Government / NIST
Available nowNIST SP 800-171 · Rev. 2
NIST SP 800-171 Rev. 2 protects Controlled Unclassified Information (CUI) on nonfederal systems. Its 110 requirements across 14 families are the scope of CMMC Level 2 and the price of admission for DoD supply-chain work.
110
requirements tracked
Premium
Access
Add-on from $49/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 110 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 110 requirements
- In Keel’s scored scope
- 110 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs NIST SP 800-171?
- Contractors and subcontractors handling CUI for the Department of Defense
- Companies preparing for CMMC Level 2 assessment
- Teams that need an SSP, a POA&M, and an SPRS score they can defend
What Keel does
How Keel helps with NIST SP 800-171
- All 110 requirements across the 14 families as a trackable framework
- Gaps surfaced for your POA&M, and coverage shared with SOC 2 and CIS
- A living readiness view so your SSP and score stay current
Collect once, comply everywhere
NIST SP 800-171 shares canonical controls with ISO/IEC 27001, NIST SP 800-53 and CIS Critical Security Controls and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding NIST SP 800-171 rarely means starting from scratch.
Shares canonical controls with
- ISO/IEC 27001
- CIS Critical Security Controls
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks