How to Map CMMC / NIST 800-171 Status (Without Theater)
Quick answer: Status mapping means one living register of every applicable NIST SP 800-171 requirement with an honest status (satisfied / partial / not), an owner, evidence type, scoring weight, and next action—not a spreadsheet of wishful thinking. Use the official requirement list from NIST (or the Pro Template Pack’s enumerated reference); this page teaches the method, not a substitute for the control text.
Key takeaways
- Freeze scope (enclave, users, CUI paths) before you mark a single control.
- Use three statuses only: Satisfied, Partially satisfied, Not satisfied—plus notes, never a silent fourth fantasy state.
- Every Satisfied mark needs an evidence type and a human who can defend it.
- Weights (1/3/5) belong on the register so gap work hits high-impact rows first.
- DIY register → Pack for full templates → paid Gap when you need an independent 110-control report.
Why ops managers get stuck
Most teams either (a) copy last year’s SPRS number or (b) open a blank SSP and freeze. Operations needs a third path: a status register that leadership can interrogate without theater.
This page is that method. It does not replace:
- The official NIST SP 800-171 requirement text
- Your contracts and flow-downs (contract checklist)
- A paid Gap Analysis when you need independent challenge
Need the list to fill the rows? Use the free NIST publication, the interactive Defensibility Check for optimism patterns, or the full enumerated reference in the Pro Template Pack.
Step 0 — Freeze scope before status
If scope is fuzzy, every “Satisfied” is provisional.
Document (no CUI required on this site—keep details offline):
| Scope element | What to capture |
|---|---|
| Boundary | Systems, networks, locations in the assessment enclave |
| Users | Roles with access to in-scope systems |
| CUI / CDI paths | How protected info enters, lives, leaves (email, share, OEM portal, etc.) |
| Shared services | MSP, cloud, identity, backup—what you own vs they own (matrix) |
| Baseline | Rev 2 vs Rev 3 applicability for your assessment path |
Until this exists, mark aggressive “green” only with leadership’s eyes open.
The register — required columns
Download a blank starter: cmmc-status-register-template.csv (headers only—no control text).
| Column | Purpose |
|---|---|
| control_id | e.g. 3.1.1 (from NIST / Pack) |
| family | Access Control, etc. (rollup reporting) |
| requirement_summary | Short plain-language restatement (optional if full text is linked offline) |
| status | satisfied | partial | not |
| confidence | high / medium / low (how sure is the scorer?) |
| owner | Named human (not “IT”) |
| evidence_type | policy, config, ticket, log, screenshot, contract, training record, other |
| evidence_location | Path/ticket ID in your system—not pasted CUI here |
| weight | 1, 3, or 5 per official scoring methodology you use |
| poam_eligible | yes / no / unknown under current rules |
| residual_risk | one-line business risk if still open |
| next_action | concrete next step |
| due_date | ISO date |
| last_reviewed | ISO date |
| notes | caveats, MSP dependency, multi-site issues |
Status definitions (be ruthless)
| Status | Means | Does not mean |
|---|---|---|
| Satisfied | Fully implemented and you can show evidence | “We bought a tool” / “policy exists somewhere” |
| Partial | Real progress, incomplete coverage, or weak evidence | “Scheduled for Q4” with no work done |
| Not | Missing, unknown, or out of scope wrongly assumed in | Shame—unknowns should be Not until proven |
How to run a mapping sprint (1–2 weeks)
- Skeleton — all control IDs into the sheet (from NIST or Pack).
- Owner pass — assign owners by family; no orphans.
- Honest first pass — force a status on every row; ban blank.
- Evidence pass — for each Satisfied, attach evidence type + location. Downgrade if empty.
- Weight pass — apply 1/3/5; sort open/partial by weight × residual risk.
- Challenge pass — someone other than the original scorer samples high-weight Satisfied rows (FCA / signature risk).
- Score last — only after the register stabilizes (how to calculate SPRS).
Multi-site and multi-enclave
If you have more than one boundary, do not merge fantasies:
- One register per assessment boundary, or
- One register with a
boundary_idcolumn and filters
MSP-run tools still need your owner and your evidence story.
DIY vs done-with-you
| Need | Path |
|---|---|
| Method + free triage | This page + tool + workbook |
| Editable 110 reference + scoring workbook | Pro Template Pack ($199) |
| Independent 110-control gap report | Gap Analysis SKU |
| Gap + SSP/POA&M package structure | Readiness Package |
| Keep SSP/POA&M alive yearly | Annual Maintenance |
What “done” looks like for ops
You can answer in a 15-minute leadership meeting:
- How many Satisfied / Partial / Not?
- Top 10 open items by weight?
- Who owns each top item and when is the next artifact due?
- Would we sign a SPRS score this week—yes/no, with residual risk?
If any answer is hand-wavy, the map is not done.
Next steps
- Download the CSV register template
- Pull requirement IDs from NIST SP 800-171 or the Pro Pack
- Run the free Defensibility Check for optimism patterns
- Proceed to the gap analysis process and remediation roadmap
Frequently asked questions
Do I need all 110 rows on day one?
If Level 2 / 800-171 CUI obligations apply, yes—eventually. Start with a complete skeleton (all control IDs) and honest unknowns marked Not or Partial. Blank rows that hide gaps are worse than red rows you can fix.
Can I use this site as my control database?
No. DefensibleScore does not store CUI or your control evidence. Keep the register in your protected environment (or Pro Pack files). We teach the method and sell readiness help—we do not host your SSP.
Where do I get the official 110 requirements list?
Free from NIST SP 800-171. For a working editable reference plus scoring sheet, use the Pro Template Pack. We deliberately do not republish the full enumerated list on free pages.
How is this different from a SPRS score?
The register is the work product. The SPRS score is arithmetic over fully implemented controls. Map status first; score second. Inflated status produces indefensible scores.
What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).