Three Things to Consider Before Starting Your NIST 800-171 Implementation

By Kristen Morales • October 7, 2019

Your assessment is behind you. You have been working to create a System Security Plan (SSP) detailing a Plan of Action & Milestones (POA&Ms) based on your assessment findings.  Your goal, to remediate gaps discovered to ensure NIST 800-171 compliance with full implementation of all 110 security requirements.

Think of your SSP and POA&Ms as the required foundation and roadmap to get you to compliance. With over 110 security requirements in NIST 800-171, you need this layer of groundwork and direction to effectively tackle what is likely the most significant aspect of NIST 800-171 compliance, remediation or full implementation. So, where to start when working toward implementation?


3 Things to Consider Before Diving into Your NIST 800-171 Implementation:


1. Project Management

The SSP and POA&Ms outline the plan and timeline, but who is responsible for owning the outcome? A dedicated resource whose primary focus is ensuring the implementation of the plan is the best way to guarantee success. Implementing outstanding NIST 800-171 requirements is a large project but a project, nonetheless. By assigning a project manager, you have a clear leader to accept accountability, coach, and motivate your team. Also, they will ensure the right processes, resources, and tools are available to keep the project on schedule and within budget.


2. Staff Augmentation

NIST 800-171 has been a contractual obligation since December 2017, maybe you’re new to the DoD acquisition process or have been contracting with the DoD for some time. If you are the latter, there is a good chance one reason you are not compliant today is due to a lack of resources. As we all know, NIST 800-171 is in addition to your day job, so making it a priority is challenging. If you are already struggling to keep up with your day job due to constrained resources, then NIST compliance may not seem possible. If hiring a long-term employee is not an option contracting a third-party to partner with during the NIST 800-171 compliance project can help alleviate the stress of limited or already overworked staff.


3. Experience

Maybe you have the resources but lack the expertise.  Missing the experience, specifically, with NIST 800-171, within your team, can reduce efficiency ultimately increasing the cost.  The difference between how you handle the implementation for a tier 1 level Prime versus a small 1 to 10-person Subcontractor are significantly dissimilar, yet the same requirements apply.

We are often asked questions like, “Does CyberSheath have a list of tools for a business our size?” ” Does CyberSheath have experience implementing the NIST 800-171 controls for similar-sized businesses?”

Questions like this rely on our 10+ years of experience and 100+ successful NIST 800-171 implementations. Experience allows for decisions to be made in a manner that enables compliance as a documented, automated outcome of day-to-day operations. Hiring a third-party that has demonstrated NIST knowledge will allow your team to learn and grow through the lessons learned and best practices formed by other’s past experiences. More importantly, enable your organization to continue the work of maintaining compliance after the greater effort is complete.


Start Your NIST 800-171 Implementation Today

Overall, all three areas of consideration can be handled internally within your organization. The first step being your assessment to discover gaps.  Second, putting the SSP and POA&Ms in place to address those gaps. Lastly, creating a team dedicated to ensuring all 110 security requirements are implemented. However, partnering with a third-party organization will help ease the pains of growing an internal staff or burdening a current resource to manage the project. If partnering with a third-party interest you, check out our NIST Managed Services.  CyberSheath’s Managed Services are specifically designed to address the hurdles you will need to overcome during your implementation of the NIST requirements.  Learn More


Business photo created by pressfoto –

Cybersheath Blog

CMMC Compliance Dashboard: Gain New Visibility into Compliance

CMMC is not a compliance framework. It’s a maturity model. That has big implications for how you approach compliance, but also how you keep track of all the elements that make up compliance. And yet, visibility has been one of the most difficult challenges facing DIB contractors. It used to…

CMMCEnclave: Add Versatility with a More Flexible Approach

The enclave approach to CMMC compliance is one of the most cost effective and least disruptive ways to safeguard CUI. You can maintain high-value custodial security of CUI without upending your existing processes, procedures, and people. That way, you can maintain the proper level of CMMC compliance and remain eligible…

How to Offboard Your Managed Services Provider

For any of a variety of reasons including lack of communication, slow response times, or prolonged downtime, your organization has decided to change your managed service provider (MSP). Whether you have already signed an agreement with a new MSP or you are actively looking for a replacement, now is the…

Our Trusted Partners

Cyberark McAfee Thycotic RSA Tenable Alien Vault Alert Logic Microsoft