{"id":12611,"date":"2021-08-23T01:25:33","date_gmt":"2021-08-23T05:25:33","guid":{"rendered":"https:\/\/tsisupport.com\/?p=12611"},"modified":"2022-01-26T23:26:30","modified_gmt":"2022-01-27T04:26:30","slug":"how-to-find-your-nist-800-171-cmmc-requirements-a-comprehensive-guide-to-determine-your-compliance-requirements-from-your-primes-and-clients","status":"publish","type":"post","link":"https:\/\/tsisupport.com\/tsistaging\/?p=12611","title":{"rendered":"How to Find Your NIST 800-171 &#038; CMMC Requirements: A Comprehensive Guide to Determine Your Compliance Requirements from Your Primes &#038; Clients"},"content":{"rendered":"<p>One of the most frequently asked questions I receive is:<\/p>\n<p><i>\u201cHow do I know if I need to be compliant with either the NIST 800-171 or CMMC frameworks?\u201d<\/i><\/p>\n<p>The bottom line is that if you possess controlled unclassified information (CUI) then your organization will likely have to fulfill these compliance requirements- even if you are considered a commercial off the shelf (COTS) company if you\u2019re required to do so by your clients. Unfortunately, it\u2019s not always clear to many organizations if they fall under this umbrella, so we\u2019ve developed a comprehensive guide to help clarify your compliance obligations to not only ensure you\u2019re in good standing with your existing contracts but are also able to bid for future contracts which will include both of these requirements.<\/p>\n<h4><strong>Speak to your Clients &amp; Vendors:<\/strong><\/h4>\n<p>Our first recommendation is to simply reach out to your clients to learn if they currently require or anticipate you will be required to accomplish either NIST 800-171 or CMMC compliance. Based on our experience, company contracting officers or program managers for a contract are great resources to learn about what they expect from their vendors and if they anticipate incorporating these compliance requirements as part of their contracts. You should also learn if the clients themselves have NIST 800-171 or CMMC requirements related to your contract with them. If they do, it is likely that your contract with the client will also have this language, as both NIST 800-171 and CMMC both feature flow-down requirements to be included in subcontracts.<\/p>\n<h4><strong>Look In Your Contract:<\/strong><\/h4>\n<p>If you\u2019re unsure or not comfortable reaching out to your clients to ask them about their compliance expectations, you can oftentimes find these requirements within your contract. By referring to Section H.27 (Facility, Personnel, and Systems Security Documentation), you\u2019ll find language indicating your potential compliance requirements and will want to keep an eye out for terms such as DFARS (7012), NIST, NIST 800-171, CMMC, and ITAR. In addition to this, you can also find additional compliance obligations by referring to your DD254 form which is an appendix within your contract.<\/p>\n<h4><strong>Additional Insights &amp; Considerations:<\/strong><\/h4>\n<p>Last but not least there are three insights, recommendations and considerations you should keep in mind as part of your compliance strategy to help determine if your organization will likely be required to address these compliance requirements and position itself for long-term success.<\/p>\n<p><strong>1. Consider NIST 800-171 &amp; CMMC as a competitive marketing advantage:<\/strong><\/p>\n<p>If you determine that the NIST 800-171 or CMMC are not an immediate requirement for your organization and are not included in any of your current contracts, then it may be a good idea to consider implementing them as a competitive marketing advantage. At TSI, we became CMMC Level-3 compliance ready to distinguish ourselves in the market and almost half of our NIST\/CMMC DoD clients are doing so for the same reason. Although they\u2019re not required to be compliant today, they choose to do so from a strategic marketing decision to improve their chances of success in an increasingly competitive market that if not today, will very soon require contractors to be compliant.<\/p>\n<p><strong>2. Be aware of the timeline to implement the NIST 800-171 &amp; CMMC frameworks:<\/strong><\/p>\n<p>In the worst-case scenario that your organization has done very little to nothing at all to become compliant today, it very well could take anywhere from\u00a012-18 months\u00a0to implement the technical and programmatic controls and solutions to accomplish compliance.<\/p>\n<p>For example, from a technical standpoint, of the 130+ NIST 800-171 &amp; CMMC controls, there are at least 25+ technical services or tools required to adequately address them with many of them requiring the expertise of an MSP or MSSP, to purchase and successfully implement them. Microsoft GCC High is one such frequently overlooked solution that will be required for organizations with CMMC + ITAR requirements and can only be purchased from 9 registered Microsoft GCC High Companies and implemented by a limited number of organizations nationally- TSI is one of them.<\/p>\n<p>Regarding the programmatic component of the CMMC, the policy development, supporting documentation, and process development for each of the 130+ CMMC controls was one of the primary areas of focus for our assessors and on average, we estimate it takes 120 hours to complete and generally requires a CISSP-level Security Engineer or CISO to complete an audit-ready Security and Compliance Program. Without experience in developing these programs, it will take significantly longer. In addition to this developing a Security and Compliance Program for CMMC 2.0 Level-2 requires that the program is managed and sustained over time. A complete program includes requisite policies, practices, procedures, strategic implementation plans, process development and resources to manage and sustain the program and its associated controls. Developing a program with this level of rigor, detail and congruence requires CISO level knowledge and experience. As our own assessment ended, we received excellent comments on our program including how it has made our assessor\u2019s job much easier!