Two of 110 requirements come back covered — and that is the honest number.
NSAuditor AI EE maps scan findings to NIST SP 800-171 Rev 2 at the SP 800-171A
determination-statement level, as evidence substrate for CMMC Level 2
preparation. All 110 requirements are enumerated — none sampled, none silently
omitted. It is not a certification, and it makes no assessment determination.
✓ 2 requirements covered⚠ 49 partial⊘ 59 OOS with a written reason⚡ Rev 2 — pinned, not Rev 3Introduced: EE 0.40.0
What this is, stated as a refusal rather than a disclaimer
The approved scope is “NIST SP 800-171 evidence
substrate for CMMC Level 2 preparation”. This engine produces
EXAMINE-method material an assessor reads. It is not a
CMMC certification — certification is a per-contractor C3PAO assessment
outcome. It is not a FedRAMP authorization, and
running in a government region is not one either. It emits
no MET / NOT MET determination — those are
the assessor’s words — and no SPRS
score, because the DoD Assessment Methodology’s weighted deductions require
the full 110-requirement determination and a score implied from partial evidence is a
fabrication.
A misrepresented SP 800-171 posture is the shape the DOJ Civil Cyber-Fraud Initiative
settles. That is why the wording above is a refusal rule inside the product and not a
footnote on this page.
CMMC Level 2 certification comes from a C3PAO assessing a contractor against NIST SP
800-171 Rev 2 using the SP 800-171A assessment objectives. Nothing a scanner produces is that
assessment. What a scanner can produce is substrate: configuration state an assessor
reads under the EXAMINE method, for the subset of objectives that are statements about
technical system state.
SP 800-171A recognises three methods — EXAMINE, INTERVIEW, TEST. This engine supplies
material for one of them, for some objectives. Every claim on this page is bounded by that
sentence.
Why only two of 110 come back “covered”
Because coverage is claimed at the objective level, which is where it is scored. Each
requirement decomposes into determination statements, and a C3PAO scores every one. A
requirement is covered here only when every one of its objectives is
a statement about technical system state the scan reads directly.
Almost every requirement retains at least one objective about a defined procedure, an
identified set, an authorization, or an organization-defined parameter. Configuration
cannot evidence any of those. Two requirements clear the bar. A product reporting many more is
either measuring something else, or claiming a requirement from a subset of its objectives
— which is the first overclaim a C3PAO tests for.
The 49 partial entries each name which objectives the engine supplies material
for and which it does not, so an assessor can thread the evidence rather than take a colour on
trust.
Rev 2 is pinned — and Rev 3 is a different universe
CMMC assesses Rev 2 by rule. Rev 3 (2024) is 97 requirements with organization-defined
parameters. Answering a Rev 3 question with Rev 2 output is drift, not currency, and a
universe that accepted 97 would be accepting the wrong baseline. Every citation on this page
and in the report is a Rev 2 3.x.y identifier.
One consequence worth stating: SP 800-171 requirement identifiers collide exactly with
PCI DSS sub-requirement identifiers — 3.5.1 is a real identifier in
both standards. Every citation therefore carries its qualifier. A bare 3.5.1 is
ambiguous to a reader and unattributable to an instrument.
CUI scope is the operator’s assertion, not the scanner’s finding
The scanner cannot see CUI. It cannot distinguish FCI (Level 1, FAR 52.204-21) from CUI
(Level 2), and it cannot see an enclave boundary — which matters, because the
dominant DIB architecture is a CUI enclave built precisely to shrink the assessed scope.
Every control carries its own CUI-scope caveat. The product’s offline operation
fits enclave deployments; fitting inside a boundary is not defining one, and this
engine never asserts where yours lies.
Coverage matrix — the full Rev 2 universe
110 requirements across 14 families, enumerated in full rather than as a declared subset. 110
is small enough to carry every requirement with an explicit reason, so there is no
under-enumeration surface at all.
Classification
Count
What it means
Covered
2
Every SP 800-171A objective for the requirement is technical system state this scan reads directly.
