NIST 800-171 Compliance
for SoCal DoD contractors.
NIST 800-171 compliance services for Southern California businesses handling Controlled Unclassified Information — DFARS 252.204-7012 readiness, SPRS scoring, SSP authorship, POA&M management, and implementation of all 110 security requirements across 14 control families. WCC has supported SoCal's defense supplier base since 2003.
NIST 800-171 — the control framework protecting CUI in nonfederal systems
NIST 800-171 is the National Institute of Standards and Technology framework for Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. It defines 110 security requirements organized into 14 control families. The framework has been required for DoD contractors since December 2017 via the DFARS 252.204-7012 clause — well before CMMC existed. NIST 800-171 compliance is the underlying obligation; CMMC is the certification mechanism layered on top.
For SoCal's defense supplier base — aerospace manufacturers, defense electronics firms, machine shops, engineering services companies, IT vendors, and universities with DoD research — the question is not whether NIST 800-171 applies. If you handle CUI under a DoD contract, the requirement attaches by clause. The question is what your current SPRS score actually is, what controls you can claim are fully implemented, and what evidence you can produce when a prime contractor or the DoD asks. Most SoCal businesses start an honest assessment somewhere between 30 and 70 against a possible 110 score.
This page covers WCC's NIST 800-171 services scope. For the related certification work, see the CMMC compliance page — CMMC Level 2 IS NIST 800-171 verified through third-party assessment. For executive leadership of the compliance program, see vCISO services. Start a conversation with a free IT consultation.
Where NIST 800-171 fits in the DoD compliance landscape
NIST 800-171 is one of three related NIST documents that govern DoD contractor cybersecurity. Understanding which applies to your contracts — and which you actually have to implement — matters before you start building toward compliance.
NIST SP 800-171
- Protects Controlled Unclassified Information (CUI)
- 110 security requirements across 14 control families
- Required for any DoD contractor handling CUI since 2017
- Self-assessment scored in SPRS (max 110)
- Rev 2 currently in DFARS contracting baseline
- Rev 3 finalized May 2024 — transition pending
CMMC 2.0
- DoD certification program verifying NIST 800-171 implementation
- Level 1: 17 practices, self-assessment, FCI only
- Level 2: 110 NIST 800-171 controls, third-party assessment
- Level 3: 110 plus 24 NIST 800-172 controls, DIBCAC audit
- Rolling out via DFARS 252.204-7021 through 2026-2027
- See the CMMC compliance page for details
NIST SP 800-172
- Enhanced security requirements for high-value CUI
- 24 additional controls on top of NIST 800-171's 110
- Applies only to CMMC Level 3 environments
- Addresses Advanced Persistent Threats (APT) specifically
- Required for select critical defense programs
- Most SoCal suppliers never reach this level
How WCC delivers NIST 800-171 compliance end-to-end
Four layers underneath every WCC engagement. Most compliance consultants stop at documentation. WCC owns the documentation AND the technical implementation AND the ongoing operations — one company, one accountable team.
Why choose WCC for NIST 800-171 compliance in Southern California
NIST 800-171 compliance is a multi-year program, not a project. The right partner has SoCal defense industry context, deep operational depth across the 14 control families, and a track record across the verticals you operate in.
Founded in SoCal
22+ years operating across SoCal's defense industrial base footprint — LA, Orange, Inland Empire, San Diego, and Ventura counties.
Defense supply chain experience
Aerospace, defense electronics, machine shops, engineering services, and DoD IT vendors — the exact verticals where DFARS clauses flow down.
CSLB Licensed
California Contractors State License Board #819788. C-7, C-10, and C-28 classifications. Real California regulatory accountability.
Integrated practice
Physical Protection (PE) is one of the 14 NIST 800-171 control families. WCC handles both the cyber controls and the physical security install.
End-to-end NIST 800-171 program management
Every WCC NIST 800-171 compliance engagement is scoped to current security maturity, contract timeline, and target SPRS score. These are the six core capability areas every engagement covers.
Gap Assessment & SPRS Scoring
Current-state assessment against all 110 NIST 800-171 controls. SPRS score calculation following DoD scoring methodology — 5-point and 3-point control weights. Prioritized remediation roadmap with cost estimates and contract-aligned milestones.
SSP Authorship
System Security Plan (SSP) authored in DoD-acceptable format. Defines the assessment boundary, identifies CUI flows, documents control implementation status, and forms the central document a C3PAO or DCMA auditor will review.
POA&M Management
Plan of Action and Milestones for controls not yet fully implemented. Realistic remediation timelines, owner assignments, and evidence-of-closure documentation. POA&M items closed against documented implementation evidence, not just dates.
Control Implementation
Hands-on technical implementation across all 14 control families — MFA, FIPS-validated encryption, network segmentation, audit logging, vulnerability management, configuration baselines, and the GCC High or Azure Government tenancy required for CUI handling.
