image

i2ACT NIST 800-171 | CMMC Level 2 Software

The i2ACT NIST 800-171 | CMMC Level 2 product provides tools to assist in assessing compliance with the NIST 800-171r1 requirements as specified in the DFARS Subparts 204.73 and 239.76 and contains all 110 requirements and the 125 referenced controls from NIST 800-53r4. In addition to the 14 Domains in CMMC Level 1, the Level 2 Software includes the following enhancements for CMMC Level 2.

This software was created to provide an Advanced Cybersecurity Platform for any organization that handles CUI, which requires a higher level of security than an organization with only FCI. The i2ACT Level 2 software includes enhanced functionality which allows for multiple remediation tasks per practice to be defined in the assessment process thereby enhancing the detail in the POA&M produced directly from the tool. The tool also allows for multiple evidentiary artifacts for each practice/requirement and, in turn, each evidentiary artifact can be associated with multiple practices/requirements. If the company desires, the i2ACT tool supports the evaluation of the 800-53 NFO controls referenced by the 800-171r2 standard.

Key Points about CMMC Level 2:

  • Alignment: CMMC Level 2 is directly aligned with the 125 NIST SP 800-171 referenced controls, meaning all 110 requirements must be implemented to achieve Level 2 compliance.
  • Third-Party Assessment: Unlike self-assessments in CMMC Level 1 and NIST 800-171, CMMC Level 2 will require most organizations to have a third-party assessment by a CMMC Certified Third Party Assessor Organization (C3PAO) to verify compliance every 3 years. Documented annual self-assessments will be required.
  • Focuses on CUI Protection: The primary goal of CMMC Level 2 is to ensure robust protection of CUI handled by DoD contractors and their supply chains.

The i2ACT Assessment and Compliance Tool

Establishing Baselines for CMMC Level 2

A baseline is the set of controls you choose for the security standard or configuration you want to meet and fully implement. The i2ACT CMMC Level 2 software tool allows you to toggle back and forth between NIST 800-171 and CMMC since the 2 are aligned. Organizations must implement and demonstrate adherence to every single requirement specified in NIST 800-171 which covers a wide range of cybersecurity practices for protecting CUI across different domains like Access Control, Audit and Accountability, Awareness and Training, etc.

Click on the images below for larger screen shots of how to select a baseline and how each looks to the user.

CMMC Level 2 Baseline Setting

Complete NIST/CMMC Reference Section

The i2ACT Software Tool has a complete online reference section that includes all FAR, NIST 800-171 and CMMC standards, Auditor Guides, DoD regulations and much more. In addition it includes NIST 800-53 NFO Evaluations and DFARS Evaluations. These reference sections can be used to familiarize the user with their content and layout. These are provided to clarify the information about the Security Controls and each control within the standard. NIST 800-171 refers to their Security Controls as Requirements, and CMMC Level 2 refers to their Security Controls as Practices.

In the i2ACT Software tool, the term "Control" is used throughout as a generic way to reference Security Controls in both standards when needed to keep explanations simple. These reference guides are available at the click of a button and can "float" in a separate window for quick and easy reference. In addition as you "step through" your assessment at each requirement level, these screens update dynamically for each requirement.

  • image

    FAR Regulations

    The wait is finally over! After more than 14 years of anticipation, the Federal Acquisition Regulation (“FAR”) Proposed Rule on Controlled Unclassified Information (“CUI”) was released on January 15, 2025 and comes as part of the Government’s broader efforts to identify, detect, and respond to ever-evolving threats targeting Federal contractors. The final FAR CUI rule has not yet been published, as it is still in the public comment phase which closed on March 17, 2025. The FAR Council will adjudicate the comments before issuing the final rule, which may take approximately one year after the comment period ends, though this timeline can vary. Publication of proposed rule: The proposed rule was published in the Federal Register on January 15, 2025. Public comment period: The public comment period ended on March 17, 2025. Finalization timeline: The FAR Council will review all comments before publishing the final rule, which is expected to take about a year after the comment period ends. Key changes: The rule aims to standardize CUI handling, implement NARA's policies, and introduce new reporting and compliance obligations for federal contractors

  • image

    NIST 800-171

    NIST Special Publication 800-171 Rev2, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, was originally published in February 2020, and included an update in January 2021. The Rev. 2 publication provides agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations; when the nonfederal organization is not collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency; and where there are no specific safeguarding requirements for protecting the confidentiality of CUI prescribed by the authorizing law, regulation, or government-wide policy for the CUI category listed in the CUI Registry.

  • image

    DoD CMMC Practices

    The DoD CMMC Practices Reference contains Tabs for the CMMC Discussion, the practice itself; various references from the 800-171A Assessment Guidelines and NIST Guidance from Handbook 162, (which was withdrawn and archived back in September of 2022 but still had a lot of good best practice information). This includes the details from the Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in response to DFARS Cybersecurity Requirements and provides guidance on implementing NIST SP 800-171 in response to the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012. The original NIST Handbook provided a step-by-step guide to assessing a small manufacturer’s information systems against the security requirements in NIST SP 800-171 rev 1, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations". All of this information is right at your fingertips in context-oriented pop-up windows.

  • image

    NFO Controls

    The SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations | CSRC provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. "NFO controls" in the context of NIST 800-53 refer to "Non-Federal Organization controls" which are essentially basic security practices considered so fundamental to any organization's operations that NIST does not provide detailed guidance on them; they are expected to be implemented as part of regular business practices, without requiring additional specific instructions. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk.

  • image

    DFARS Regulations

    The DFARS Regulations in the i2ACT are specifically curated from Part 252 for Defense Contractors. It is a set of regulations that apply to all U.S. Department of Defense (DoD) contracts and subcontracts. The regulations are designed to ensure that the DoD receives quality goods and services at fair and reasonable prices. DFARS is important because it provides essential regulations and guidelines for the DoD to acquire goods and services in a way that supports defense objectives and promotes national security. These regulations help ensure that the DoD conducts acquisitions in a transparent, accountable, and compliant manner. DFARS includes requirements related to contract award and administration, cybersecurity, intellectual property, small business utilization, and other critical areas.