Skip to main content

Elevate

NIST 800-171 Compliance Checklist: All 14 Control Families

A NIST 800-171 compliance checklist is most useful when it follows the standard’s own structure, because NIST SP 800-171 organizes its 110 requirements into 14 control families, and an assessment works through them family by family. Treating compliance as one undifferentiated list of 110 items is how contractors lose track of where they stand; treating it as 14 families, each with a purpose and a set of evidence, is how they stay oriented. This checklist walks all 14 families, what each one covers, and the evidence each needs before an assessment.

The value of the family view is that it turns an overwhelming standard into a manageable map. Each family groups related requirements around a single security objective, so you can assess your posture one objective at a time and know exactly what evidence an assessor will expect for each. Used before an assessment, the checklist tells you not just whether a control exists but whether you can prove it, which is the distinction that decides your score.

The 14 NIST 800-171 Control Families

The table below lists all 14 families in the order the standard presents them, with the objective each addresses and the kind of evidence that demonstrates it. It is the fastest way to see the whole standard at a glance and to identify which families are strongest and weakest in your environment.

Control familyWhat it coversKey evidence to keep
3.1 Access ControlWho and what can access systems and controlled unclassified informationAccess control policy, account and privilege lists, least-privilege configuration
3.2 Awareness and TrainingSecurity awareness and role-based training for usersTraining completion records, awareness materials
3.3 Audit and AccountabilityLogging activity and reviewing itAudit logs, log-review records, retention settings
3.4 Configuration ManagementSecure, controlled baselines and change controlBaseline configurations, change records, approved-software lists
3.5 Identification and AuthenticationVerifying the identity of users and devicesMultifactor authentication configuration, authentication policy
3.6 Incident ResponseDetecting, handling, and reporting incidentsIncident response plan, incident logs, test records
3.7 MaintenancePerforming and controlling system maintenanceMaintenance logs, maintenance-tool control records
3.8 Media ProtectionProtecting and sanitizing media that holds CUIMedia handling policy, sanitization and disposal records
3.9 Personnel SecurityScreening personnel and managing access on changesScreening records, access-removal-on-termination records
3.10 Physical ProtectionControlling physical access to systems and facilitiesPhysical access logs, visitor records, facility controls
3.11 Risk AssessmentIdentifying and assessing risk, including vulnerabilitiesRisk assessments, vulnerability scan records
3.12 Security AssessmentAssessing controls and planning remediationSystem Security Plan, Plan of Action and Milestones
3.13 System and Communications ProtectionProtecting data in transit and system boundariesFIPS-validated encryption configuration, boundary protection records
3.14 System and Information IntegrityFinding and fixing flaws and malicious codePatch and update records, malware protection, monitoring records

The table is the map, but the work is in the evidence column, because that is what an assessment actually examines. A family where the controls are implemented but the evidence is thin will not score as well as its reality deserves, so the checklist is best used to test each family twice: once for whether the control is in place, and once for whether you can prove it.

Evidence Each Family Needs

Walking the families in related groups makes the evidence expectations clearer than reading them in isolation. The access and identity families, Access Control and Identification and Authentication, together govern who reaches your systems, and their evidence is largely configuration and policy: account and privilege records, least-privilege settings, and the multifactor authentication configuration that a heavily weighted requirement depends on. Awareness and Training sits alongside them, evidenced by the records showing your people were actually trained.

The configuration and maintenance families, Configuration Management and Maintenance, govern how your systems are built and kept, and their evidence is baselines, change records, and maintenance logs that show control rather than ad hoc administration. The media, physical, and personnel families, Media Protection, Physical Protection, and Personnel Security, protect controlled unclassified information from physical and human exposure, evidenced by handling and sanitization records, physical access and visitor logs, and personnel screening and access-removal records.

The monitoring and integrity families, Audit and Accountability and System and Information Integrity, are where many assessments find gaps, because collecting logs and deploying protection is only half the requirement; the evidence has to show the logs are reviewed and the flaws are remediated. Incident Response and Risk Assessment cover detecting and anticipating problems, evidenced by an incident response plan with test records and by risk assessments and vulnerability scans. Finally, System and Communications Protection and Security Assessment protect your data and document your posture, evidenced by FIPS-validated encryption configuration and boundary controls on one side and your System Security Plan and Plan of Action and Milestones on the other. For the incident response family specifically, the requirements and their evidence are covered in depth in the guide to CMMC incident response.

How to Use This NIST 800-171 Compliance Checklist Before an Assessment

The checklist earns its keep when you run it as a two-pass exercise rather than a single tick-through. On the first pass, go family by family and mark honestly whether each requirement is implemented, resisting the urge to round up a partial control to a complete one. On the second pass, go back through and ask, for each requirement you marked as implemented, whether you have the evidence to prove it, because the assessment scores demonstrable implementation and treats an unprovable control as absent.