SPRS Score Improvement
Structured work toward your target SPRS score. Most SoCal businesses start in the 30-70 range. Each closed gap moves the score. WCC builds the implementation plan around the SPRS scoring methodology to maximize the score per dollar invested.
Ongoing Compliance Maintenance
Annual SPRS refresh. Quarterly control monitoring. Continuous evidence collection. Rev 3 transition planning. Often combined with vCISO services for designated cybersecurity leadership.
NIST 800-171 organizes 110 controls into 14 control families
Every NIST 800-171 control maps to one of 14 control families defined by NIST SP 800-171. WCC's practice covers every control family — both technical implementation and ongoing operational maintenance.
Access Control
User access policies, role-based access, separation of duties, least privilege.
22 controlsAwareness & Training
Security awareness, role-based training, insider threat education.
3 controlsAudit & Accountability
Audit logging, log review, log retention, system audit reporting.
9 controlsConfiguration Mgmt
Baseline configurations, change control, configuration enforcement.
9 controlsIdentification & Auth
User identification, MFA, password complexity, replay-resistant authentication.
11 controlsIncident Response
IR plan, IR testing, incident reporting, post-incident analysis.
3 controlsMaintenance
System maintenance procedures, personnel screening for maintainers.
6 controlsMedia Protection
Media marking, sanitization, removable media controls.
9 controlsPersonnel Security
Background screening, personnel termination procedures.
2 controlsPhysical Protection
Physical access control, visitor logs, equipment protection.
6 controlsRisk Assessment
Risk assessment program, vulnerability scanning, risk treatment.
3 controlsSecurity Assessment
Security plan, control assessment, system monitoring program.
4 controlsSystem & Comms Protection
Boundary protection, cryptographic protection, network segmentation.
16 controlsSystem & Info Integrity
Flaw remediation, malicious code protection, monitoring tools.
7 controlsNIST 800-171 across SoCal's defense supply chain
NIST 800-171 applies to any business handling Controlled Unclassified Information through a DoD contract or subcontract — prime contractors, Tier-2 and Tier-3 suppliers, and the IT and engineering services firms supporting them.
Aerospace Manufacturers
Aerospace primes and tiered suppliers across SoCal — Long Beach, Huntington Beach, Hawthorne, El Segundo, Redondo Beach, Palmdale, San Diego. Drawings, technical data, and program-specific information typically meet CUI definitions, triggering NIST 800-171 requirements via DFARS flowdowns.
Defense Electronics & Components
RF systems, sensors, embedded systems, defense electronics, and semiconductor suppliers serving DoD prime contractors. Most engagements include ITAR concurrent with NIST 800-171 obligations — export-controlled technical data is also CUI.
Machine Shops & Precision Manufacturing
Precision machining, CNC fabrication, additive manufacturing, and metal finishing shops feeding aerospace and defense primes across the Inland Empire and South Bay. Often the lowest tier where DFARS clauses still flow down with full NIST 800-171 obligations.
Engineering Services Firms
Mechanical, electrical, software, and systems engineering firms providing services to DoD prime contractors. Engineering services typically involve CUI by definition — technical data, design documentation, performance specifications — making full implementation the default scope.
IT & Cybersecurity Vendors to DoD
Cloud service providers, MSPs, cybersecurity firms, and software vendors serving DoD customers. Cloud Service Providers handling CUI must meet FedRAMP Moderate or High plus NIST 800-171. Manufacturing MSPs often have the requirement themselves.
Universities & Research Institutions
SoCal universities with DoD-funded research — USC, UCLA, Caltech, UCSD, UCI, UCR — face NIST 800-171 obligations on contracts and grants involving CUI. Research security offices coordinate institution-wide programs, often paired with NSPM-33 research security compliance.
NIST 800-171 frequently asked questions
NIST Special Publication 800-171 is the National Institute of Standards and Technology framework for Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations. It defines 110 security requirements organized into 14 control families — Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Required by DFARS 252.204-7012 for any DoD contractor handling CUI.
Any Department of Defense contractor or subcontractor that processes, stores, or transmits Controlled Unclassified Information must comply. The requirement is triggered by the DFARS 252.204-7012 clause, which has been in DoD contracts since December 2017. The clause flows down to subcontractors at all tiers. Beyond DoD, several federal agencies (NASA, GSA, DHS) and increasingly some commercial primes flow down NIST 800-171 to suppliers. SoCal manufacturers, aerospace suppliers, engineering services firms, and IT vendors serving DoD all typically have this requirement.
