Access control & authentication
Limit system access to authorized users and devices, and verify identities with strong, multi-factor authentication.
Frameworks · Government & supply chain
The bar for handling sensitive government information, and for doing business in its supply chain.
NIST Special Publication 800-171 is a U.S. standard for protecting Controlled Unclassified Information, the sensitive but unclassified government information that lives on the systems of non-government organizations. If a contractor, supplier, or research partner handles this kind of information, 800-171 defines the security requirements they must meet.
CMMC, the Cybersecurity Maturity Model Certification, is the U.S. Department of Defense’s program for verifying that its contractors actually meet those requirements. Where 800-171 has historically relied on self-attestation, CMMC adds tiered certification, including independent third-party assessment at higher levels, so the DoD can trust that its supply chain is protected before awarding work.
For Canadian organizations, this matters whenever they sit in a U.S. federal or defense supply chain, as a subcontractor, supplier, or research collaborator, where these requirements flow down through contracts.
NIST 800-171 organizes its requirements into control families covering the familiar pillars of security: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Compliance is measured against these requirements and documented in a System Security Plan with a Plan of Action and Milestones for any gaps.
CMMC 2.0 wraps this in a tiered model. Level 1 (Foundational) covers basic safeguarding of less-sensitive information. Level 2 (Advanced) aligns with the full set of 800-171 requirements and, for many contracts, requires assessment by an accredited third party. Level 3 (Expert) adds further requirements for the most sensitive programs. The control families below summarize the 800-171 backbone shared across these levels.
Limit system access to authorized users and devices, and verify identities with strong, multi-factor authentication.
Ensure personnel are aware of security risks and trained in their responsibilities.
Establish secure baselines, manage changes, and protect systems against malware and flaws through timely updates.
Create, protect, and review logs so actions can be traced to individuals and incidents investigated.
Detect, report, and respond to incidents, and maintain the ability to recover affected systems and data.
Protect information on media and limit physical access to systems that store or process sensitive information.
These requirements apply to organizations that handle Controlled Unclassified Information for the U.S. government: defense contractors and their subcontractors, suppliers, manufacturers, and research institutions anywhere in the supply chain, including Canadian firms that participate in it.
The driver is contractual. The requirement to meet 800-171, and increasingly to hold the appropriate CMMC level, flows down from the prime contract to every supplier that touches the protected information. If you want to win or keep that work, compliance is a prerequisite, not an option.
For organizations with no U.S. government or defense business, 800-171 is not a requirement, though its control families are a rigorous reference. Outside this supply chain, a foundational framework like NIST CSF or the CIS Controls is the more proportionate choice.
800-171 is derived from the broader NIST control catalogue (SP 800-53) and shares its DNA with NIST CSF and the CIS Controls: the same access control, configuration, logging, and incident-response ideas, specified more precisely and made mandatory for this context. A mature CIS- or NIST-based program covers much of the ground 800-171 demands.
CMMC is the assurance layer on top. Where ISO 27001 and SOC 2 provide independent assurance for commercial markets, CMMC provides it for the U.S. defense supply chain. The difference is who requires it and how it is verified, not a wholly different idea of security.
NIST SP 800-171 / CMMC is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 5 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Know your obligation
—Access & authentication
—Configuration & integrity
—Audit & monitoring
—Incident response & media
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: NIST SP 800-171 (csrc.nist.gov) & CMMC
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.