals with elevated responsibilities receive role-based training commensurate with their duties.

Common gap

Training happened verbally at onboarding and was never recorded. No documentation of who received what training, when, or what it covered. A small family by requirement count but easy to score zero on without records.

AU Audit and Accountability 9 requirements

Covers creation, protection, retention, and review of audit logs for systems that process or store CUI. Assessors will ask to see logs, confirm they are tamper-resistant, and verify that someone actually reviews them.

Common gap

Logging is enabled on the firewall and endpoints but logs are never reviewed and have no defined retention period. Log storage is on the same system being audited, which means logs could be altered.

CM Configuration Management 9 requirements

Requires a documented baseline configuration for CUI systems and a process for controlling changes to that baseline. Unauthorized software must be identified and blocked or removed.

Common gap

No formal baseline has been documented. Software is installed by employees without going through an approval process, and there is no inventory of what is running on which system.

IA Identification and Authentication 11 requirements

Covers unique identification of users and devices, multi-factor authentication for privileged and remote access, and password management. MFA requirements in this family are among the most commonly cited deficiencies across the DIB.

Common gap

MFA is enabled on email but not on the VPN or systems that directly store CUI. Shared service accounts exist. Password complexity rules are set in policy but not enforced by the system.

IR Incident Response 3 requirements

Requires an incident response capability: a documented plan, a process for handling incidents, and a mechanism for testing that plan. Under DFARS 252.204-7012, contractors must also report certain cyber incidents to DoD within 72 hours.

Common gap

An incident response plan was drafted but has never been tested or updated. The 72-hour DoD reporting requirement is either unknown or not reflected in the plan.

MA Maintenance 6 requirements

Controls how maintenance is performed on CUI systems, with specific requirements around remote maintenance tools, maintenance personnel who are not employees, and logging of maintenance activities.

Common gap

A third-party IT provider uses remote support tools to access CUI systems, but that access is not logged, is not reviewed after the session ends, and the tools remain persistently installed rather than being used on demand.

MP Media Protection 9 requirements

Covers protection, transport, and disposal of media that contains CUI - including portable drives, laptops, printed documents, and digital output. Sanitization requirements apply before media is reused, repurposed, or discarded.

Common gap

USB drives travel in and out of the building with no tracking or encryption. Paper documents containing CUI are placed in standard recycling bins rather than shredded, and there is no sanitization process for retired hard drives.

PS Personnel Security 2 requirements

Requires screening individuals before granting access to CUI systems and revoking access upon termination or role change. Small by count, but a clean termination process is an area assessors frequently probe.

Common gap

No formal screening process is documented. More commonly, offboarding is inconsistent: departing employees retain active credentials for days after their last day because there is no termination checklist that ties access revocation to HR notification.

PE Physical Protection 6 requirements

Requires physical access controls for facilities and systems that store or process CUI. This includes managing visitor access and maintaining physical access logs.

Common gap

Servers or workstations that hold CUI sit in an unlocked room accessible to all employees and visitors. There are no visitor logs, no escort requirements, and no record of who accessed the physical space.

RA Risk Assessment 5 requirements

Requires periodic risk assessments of CUI systems and regular vulnerability scanning. The output of this family feeds directly into your Plan of Action and Milestones (POA&M) and your SPRS score.

Common gap

No formal risk assessment has been conducted or documented. Vulnerability scans are either not running or their results are never acted on and connected back to a remediation plan.

CA Security Assessment 4 requirements

Requires a System Security Plan (SSP), a plan of action and milestones for deficiencies, and periodic review of security controls. Your SSP is the document that defines the boundary of your CUI environment - without it, you cannot meaningfully self-assess anything else.

Common gap

An SSP was started but is incomplete, outdated, or does not accurately describe the current system boundary. There is no active POA&M that tracks open deficiencies and target remediation dates.

SC System and Communications Protection 16 requirements

Covers network architecture, segmentation of CUI from other traffic, encryption of data in transit, and controls on external connections. Second only to Access Control in requirement count and scope.

Common gap

CUI flows across the same network as general business traffic with no segmentation. Email containing CUI is sent unencrypted. There is no documented boundary between the CUI environment and other systems or external connections.

SI System and Information Integrity 7 requirements

Covers malware protection, security alerts, patch management, and monitoring of CUI systems for anomalous behavior. This family ties together several operational security practices that are often present but poorly documented.

Common gap

Antivirus is deployed but centralized monitoring of its status is absent, so infected endpoints go unnoticed. Patch management is informal, meaning critical patches are applied eventually but not within any defined window.

How these families connect to your SPRS score

Your Supplier Performance Risk System score is calculated by starting at 110 - one point per met requirement - and subtracting the weighted value of every gap. The DoD assessment methodology assigns different point weights to different requirements, so not all gaps cost the same. Gaps in Access Control and System and Communications Protection tend to carry the highest individual penalties because of the number of requirements involved.

You are required to submit your SPRS score under DFARS 252.204-7019. That score is visible to contracting officers and can affect your competitiveness on bids. An honest, well-documented self-assessment is both a compliance requirement and a business advantage - contractors who can point to a current, accurate SSP and a clean SPRS score stand out during source selection.

Important Note

Self-assessment vs. third-party assessment

CMMC Level 2 allows self-assessment for contracts that do not involve prioritized acquisition programs. For contracts that involve critical programs or technologies, a Certified Third-Party Assessment Organization (C3PAO) assessment is required. Check your contract requirements carefully before relying on self-attestation - your contracting officer and legal counsel can help you determine which path applies.

Frequently asked questions

What are the 14 control families in NIST SP 800-171?

The 14 families are: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Together they cover 110 security requirements.

Can a subcontractor do a CMMC Level 2 self-assessment?

Yes, for contracts that do not involve prioritized acquisition programs. CMMC Level 2 allows self-assessment and annual affirmation for those contracts. Contracts involving critical programs or technologies require a third-party assessment by a C3PAO.

What is an SPRS score and how does it relate to these control families?

The Supplier Performance Risk System (SPRS) score reflects how many of the 110 NIST SP 800-171 requirements your organization currently meets, weighted by the DoD assessment methodology. Submitting an accurate SPRS score is a contract requirement under DFARS 252.204-7019.

Which control family has the most requirements?

Access Control has the most, with 22 requirements. System and Communications Protection is second with 16, followed by Identification and Authentication with 11.

Your next step

Knowing the 14 families is the starting point. Knowing exactly where your organization stands against all 110 requirements is what produces an SPRS score you can defend. Request a NIST Gap Assessment from Capital Cyber and we will map every requirement to your current controls, identify the gaps by family, and give you a prioritized remediation plan before your assessment date.

Defense contractors may also qualify for a fully funded CMMC Gap Assessment Grant through Cyber Grants Alliance, covering all 110 NIST 800-171 controls at no cost.

Request a NIST Gap Assessment
Disclaimer: This article is for informational purposes and reflects NIST SP 800-171 Rev 2 and CMMC 2.0 as of the publish date. CMMC rules and DoD assessment guidance continue to evolve. Always verify requirements with your contracting officer and a qualified government contracts or cybersecurity professional before conducting or submitting a self-assessment.