<\/p>\n<p><strong>3. Determine your IT provider\u2019s RPO status and CMMC readiness:<\/strong><\/p>\n<p>If you\u2019re currently working with an IT provider that isn\u2019t an\u00a0<a href=\"https:\/\/cmmcab.org\/rpo\/\" target=\"_blank\" rel=\"noopener\">CMMC-AB RPO<\/a>\u00a0today, it may benefit you to partner with one. A CMMC RPO is registered with the CMMC Accreditation Board and have undergone a background check to ensure they fulfill the basic requisites to provide NIST\/CMMC services to the DIB. In addition to this and even more importantly, in order for them to continue providing your organization with services- especially if those services or solutions address your compliance requirements- they will also need to adhere to the same level of NIST 800-171 and CMMC level that is required of yourself if they have (verified or unverified) access to your CUI. To ensure your organization is adequately prepared for an audit, you should speak to your IT provider as soon as possible to clarify if they meet these standards and if they\u2019ve undergone a 3rd\u00a0party audit of their systems attesting their ability to be CMMC certified ready when that time comes. Overlooking this critical detail could significantly impact your organization\u2019s NIST\/CMMC implementation process from both a time and financial standpoint.<\/p>\n<p>As a nation-wide partner to the DIB, we hope that our guidance here has helped clarify your compliance obligations so you can take the appropriate measures to improve your security posture and ensure that your organization is able to pursue and keep your DoD contracts.<\/p>\n<p>Feel free to check out TSI\u2019s <a href=\"https:\/\/tsisupport.com\/tsistaging\/cmmc-support\/\">NIST 800-171 &amp; CMMC Services Page<\/a> to learn how we can help support your organization\u2019s compliance objectives.<\/p>\n<div class=\"fl-builder-content fl-builder-content-12627 fl-builder-template fl-builder-row-template fl-builder-global-templates-locked\" data-post-id=\"12627\"><div class=\"fl-row fl-row-full-width fl-row-bg-photo fl-node-61277d5bc570d fl-row-default-height fl-row-align-center fl-row-bg-overlay sec-pad cta\" data-node=\"61277d5bc570d\">\n\t<div class=\"fl-row-content-wrap\">\n\t\t\t\t\t\t\t\t<div class=\"fl-row-content fl-row-fixed-width fl-node-content\">\n\t\t\n<div class=\"fl-col-group fl-node-61277d5bc5705\" data-node=\"61277d5bc5705\">\n\t\t\t<div class=\"fl-col fl-node-61277d5bc5709 fl-col-bg-color\" data-node=\"61277d5bc5709\">\n\t<div class=\"fl-col-content fl-node-content\"><div class=\"fl-module fl-module-heading fl-node-61277d5bc570a sec-title-big\" data-node=\"61277d5bc570a\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<h3 class=\"fl-heading\">\n\t\t<span class=\"fl-heading-text\">Get in Touch with TSI<\/span>\n\t<\/h3>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-rich-text fl-node-61277d5bc570b\" data-node=\"61277d5bc570b\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-rich-text\">\n\t<p>If you have any questions, please give us a call at <a href=\"tel:508-543-6979\">508-543-6979<\/a> or send us a message here to get started.<\/p>\n<\/div>\n\t<\/div>\n<\/div>\n<div class=\"fl-module fl-module-button fl-node-61277d5bc570c fl-animation fl-fade-down primary-btn red-btn\" data-node=\"61277d5bc570c\" data-animation-delay=\"0\" data-animation-duration=\"1\">\n\t<div class=\"fl-module-content fl-node-content\">\n\t\t<div class=\"fl-button-wrap fl-button-width-auto fl-button-center\">\n\t\t\t<a href=\"https:\/\/tsisupport.com\/tsistaging\/contact\/\"  target=\"_self\"  class=\"fl-button\" >\n\t\t\t\t\t\t\t<span class=\"fl-button-text\">get in touch<\/span>\n\t\t\t\t\t<\/a>\n<\/div>\n\t<\/div>\n<\/div>\n<style>.fl-node-61277d5bc570c.fl-animation:not(.fl-animated){opacity:0}<\/style><\/div>\n<\/div>\n\t<\/div>\n\t\t<\/div>\n\t<\/div>\n<\/div>\n<\/div><div class=\"uabb-js-breakpoint\" style=\"display: none;\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>One of the most frequently asked questions I receive is: \u201cHow do I know if I need to be compliant with either the NIST 800-171 or CMMC frameworks?\u201d The bottom line is that if you possess controlled unclassified information (CUI) then your organization will likely have to fulfill these compliance requirements- even if you are&hellip;<\/p>\n","protected":false},"author":7,"featured_media":13198,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[369],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Find CUI for NIST 800-171 &amp; CMMC Requirements | Security &amp; Compliance | TSI<\/title>\n<meta name=\"description\" content=\"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI&#039;s security and compliance guide to get the answers your organization needs.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Find CUI for NIST 800-171 &amp; CMMC Requirements | Security &amp; Compliance | TSI\" \/>\n<meta property=\"og:description\" content=\"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI&#039;s security and compliance guide to get the answers your organization needs.