800-171 Evidence

September 30, 2026

What the DMDC Breach Teaches Contractors About 800-171

Your file servers hold the same kind of personal data the Pentagon just lost.

On September 18, the Defense Manpower Data Center (DMDC) began notifying over 3 million people of a data breach. DMDC is the agency that keeps personnel records for the Defense Department. Unauthorized users reached a file sharing system from October 2025 until discovery on July 16, 2026 (SecurityWeek).

The files held unencrypted personally identifiable information (PII), including Social Security numbers plus at least one more identifier per person. The breach touched 2.76 million living people and 294,000 deceased former personnel or their dependents. That count comes from a Defense Department official (teiss).

This article answers one question: which 800-171 requirements would have stopped this? It also tells you what to do this week.

Which requirement covers the unencrypted data?

Requirement 3.13.11 of NIST SP 800-171 Revision 2 covers encryption for controlled unclassified information (CUI). It requires validated cryptography, not just any encryption (NIST SP 800-171 Rev. 2). The breached files held Social Security numbers in plain form, which is the exact failure this requirement exists to prevent.

For your own systems: encrypt data at rest wherever CUI or PII sits, and keep a dated scan as proof. An assessor wants to see the scan, not a promise.

Which requirement covers nine months of undetected access?

Requirement 3.6.1 says to build an incident handling capability that includes detection and analysis. Requirement 3.3.1 says to create and keep audit records that support monitoring and investigation (NIST SP 800-171 Rev. 2).

Nine months of quiet access means the monitoring side of these two requirements was missing. Logging without review is decoration.

For your own systems: review access logs for sensitive shares weekly. Keep the records for at least one year. One named person should own that review.

Which requirement covers the vulnerable file sharing system?

Requirement 3.14.1 says to identify, report, and correct information system flaws in a timely manner (NIST SP 800-171 Rev. 2). DMDC patched the flaw the day it was found, which is the right response after discovery.

The gap was the months before discovery, when the flaw sat unpatched and unnoticed. Timely correction starts with timely finding.

For your own systems: run a vulnerability scan each month and fix critical findings within 30 days. Record each scan date and each fix date.

What would a contractor owe if this were their system?

DFARS is the Defense Department's contract rulebook. DFARS clause 252.204-7012 requires contractors to implement NIST SP 800-171 where they handle covered defense information (DFARS 252.204-7012 full text). It also requires reporting a cyber incident to the Defense Department within 72 hours of discovery.

DMDC notified individuals about two months after finding the flaw. A contractor on the same timeline would miss the 72-hour clock by weeks.

For your own systems: write down who reports, what they report, and the deadline they follow, before an incident happens. Tape that page inside your incident response plan.

Sources

Next step

A dated encryption scan and a weekly log review would have caught both failure patterns. See how PolicyCortex maps your Azure evidence to 800-171 automatically.