CMMC Ready Now
Back to Knowledge Center
The Framework10 min read

The 14 NIST SP 800-171 Control Domains

CMMC Level 2's 110 controls are organized into 14 domains. Each domain covers a distinct area of cybersecurity — from access control to system integrity.

NIST SP 800-171 Revision 2 organizes its 110 security requirements into 14 families (domains). CMMC Level 2 maps directly to these 14 families. Understanding what each domain covers helps prioritize remediation and anticipate where assessment findings are most likely.

DomainControlsWhat it covers
Access Control (AC)22Who can access systems and data, and under what conditions — including remote access, mobile devices, and least-privilege enforcement
Awareness & Training (AT)3Security awareness for all users; role-based training for system administrators and CUI handlers
Audit & Accountability (AU)9Logging of system events, protecting audit logs, reviewing logs for anomalous activity
Configuration Management (CM)9Baseline configurations, change control processes, restricting unauthorized software installation
Identification & Authentication (IA)11Multi-factor authentication, password policies, authenticator management, device authentication
Incident Response (IR)3Incident response planning, capability, and reporting to DoD within 72 hours
Maintenance (MA)6Sanitizing maintenance tools, controlling remote maintenance, media sanitization before use
Media Protection (MP)9Restricting access to CUI on media, sanitizing media before disposal, encrypting portable media
Personnel Security (PS)2Screening individuals before access; protecting CUI during and after personnel actions
Physical Protection (PE)6Controlling physical access to systems, monitoring facilities, escort requirements
Risk Assessment (RA)3Periodic risk assessments, vulnerability scanning, remediation based on risk prioritization
Security Assessment (CA)4Assessing security controls periodically, maintaining the SSP, developing and tracking the POA&M
System & Comm. Protection (SC)16Network segmentation, boundary protection, encryption of CUI in transit, DNS filtering
System & Info. Integrity (SI)7Malware protection, patching, security alerts, spam filtering, system monitoring

Which domains generate the most findings?

  • Access Control (AC): particularly around multi-factor authentication, least privilege, and remote access controls
  • Configuration Management (CM): especially around baseline configuration documentation and unauthorized software controls
  • Audit & Accountability (AU): organizations frequently have logging gaps or no formal log review process
  • System & Communications Protection (SC): encryption of CUI at rest and in transit, network segmentation deficiencies

A thorough gap assessment will score each of the 110 controls and produce a weighted SPRS score with a domain-by-domain breakdown.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.