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tsisupport.com\/tsistaging\/?p=12611\" \/>\n<meta property=\"og:site_name\" content=\"TSI Support\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-23T05:25:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-01-27T04:26:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1140\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jeremy Louise\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeremy Louise\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611\",\"name\":\"How to Find CUI for NIST 800-171 & CMMC Requirements | Security & Compliance | TSI\",\"isPartOf\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage\"},\"image\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg\",\"datePublished\":\"2021-08-23T05:25:33+00:00\",\"dateModified\":\"2022-01-27T04:26:30+00:00\",\"author\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/48ad37aeeae9afb7d52479029f14f926\"},\"description\":\"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI's security and compliance guide to get the answers your organization needs.\",\"breadcrumb\":{\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/tsisupport.com\/tsistaging\/?p=12611\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg\",\"contentUrl\":\"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg\",\"width\":1140,\"height\":380,\"caption\":\"How to Find Your NIST 800-171 & CMMC Requirements\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/?p=12611#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/tsisupport.com\/tsistaging\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Find Your NIST 800-171 &#038; CMMC Requirements: A Comprehensive Guide to Determine Your Compliance Requirements from Your Primes &#038; Clients\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#website\",\"url\":\"https:\/\/tsisupport.com\/tsistaging\/\",\"name\":\"TSI Support\",\"description\":\"TSI - Technical Support International\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/48ad37aeeae9afb7d52479029f14f926\",\"name\":\"Jeremy Louise\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e2a1c4b01ee6c09554d8f086ff657b1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e2a1c4b01ee6c09554d8f086ff657b1a?s=96&d=mm&r=g\",\"caption\":\"Jeremy Louise\"},\"url\":\"https:\/\/tsisupport.com\/tsistaging\/?author=7\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Find CUI for NIST 800-171 & CMMC Requirements | Security & Compliance | TSI","description":"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI's security and compliance guide to get the answers your organization needs.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"How to Find CUI for NIST 800-171 & CMMC Requirements | Security & Compliance | TSI","og_description":"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI's security and compliance guide to get the answers your organization needs.","og_url":"https:\/\/tsisupport.com\/tsistaging\/?p=12611","og_site_name":"TSI Support","article_published_time":"2021-08-23T05:25:33+00:00","article_modified_time":"2022-01-27T04:26:30+00:00","og_image":[{"width":1140,"height":380,"url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg","type":"image\/jpeg"}],"author":"Jeremy Louise","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jeremy Louise","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611","url":"https:\/\/tsisupport.com\/tsistaging\/?p=12611","name":"How to Find CUI for NIST 800-171 & CMMC Requirements | Security & Compliance | TSI","isPartOf":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage"},"image":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage"},"thumbnailUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg","datePublished":"2021-08-23T05:25:33+00:00","dateModified":"2022-01-27T04:26:30+00:00","author":{"@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/48ad37aeeae9afb7d52479029f14f926"},"description":"Need to know whether you need to be CMMC or NIST 800-171 compliant? Read TSI's security and compliance guide to get the answers your organization needs.","breadcrumb":{"@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tsisupport.com\/tsistaging\/?p=12611"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611#primaryimage","url":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg","contentUrl":"https:\/\/tsisupport.com\/tsistaging\/wp-content\/uploads\/2021\/08\/How-to-Find-Your-NIST-800-171-CMMC-Requirements.jpg","width":1140,"height":380,"caption":"How to Find Your NIST 800-171 & CMMC Requirements"},{"@type":"BreadcrumbList","@id":"https:\/\/tsisupport.com\/tsistaging\/?p=12611#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/tsisupport.com\/tsistaging\/"},{"@type":"ListItem","position":2,"name":"How to Find Your NIST 800-171 &#038; CMMC Requirements: A Comprehensive Guide to Determine Your Compliance Requirements from Your Primes &#038; Clients"}]},{"@type":"WebSite","@id":"https:\/\/tsisupport.com\/tsistaging\/#website","url":"https:\/\/tsisupport.com\/tsistaging\/","name":"TSI Support","description":"TSI - Technical Support International","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/tsisupport.com\/tsistaging\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/48ad37aeeae9afb7d52479029f14f926","name":"Jeremy Louise","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tsisupport.com\/tsistaging\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e2a1c4b01ee6c09554d8f086ff657b1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e2a1c4b01ee6c09554d8f086ff657b1a?s=96&d=mm&r=g","caption":"Jeremy Louise"},"url":"https:\/\/tsisupport.com\/tsistaging\/?author=7"}]}},"_links":{"self":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/12611"}],"collection":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12611"}],"version-history":[{"count":0,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/posts\/12611\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=\/wp\/v2\/media\/13198"}],"wp:attachment":[{"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tsisupport.com\/tsistaging\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}