Back to Knowledge Center
The Framework10 min read
The 14 NIST SP 800-171 Control Domains
CMMC Level 2's 110 controls are organized into 14 domains. Each domain covers a distinct area of cybersecurity — from access control to system integrity.
NIST SP 800-171 Revision 2 organizes its 110 security requirements into 14 families (domains). CMMC Level 2 maps directly to these 14 families. Understanding what each domain covers helps prioritize remediation and anticipate where assessment findings are most likely.
| Domain | Controls | What it covers |
|---|---|---|
| Access Control (AC) | 22 | Who can access systems and data, and under what conditions — including remote access, mobile devices, and least-privilege enforcement |
| Awareness & Training (AT) | 3 | Security awareness for all users; role-based training for system administrators and CUI handlers |
| Audit & Accountability (AU) | 9 | Logging of system events, protecting audit logs, reviewing logs for anomalous activity |
| Configuration Management (CM) | 9 | Baseline configurations, change control processes, restricting unauthorized software installation |
| Identification & Authentication (IA) | 11 | Multi-factor authentication, password policies, authenticator management, device authentication |
| Incident Response (IR) | 3 | Incident response planning, capability, and reporting to DoD within 72 hours |
| Maintenance (MA) | 6 | Sanitizing maintenance tools, controlling remote maintenance, media sanitization before use |
| Media Protection (MP) | 9 | Restricting access to CUI on media, sanitizing media before disposal, encrypting portable media |
| Personnel Security (PS) | 2 | Screening individuals before access; protecting CUI during and after personnel actions |
| Physical Protection (PE) | 6 | Controlling physical access to systems, monitoring facilities, escort requirements |
| Risk Assessment (RA) | 3 | Periodic risk assessments, vulnerability scanning, remediation based on risk prioritization |
| Security Assessment (CA) | 4 | Assessing security controls periodically, maintaining the SSP, developing and tracking the POA&M |
| System & Comm. Protection (SC) | 16 | Network segmentation, boundary protection, encryption of CUI in transit, DNS filtering |
| System & Info. Integrity (SI) | 7 | Malware protection, patching, security alerts, spam filtering, system monitoring |
Which domains generate the most findings?
- ✓Access Control (AC): particularly around multi-factor authentication, least privilege, and remote access controls
- ✓Configuration Management (CM): especially around baseline configuration documentation and unauthorized software controls
- ✓Audit & Accountability (AU): organizations frequently have logging gaps or no formal log review process
- ✓System & Communications Protection (SC): encryption of CUI at rest and in transit, network segmentation deficiencies
A thorough gap assessment will score each of the 110 controls and produce a weighted SPRS score with a domain-by-domain breakdown.
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in The Framework
