Reference · NIST 800-171 Rev 2 / CMMC Level 2

All 110 NIST 800-171 controls, explained

CMMC Level 2 maps to all 110 security requirements in NIST SP 800-171 Rev 2, organized into 14 families. Each control page below gives the official requirement, a plain-English explanation, the SPRS deduction if unmet, step-by-step remediation, the evidence a C3PAO assessor asks for — and an honest verdict on whether AI prompt monitoring helps with it.

ACAccess Control22 controls

Limit system access to authorized users, processes, and devices

ATAwareness & Training3 controls

Ensure personnel are aware of security risks and trained in policies

AUAudit & Accountability9 controls

Create, protect, and retain system audit records

CMConfiguration Management9 controls

Establish and maintain baseline configurations and inventories

IAIdentification & Authentication11 controls

Identify and authenticate users, processes, and devices

IRIncident Response3 controls

Establish operational incident-handling capability

MAMaintenance6 controls

Perform timely maintenance on organizational systems

MPMedia Protection9 controls

Protect, sanitize, and destroy media containing CUI

PSPersonnel Security2 controls

Screen individuals and protect CUI during personnel actions

PEPhysical Protection6 controls

Limit physical access to systems and protect physical plant

RARisk Assessment3 controls

Periodically assess risk to operations, assets, and individuals

CASecurity Assessment4 controls

Assess, monitor, and correct deficiencies in security controls

SCSystem & Communications Protection16 controls

Monitor, control, and protect communications at boundaries

SISystem & Information Integrity7 controls

Identify, report, and correct system flaws in a timely manner

Turn this list into your SPRS score

The free ShieldReady assessment walks all 110 controls and computes your score as you go.