Two of 110 requirements come back covered — and that is the honest number.

NSAuditor AI EE maps scan findings to NIST SP 800-171 Rev 2 at the SP 800-171A determination-statement level, as evidence substrate for CMMC Level 2 preparation. All 110 requirements are enumerated — none sampled, none silently omitted. It is not a certification, and it makes no assessment determination.

✓ 2 requirements covered ⚠ 49 partial ⊘ 59 OOS with a written reason ⚡ Rev 2 — pinned, not Rev 3 Introduced: EE 0.40.0

What this is, stated as a refusal rather than a disclaimer

The approved scope is “NIST SP 800-171 evidence substrate for CMMC Level 2 preparation”. This engine produces EXAMINE-method material an assessor reads. It is not a CMMC certification — certification is a per-contractor C3PAO assessment outcome. It is not a FedRAMP authorization, and running in a government region is not one either. It emits no MET / NOT MET determination — those are the assessor’s words — and no SPRS score, because the DoD Assessment Methodology’s weighted deductions require the full 110-requirement determination and a score implied from partial evidence is a fabrication.

A misrepresented SP 800-171 posture is the shape the DOJ Civil Cyber-Fraud Initiative settles. That is why the wording above is a refusal rule inside the product and not a footnote on this page.

NIST SP 800-171 evidence substrate for CMMC Level 2 preparation — eight compliance frameworks mapped from one scan: SOC 2, HIPAA, PCI DSS, NIST CSF 2.0, CIS v8, ISO 27001, GDPR Article 32, and NIST SP 800-171 Rev 2

TL;DR — the scoping doctrine (read this first)

CMMC Level 2 certification comes from a C3PAO assessing a contractor against NIST SP 800-171 Rev 2 using the SP 800-171A assessment objectives. Nothing a scanner produces is that assessment. What a scanner can produce is substrate: configuration state an assessor reads under the EXAMINE method, for the subset of objectives that are statements about technical system state.

SP 800-171A recognises three methods — EXAMINE, INTERVIEW, TEST. This engine supplies material for one of them, for some objectives. Every claim on this page is bounded by that sentence.

Why only two of 110 come back “covered”

Because coverage is claimed at the objective level, which is where it is scored. Each requirement decomposes into determination statements, and a C3PAO scores every one. A requirement is covered here only when every one of its objectives is a statement about technical system state the scan reads directly.

Almost every requirement retains at least one objective about a defined procedure, an identified set, an authorization, or an organization-defined parameter. Configuration cannot evidence any of those. Two requirements clear the bar. A product reporting many more is either measuring something else, or claiming a requirement from a subset of its objectives — which is the first overclaim a C3PAO tests for.

The 49 partial entries each name which objectives the engine supplies material for and which it does not, so an assessor can thread the evidence rather than take a colour on trust.

Rev 2 is pinned — and Rev 3 is a different universe

CMMC assesses Rev 2 by rule. Rev 3 (2024) is 97 requirements with organization-defined parameters. Answering a Rev 3 question with Rev 2 output is drift, not currency, and a universe that accepted 97 would be accepting the wrong baseline. Every citation on this page and in the report is a Rev 2 3.x.y identifier.

One consequence worth stating: SP 800-171 requirement identifiers collide exactly with PCI DSS sub-requirement identifiers3.5.1 is a real identifier in both standards. Every citation therefore carries its qualifier. A bare 3.5.1 is ambiguous to a reader and unattributable to an instrument.

CUI scope is the operator’s assertion, not the scanner’s finding

The scanner cannot see CUI. It cannot distinguish FCI (Level 1, FAR 52.204-21) from CUI (Level 2), and it cannot see an enclave boundary — which matters, because the dominant DIB architecture is a CUI enclave built precisely to shrink the assessed scope.

Every control carries its own CUI-scope caveat. The product’s offline operation fits enclave deployments; fitting inside a boundary is not defining one, and this engine never asserts where yours lies.

Coverage matrix — the full Rev 2 universe

110 requirements across 14 families, enumerated in full rather than as a declared subset. 110 is small enough to carry every requirement with an explicit reason, so there is no under-enumeration surface at all.