What emerges from those two passes is a prioritized list of gaps, and that list is the input to the rest of your preparation. Turning it into a scored picture and a remediation plan is the work of a CMMC gap assessment, and understanding how the families are scored, including the weighting that makes some gaps costlier than others, is covered in the guide to the NIST 800-171 assessment. Placing the whole effort in context, from checklist to assessment, is what a CMMC readiness assessment does. This 800-171 family checklist is distinct from a broader CMMC compliance checklist, which covers the CMMC process and CUI-handling workflows around the standard.

From Checklist to Policy

A checklist tells you what evidence each family needs, but much of that evidence rests on written policy, because most families require a documented policy that describes how you meet the requirements. Producing 14 families of policy from a blank page is one of the slowest parts of compliance, which is why starting from a proven, tailored policy set is the efficient path. Elevate’s CMMC Level 2 Master Policy Compendium provides policy sets mapped to the families, so the documentation half of your checklist becomes a tailoring exercise rather than a writing project. With policy in place and evidence organized by family, the checklist stops being a source of anxiety and becomes a record of readiness.

Conclusion

A NIST 800-171 compliance checklist organized by the 14 control families turns a daunting standard into a map you can work through one objective at a time, and pairing each family with the evidence it needs turns the checklist from a list of controls into a test of readiness. The families do not change with the current suspension, and 800-171 remains the live standard, so the checklist is as useful today as it will be when third-party assessment resumes. Run it as two passes, one for implementation and one for evidence, and it will show you exactly where you stand.

The contractors who use the checklist best treat the evidence column as the real work and build their policy foundation from proven templates rather than from scratch. To turn a family-by-family checklist into a documented, assessment-ready program, book a call with an Elevate advisor.

Key Takeaways

A NIST 800-171 compliance checklist works best organized by the standard’s 14 control families, each paired with the evidence an assessment expects.

  • The standard has 14 families: NIST SP 800-171 groups its 110 requirements into 14 families, from Access Control to System and Information Integrity, and an assessment works through them family by family.
  • Evidence is the real test: for each family, the question is not only whether a control exists but whether you can prove it, because an unprovable control is scored as not met.
  • Some families are common gap areas: audit and monitoring, and system integrity, often fall short because collecting logs and deploying tools is only half the requirement, with review and remediation the other half.
  • Run it as two passes: mark implementation honestly first, then verify the evidence for each implemented control, and the result is a prioritized gap list.
  • Policy underpins the checklist: most families require a documented policy, and building those from a proven, tailored set is far faster than writing 14 families of policy from scratch.

FAQs

Q1. What are the 14 NIST 800-171 control families? NIST SP 800-171 organizes its 110 requirements into 14 control families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each family groups requirements around a single security objective, which is why a compliance checklist organized by family is easier to work through than a flat list of 110 items.

Q2. What is a NIST 800-171 compliance checklist? A NIST 800-171 compliance checklist is a structured way to assess your environment against the standard’s requirements, ideally organized by its 14 control families so you can evaluate one security objective at a time. A good checklist pairs each family with the evidence an assessor expects, so it tests not only whether a control is implemented but whether you can prove it. Used before an assessment, it produces a prioritized list of the gaps you need to close.

Q3. What evidence does each NIST 800-171 family need? The evidence varies by family but generally combines policy, configuration, and records. Access and identity families rely on account records, least-privilege settings, and multifactor authentication configuration; audit and integrity families rely on logs plus proof they are reviewed and flaws remediated; media, physical, and personnel families rely on handling, access, and screening records; and the security assessment family rests on the System Security Plan and Plan of Action and Milestones. The consistent rule is that a control which cannot be evidenced is treated as not met.

Q4. How do I use a NIST 800-171 checklist before an assessment? Run it as a two-pass exercise. On the first pass, mark honestly whether each requirement is implemented, without rounding partial controls up to complete. On the second pass, confirm that you have the evidence to prove each implemented control, because the assessment scores demonstrable implementation. The gaps that emerge become your remediation priorities, which a gap assessment can turn into a scored plan and a readiness assessment can place in full context.

Q5. Is the NIST 800-171 checklist affected by the 2026 CMMC suspension? No. The 14 control families and the 110 requirements of NIST SP 800-171 Revision 2 are unchanged, and 800-171 remains the live standard during the suspension, which paused third-party certification assessment rather than the underlying requirements. The self-assessment against these families is the live obligation, so a family-by-family checklist is as relevant today as it will be when third-party assessment resumes. A future move to Revision 3 is expected through rulemaking but has no finalized deadline.