NIST 800-171 policy templates: what each control family needs
NIST SP 800-171 has no requirement that simply says "write a policy", which confuses people. But the assessment objectives repeatedly ask whether something is defined, documented, or established, and that means written down somewhere.
Free preview before you pay. Editable Word files. 14 day refund.
Policy, plan, and POA&M do different jobs
- Policy says what the organization requires. It is stable and changes rarely.
- The System Security Plan says how it is done here today, on these systems.
- The POA&M says what is not done yet, who owns it, and by when.
Why an assessor wants all three
They compare them. A policy requiring something the plan says is not implemented is fine, as long as the POA&M records the gap. A policy requiring something the plan claims is implemented but the systems do not do is a finding.
This is also why copying a policy pack that marks everything as done is a bad trade. It removes the honest gap record that makes the rest credible.
The 14 families
- Access Control (AC). Who gets access to what, named accounts, least privilege, remote access, session lock.
- Awareness and Training (AT). Training at hire and annually, role specific training, insider threat awareness, and records.
- Audit and Accountability (AU). What is logged, traceability to a person, protection of logs, review cadence.
- Configuration Management (CM). Baselines, least functionality, change approval, software restrictions, inventory.
- Identification and Authentication (IA). Multifactor authentication, password rules, default credentials, identifier reuse.
- Incident Response (IR). The plan, who responds, testing, and the 72 hour DIBNet reporting deadline.
- Maintenance (MA). Controlled maintenance, vendor supervision, non local maintenance, sanitizing equipment sent out.
- Media Protection (MP). Marking CUI, sanitization before disposal, transport, removable media, backup protection.
- Personnel Security (PS). Screening before access, and access removal on termination or transfer.
- Physical Protection (PE). Limiting physical access, escorting visitors, access logs, controlling keys and badges.
- Risk Assessment (RA). Periodic risk assessment, vulnerability scanning, remediation by severity.
- Security Assessment (CA). Assessing the controls periodically, maintaining the plan, tracking deficiencies.
- System and Communications Protection (SC). Boundary protection, subnetwork separation, encryption in transit and at rest, FIPS validated cryptography.
- System and Information Integrity (SI). Flaw remediation, malicious code protection, monitoring, alerts.
The control people fail without realising
FIPS validated cryptography, 3.13.11, is commonly marked as met because encryption is switched on. The requirement is narrower: the cryptographic module itself must carry a current CMVP certificate, and on several platforms FIPS mode has to be explicitly enabled. Check the specific module against the NIST CMVP validated modules list rather than assuming.
Keep it to one manual
Fourteen separate policy files means fourteen documents to keep current, and in a small company that means none of them stay current. One manual with a section per family, one owner, and one review date is easier to maintain and just as easy for an assessor to follow.
Questions
Does NIST 800-171 require written policies?
Not in a single requirement, but the assessment objectives repeatedly ask whether things are defined or documented, which in practice means written policy for each family.
Is NIST 800-171 the same as CMMC Level 2?
CMMC Level 2 assesses the 110 requirements of NIST SP 800-171. CMMC adds the assessment and certification programme around them.
Rev. 2 or Rev. 3?
CMMC Level 2 and DFARS 252.204-7012 are tied to Rev. 2 with its 110 requirements. Check your contract, and do not assume a Rev. 3 document set applies to your obligation.
Can one person own all 14 families?
In a small contractor, usually yes, often alongside another job. Naming that person is the part that matters.
Full CMMC Level 2 Documentation Kit, $249
- System Security Plan, written around your answers, with your boundary and roles
- SPRS Score Worksheet showing your estimated score and every deduction
- Plan of Action and Milestones, already filled in with your gaps
- CUI Security Policy Manual covering all 14 NIST SP 800-171 control families
- START HERE guide with the deadlines that catch people out
More guides
Templates, not legal advice. Eaglizer IT is not a C3PAO, a Registered Provider Organization, or a law firm, and does not certify compliance with CMMC or NIST SP 800-171. Documentation is a prerequisite for an assessment, not a substitute for one.