ClassificationCountWhat it means
Covered2Every SP 800-171A objective for the requirement is technical system state this scan reads directly.
Partial49Material for some objectives; the entry names which, and which it does not reach.
Out of scope59Grouped, each group with a written reason — predominantly operator-side process.
Total110The complete Rev 2 universe. Nothing is unclassified.

The authoritative source is data/compliance/nist-800-171.json; the engine reads it directly and every figure here is derived from its coverageSummary.

Five families are operator-side in their entirety

Awareness and Training (3.2), Incident Response execution (3.6), Maintenance (3.7), Personnel Security (3.9) and Physical Protection (3.10) are out of scope by design for any infrastructure scanner. Their evidence streams are LMS records, runbooks and tabletop logs, HR process, and facility control — none of it system state.

Naming them as out of scope with the reason is the point. A matrix that silently omits them reports a better-looking ratio and tells an assessor less.

The SSP and the POA&M are operator artifacts

The System Security Plan (3.12.4) is what a C3PAO assesses against. Configuration evidence is an input to it, never a substitute for it. The POA&M (3.12.2) is rule-bounded under CMMC: only limited-weight requirements may be left open, and closeout is clocked.

This engine informs both and produces neither. Any tool that says “gap → just POA&M it” without checking whether the requirement is POA&M-able is giving advice the rule forbids.

DFARS 252.204-7012 obligations are signal-adjacent only

72-hour rapid reporting to DIBNet, malicious-software submission, and 90-day media preservation are operator obligations. The engine’s monitoring substrate feeds detection; it discharges none of them.

For an external cloud service provider handling CUI, clause (b)(2)(ii)(D) raises FedRAMP Moderate baseline equivalency — a Customer Responsibility Matrix question about what is inherited and what is retained, answered by the operator with the provider’s package in hand. It is never a transferred authorization, and this scanner does not answer it.

Two numbers we deliberately did not ship

An early build carried a per-requirement SPRS scoring weight and a basic-versus-derived requirement type. Both were transcribed from sources this product does not hold, and an adversarial review disputed specific values in each. Both were removed rather than guessed.

The rule applied: a compliance datum ships only when the authority it can be re-derived from is held and citable. The weight had a second, independent reason to go — it is the multiplicand of the deduction arithmetic, so shipping it hands a reader the implied score the doctrine forbids.

How to run an SP 800-171 scan

nsauditor-ai scan --host aws --compliance nist-800-171 --env org.env --out ./evidence

It composes with the other seven frameworks from a single scan — one finding stream, separate per-framework artifacts:

nsauditor-ai scan --host aws \
  --compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171 \
  --env org.env --out ./evidence

Requires Community Edition >= 0.2.45 — the version that registers the framework name. An older Community build rejects it.

Zero Data Exfiltration

The scan runs where your systems are and writes its evidence to a path you choose. Findings are not shipped to a vendor tenant for processing, which is the property that makes the tool usable inside a CUI enclave in the first place — and it is also why this page can make no claim about your boundary: the product never sees enough to have an opinion about it.

C3PAO / assessor FAQ

“CMMC certified” is deliberately not claimed by this product — so what does a clean scan actually mean?

No. Certification is the outcome of a C3PAO assessment of your organization. A clean scan is preparation substrate and nothing more.

Which MET determinations did the scanner make?

None. The scanner makes no determinations. It supplies EXAMINE-method material for named objectives; MET / NOT MET / N/A is the assessor’s to record.

What is our SPRS score?

Not computable from scan output, and not emitted. The DoD Assessment Methodology requires the full 110-requirement determination; the annual affirmation in SPRS is a named official’s attestation, not a tool output.

Which scanned systems process CUI?

Unknown to the scanner. CUI scope is your assertion, informed by the NARA CUI Registry categories and your enclave boundary.

Can you map us to Rev 3?

No. CMMC assesses Rev 2 by rule, and Rev 3 is a different 97-requirement universe with organization-defined parameters. Rev 3 numbering inside a Rev 2 citation is drift.

“FedRAMP authorized” is deliberately not claimed either — we run in GovCloud, does that change it?

No. FedRAMP authorizes cloud service offerings. Provider inheritance is a Customer Responsibility Matrix discipline, not a transferred authorization.