Partial
49
Material for some objectives; the entry names which, and which it does not reach.
Out of scope
59
Grouped, each group with a written reason — predominantly operator-side process.
Total
110
The complete Rev 2 universe. Nothing is unclassified.
The authoritative source is data/compliance/nist-800-171.json; the engine reads it
directly and every figure here is derived from its coverageSummary.
Five families are operator-side in their entirety
Awareness and Training (3.2), Incident Response execution (3.6), Maintenance (3.7), Personnel
Security (3.9) and Physical Protection (3.10) are out of scope by design for any
infrastructure scanner. Their evidence streams are LMS records, runbooks and tabletop logs,
HR process, and facility control — none of it system state.
Naming them as out of scope with the reason is the point. A matrix that silently omits
them reports a better-looking ratio and tells an assessor less.
The SSP and the POA&M are operator artifacts
The System Security Plan (3.12.4) is what a C3PAO assesses against. Configuration
evidence is an input to it, never a substitute for it. The POA&M (3.12.2) is rule-bounded
under CMMC: only limited-weight requirements may be left open, and closeout is clocked.
This engine informs both and produces neither. Any tool that says “gap → just
POA&M it” without checking whether the requirement is POA&M-able is giving advice
the rule forbids.
DFARS 252.204-7012 obligations are signal-adjacent only
72-hour rapid reporting to DIBNet, malicious-software submission, and 90-day media preservation
are operator obligations. The engine’s monitoring substrate feeds detection; it
discharges none of them.
For an external cloud service provider handling CUI, clause (b)(2)(ii)(D) raises FedRAMP
Moderate baseline equivalency — a Customer Responsibility Matrix question about
what is inherited and what is retained, answered by the operator with the provider’s
package in hand. It is never a transferred authorization, and this scanner does not answer it.
Two numbers we deliberately did not ship
An early build carried a per-requirement SPRS scoring weight and a basic-versus-derived
requirement type. Both were transcribed from sources this product does not hold, and an
adversarial review disputed specific values in each. Both were removed rather than guessed.
The rule applied: a compliance datum ships only when the authority it can be re-derived
from is held and citable. The weight had a second, independent reason to go — it
is the multiplicand of the deduction arithmetic, so shipping it hands a reader the implied
score the doctrine forbids.
Requires Community Edition >= 0.2.45 — the version that registers the
framework name. An older Community build rejects it.
Zero Data Exfiltration
The scan runs where your systems are and writes its evidence to a path you choose. Findings are
not shipped to a vendor tenant for processing, which is the property that makes the tool usable
inside a CUI enclave in the first place — and it is also why this page can make no claim
about your boundary: the product never sees enough to have an opinion about it.
C3PAO / assessor FAQ
“CMMC certified” is deliberately not claimed by this product — so what does a clean scan actually mean?
No. Certification is the outcome of a C3PAO assessment of your organization. A clean scan is
preparation substrate and nothing more.
Which MET determinations did the scanner make?
None. The scanner makes no determinations. It supplies EXAMINE-method material for named
objectives; MET / NOT MET / N/A is the assessor’s to record.
What is our SPRS score?
Not computable from scan output, and not emitted. The DoD Assessment Methodology requires the
full 110-requirement determination; the annual affirmation in SPRS is a named official’s
attestation, not a tool output.
Which scanned systems process CUI?
Unknown to the scanner. CUI scope is your assertion, informed by the NARA CUI Registry
categories and your enclave boundary.
Can you map us to Rev 3?
No. CMMC assesses Rev 2 by rule, and Rev 3 is a different 97-requirement universe with
organization-defined parameters. Rev 3 numbering inside a Rev 2 citation is drift.
“FedRAMP authorized” is deliberately not claimed either — we run in GovCloud, does that change it?
No. FedRAMP authorizes cloud service offerings. Provider inheritance is a Customer
Responsibility Matrix discipline, not a transferred authorization.