Guide

How to Map CMMC / NIST 800-171 Status (Without Theater)

Last verified: First published:

Quick answer: Status mapping means one living register of every applicable NIST SP 800-171 requirement with an honest status (satisfied / partial / not), an owner, evidence type, scoring weight, and next action—not a spreadsheet of wishful thinking. Use the official requirement list from NIST (or the Pro Template Pack’s enumerated reference); this page teaches the method, not a substitute for the control text.

Key takeaways

  • Freeze scope (enclave, users, CUI paths) before you mark a single control.
  • Use three statuses only: Satisfied, Partially satisfied, Not satisfied—plus notes, never a silent fourth fantasy state.
  • Every Satisfied mark needs an evidence type and a human who can defend it.
  • Weights (1/3/5) belong on the register so gap work hits high-impact rows first.
  • DIY register → Pack for full templates → paid Gap when you need an independent 110-control report.

Why ops managers get stuck

Most teams either (a) copy last year’s SPRS number or (b) open a blank SSP and freeze. Operations needs a third path: a status register that leadership can interrogate without theater.

This page is that method. It does not replace:

Need the list to fill the rows? Use the free NIST publication, the interactive Defensibility Check for optimism patterns, or the full enumerated reference in the Pro Template Pack.

Step 0 — Freeze scope before status

If scope is fuzzy, every “Satisfied” is provisional.

Document (no CUI required on this site—keep details offline):

Scope element What to capture
Boundary Systems, networks, locations in the assessment enclave
Users Roles with access to in-scope systems
CUI / CDI paths How protected info enters, lives, leaves (email, share, OEM portal, etc.)
Shared services MSP, cloud, identity, backup—what you own vs they own (matrix)
Baseline Rev 2 vs Rev 3 applicability for your assessment path

Until this exists, mark aggressive “green” only with leadership’s eyes open.

The register — required columns

Download a blank starter: cmmc-status-register-template.csv (headers only—no control text).

Column Purpose
control_id e.g. 3.1.1 (from NIST / Pack)
family Access Control, etc. (rollup reporting)
requirement_summary Short plain-language restatement (optional if full text is linked offline)
status satisfied | partial | not
confidence high / medium / low (how sure is the scorer?)
owner Named human (not “IT”)
evidence_type policy, config, ticket, log, screenshot, contract, training record, other
evidence_location Path/ticket ID in your system—not pasted CUI here
weight 1, 3, or 5 per official scoring methodology you use
poam_eligible yes / no / unknown under current rules
residual_risk one-line business risk if still open
next_action concrete next step
due_date ISO date
last_reviewed ISO date
notes caveats, MSP dependency, multi-site issues

Status definitions (be ruthless)

Status Means Does not mean
Satisfied Fully implemented and you can show evidence “We bought a tool” / “policy exists somewhere”
Partial Real progress, incomplete coverage, or weak evidence “Scheduled for Q4” with no work done
Not Missing, unknown, or out of scope wrongly assumed in Shame—unknowns should be Not until proven

How to run a mapping sprint (1–2 weeks)

  1. Skeleton — all control IDs into the sheet (from NIST or Pack).
  2. Owner pass — assign owners by family; no orphans.
  3. Honest first pass — force a status on every row; ban blank.
  4. Evidence pass — for each Satisfied, attach evidence type + location. Downgrade if empty.
  5. Weight pass — apply 1/3/5; sort open/partial by weight × residual risk.
  6. Challenge pass — someone other than the original scorer samples high-weight Satisfied rows (FCA / signature risk).
  7. Score last — only after the register stabilizes (how to calculate SPRS).

Multi-site and multi-enclave

If you have more than one boundary, do not merge fantasies:

  • One register per assessment boundary, or
  • One register with a boundary_id column and filters

MSP-run tools still need your owner and your evidence story.

DIY vs done-with-you

Need Path
Method + free triage This page + tool + workbook
Editable 110 reference + scoring workbook Pro Template Pack ($199)
Independent 110-control gap report Gap Analysis SKU
Gap + SSP/POA&M package structure Readiness Package
Keep SSP/POA&M alive yearly Annual Maintenance

What “done” looks like for ops

You can answer in a 15-minute leadership meeting:

  1. How many Satisfied / Partial / Not?
  2. Top 10 open items by weight?
  3. Who owns each top item and when is the next artifact due?
  4. Would we sign a SPRS score this week—yes/no, with residual risk?

If any answer is hand-wavy, the map is not done.

Next steps

  1. Download the CSV register template
  2. Pull requirement IDs from NIST SP 800-171 or the Pro Pack
  3. Run the free Defensibility Check for optimism patterns
  4. Proceed to the gap analysis process and remediation roadmap

Frequently asked questions

Do I need all 110 rows on day one?

If Level 2 / 800-171 CUI obligations apply, yes—eventually. Start with a complete skeleton (all control IDs) and honest unknowns marked Not or Partial. Blank rows that hide gaps are worse than red rows you can fix.

Can I use this site as my control database?

No. DefensibleScore does not store CUI or your control evidence. Keep the register in your protected environment (or Pro Pack files). We teach the method and sell readiness help—we do not host your SSP.

Where do I get the official 110 requirements list?

Free from NIST SP 800-171. For a working editable reference plus scoring sheet, use the Pro Template Pack. We deliberately do not republish the full enumerated list on free pages.

How is this different from a SPRS score?

The register is the work product. The SPRS score is arithmetic over fully implemented controls. Map status first; score second. Inflated status produces indefensible scores.

What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).