NIST 800-171 is the underlying control framework — 110 security requirements and 14 control families. CMMC (Cybersecurity Maturity Model Certification) is the DoD verification mechanism that audits whether contractors actually implement NIST 800-171. CMMC Level 2 IS NIST 800-171, verified through third-party assessment. CMMC Level 3 adds 24 controls from NIST 800-172 for highest-risk environments. NIST 800-171 has been required since DFARS 252.204-7012 took effect in 2017. CMMC adds certification rigor on top of the existing requirement. The control implementation work is the same regardless of which verification path applies.
SPRS (Supplier Performance Risk System) is the DoD-mandated scoring system for NIST 800-171 self-assessment. Contractors calculate a score starting at 110 and subtract points for each control not fully implemented — most controls deduct 5 points if missing, certain critical controls deduct 5 points and others deduct 3 points based on subtractive weighting. Perfect score is 110. Scores can go negative. DFARS 252.204-7019 and 7020 require contractors to post current SPRS scores before DoD contract award. Most SoCal defense suppliers start in the 30-70 range and work toward 110 over a 6-18 month implementation period.
NIST 800-171 Revision 3 was finalized by NIST in May 2024. Rev 3 restructured the 110 controls and updated several requirements to align with NIST 800-53 Rev 5. The DFARS contracting clause still references Rev 2 as of mid-2026, so most active DoD compliance work continues under Rev 2. When DFARS updates to require Rev 3 (timing not yet announced), contractors will have a transition window. WCC's practice tracks both Rev 2 (current contracting baseline) and Rev 3 (future state) so transition planning is built in from day one.
The 14 control families are Access Control (22 controls), Awareness and Training (3), Audit and Accountability (9), Configuration Management (9), Identification and Authentication (11), Incident Response (3), Maintenance (6), Media Protection (9), Personnel Security (2), Physical Protection (6), Risk Assessment (3), Security Assessment (4), System and Communications Protection (16), and System and Information Integrity (7). Total: 110 controls. Each control has assessment objectives in NIST 800-171A — multiple objectives per control. CMMC Level 2 assessment evaluates all 320+ assessment objectives derived from the 110 controls.
NIST 800-53 is the comprehensive control catalog used by federal agencies for internal systems — over 1000 controls across 20 families with multiple baselines (Low, Moderate, High). NIST 800-171 is the subset applicable to nonfederal organizations handling CUI — 110 controls derived from the moderate baseline of NIST 800-53. NIST 800-171 is meant to be implementable by contractors and suppliers, while NIST 800-53 is meant for federal agencies with dedicated security programs. Both reference the same underlying control concepts; NIST 800-171 is the contractor-facing version.
NIST 800-171 compliance preparation involves four phases. Phase 1: gap assessment against all 110 controls, current SPRS score calculation. Phase 2: SSP (System Security Plan) authorship documenting how each control is implemented or planned. Phase 3: POA&M (Plan of Action and Milestones) for controls not yet implemented with remediation timelines. Phase 4: control implementation work including MFA, encryption, audit logging, network segmentation, incident response procedures, and security training. Implementation typically runs 6 to 18 months. Ongoing maintenance includes annual SPRS refresh, control monitoring, and evidence collection — often combined with vCISO services for designated leadership.
NIST 800-171 work pairs with these WCC capabilities
NIST 800-171 implementation touches almost every cybersecurity service WCC offers. The services below are commonly bundled with NIST 800-171 engagements for SoCal defense contractors.
CMMC Compliance
The certification mechanism that verifies NIST 800-171 implementation — Level 2 IS NIST 800-171, third-party audited.
vCISO Services
Fractional CISO leadership for ongoing NIST 800-171 program management, SPRS oversight, and executive reporting.
Penetration Testing
Evidence for CA, SI, and SC control families — external and internal testing as part of the security assessment program.
Vulnerability Assessment
Required by RA-5 — ongoing vulnerability scanning, prioritization, and remediation tracking for compliance evidence.
Security Awareness Training
Required by the AT control family — annual training, phishing simulations, role-based modules with completion tracking.
Incident Response
IR plan, IR testing, and 72-hour DoD breach reporting capability — required by the IR control family.
Managed SOC
24/7 SOC monitoring — required for AU and SI controls. Logs, alerts, investigation, and the operational discipline behind compliance.
Cybersecurity Hub
The full cybersecurity services overview — assessments, operations, and compliance across SoCal businesses.
NIST 800-171 services across Southern California
WCC delivers NIST 800-171 work across all six SoCal counties — with deepest experience in the aerospace and defense corridors. Headquartered in Chino.
NIST 800-171 work starts with an honest gap assessment.
Tell us your contract pipeline, your current SPRS score (or what you think it might be), and your target compliance milestone. WCC will scope the gap assessment, SSP authorship, POA&M work, and control implementation — all on one fixed engagement plan. SoCal's defense supplier base deserves a NIST 800-171 partner who actually understands the operational stack underneath.
