800-171 Evidence

September 30, 2026

What Are the 14 Control Families of 800-171 Rev 2?

You opened the 800-171 document and it reads like a phone book. This guide breaks the book into its 14 chapters. CUI is Controlled Unclassified Information: government data that is sensitive but not classified. NIST SP 800-171 Revision 2 is the rulebook for protecting CUI on nonfederal systems. (NIST SP 800-171 Rev. 2) Its requirements are grouped into 14 control families, numbered 3.1 through 3.14. Note: NIST withdrew Revision 2 in May 2024 and replaced it with Revision 3. (withdrawal record) CMMC still uses Revision 2 for Level 2 under the CMMC rule, 32 CFR Part 170. (eCFR) CMMC is the Cybersecurity Maturity Model Certification, the program that checks defense contractors.

The 14 families, in plain words

3.1 Access Control. Decide who can touch CUI and what they can do with it. Evidence: a list of authorized users with approval records.

3.2 Awareness and Training. Teach people to spot threats before they click. Evidence: training completion records with dates for every user.

3.3 Audit and Accountability. Keep records of who did what, and check them. Evidence: system logs of access events, reviewed on a schedule.

3.4 Configuration Management. Set a safe standard setup, and control changes to it. Evidence: approved baseline configurations plus change tickets with approvals.

3.5 Identification and Authentication. Prove each user is who they claim to be. Evidence: records showing multifactor authentication is on for CUI systems.

3.6 Incident Response. Have a plan for security incidents, and practice it. Evidence: a written incident response plan with test records.

3.7 Maintenance. Watch over repairs so they do not leak CUI. Evidence: maintenance logs showing what was done and who approved it.

3.8 Media Protection. Protect the drives, disks, and printouts that hold CUI. Evidence: a media inventory plus certificates of destruction.

3.9 Personnel Security. Screen people before access, and cut access when they leave. Evidence: screening records and same-day account termination logs.

3.10 Physical Protection. Lock the doors to rooms with CUI systems. Evidence: badge logs for the server room.

3.11 Risk Assessment. Look for weaknesses on purpose, then rank them. Evidence: a risk assessment report with prioritized findings.

3.12 Security Assessment. Check your own security on a schedule, and fix what you find. Evidence: periodic assessment reports with remediation plans.

3.13 System and Communications Protection. Guard CUI while it moves across networks. Evidence: a network diagram showing segmentation and encryption points.

3.14 System and Information Integrity. Find flaws fast and keep bad software out. Evidence: vulnerability scan reports with tracked fixes.

The family list matches NIST's own table of the 14 families. (NIST SP 800-171A)

How to organize evidence by family

Make 14 folders, one per family, named 3.1 through 3.14. Every requirement number starts with its family number, so filing is direct. The Level 2 set is commonly counted at 110 requirements, and each one lands in exactly one family folder. For a self-assessment, work folder by folder and note where evidence is thin.

Sources

Next step

Organizing evidence by family is easier when the evidence collects itself. PolicyCortex reads your live Azure configuration and checks it against NIST 800-171. It turns the results into SSP, SAR, and POA&M output. See what it can collect for you