The Eighth Framework: NSAuditor AI Enterprise Maps NIST SP 800-171 Rev 2 at the Level a C3PAO Actually Scores
NIST SP 800-171 Rev 2 joins NSAuditor AI Enterprise as its eighth framework, mapped at SP 800-171A determination-statement level from one read-only scan.
An assessor does not score your requirements. They score your objectives. Everything interesting about mapping NIST SP 800-171 Rev 2 follows from that one sentence, and it is why NSAuditor AI Enterprise publishes its eighth compliance framework at the determination-statement level rather than the requirement level.
NIST SP 800-171 Rev 2 joins the coverage engine as evidence substrate for CMMC Level 2 preparation — never a CMMC certification, which is a per-contractor C3PAO assessment outcome and stays your assessor’s to make. It routes from the same single agentless, read-only scan as the other seven frameworks, and it composes with them: one pass across AWS, Azure, GCP and your on-prem network, eight framework-mapped evidence packs out the other side.
Why the objective level is the only honest level
SP 800-171A decomposes each of the 110 Rev 2 requirements into determination statements. A C3PAO scores every one of them. A requirement is therefore only genuinely evidenced by configuration when every one of its objectives is a statement about technical system state a scan can read directly — and most requirements retain at least one objective about a defined procedure, an identified set of people, or an authorization that no scanner can observe.
So this engine publishes both halves. Every mapped requirement carries the full list of its determination statements and the subset the scan supplies examine-method material for: 69 of 172 determination statements across the 51 mapped requirements. Every “partial” additionally names which of three shortfalls it actually is, because “partial” on its own hides three genuinely different situations and an assessor needs the shape of the gap, not its label.
The practical effect is that a reviewer can check your claim instead of accepting it. That is the difference between an evidence pack and a marketing artifact.
All 110 requirements are enumerated
There is no declared subset, and therefore no under-enumeration surface: every requirement is classified, and every out-of-scope group carries a written reason. Five families are operator-side in their entirety — awareness and training, incident-response execution, maintenance, personnel security, and physical protection — and the map says so rather than quietly omitting them.
Rev 2 is pinned deliberately. CMMC assesses Rev 2 by rule. Rev 3 is a different universe — 97 requirements with organization-defined parameters — and answering a Rev 3 question with Rev 2 output is drift, not currency.
One note for anyone writing citations: SP 800-171 requirement ids collide exactly with PCI DSS sub-requirement ids — 3.5.1 names a real requirement in both standards. Neither framework strips bare ids, because no rule could attribute one correctly. Always write “NIST SP 800-171 3.5.1”.
The eight shipped coverage matrices
Every figure below is returned by the product’s own compliance_matrix tool at call time, derived from the shipped framework maps rather than transcribed. Out-of-scope is the flattened sub-criterion count.
| Framework | Covered | Partial | Out of scope | Universe |
|---|---|---|---|---|
| SOC 2 (AICPA TSC 2017) | 10 | 4 | 37 | 51 |
| HIPAA Security Rule §164.312 | 7 | 3 | 45 | 55 |
| NIST CSF 2.0 (Core) | 13 | 10 | 83 | 106 |
| PCI DSS v4.0.1 | 19 | 9 | 39 | 67 |
| ISO/IEC 27001:2022 | 17 | 14 | 62 | 93 |
| CIS Controls v8 | 17 | 23 | 113 | 153 |
| GDPR Article 32 — Security of Processing infrastructure substrate only, never GDPR compliance | 4 | 5 | 2 | 11 |
| NIST SP 800-171 Rev 2 — evidence substrate for CMMC Level 2 preparation | 2 | 49 | 59 | 110 |
Two of 110 is the number we lead with, and it is a strength rather than an omission: it is what a coverage claim looks like when it is made at the level an assessment is actually scored. A product claiming substantially more is either measuring something else or claiming a requirement from a subset of its objectives — which is the first overclaim a C3PAO tests for.
What it produces, and what it refuses to
The engine informs your System Security Plan and your POA&M and never produces them — those are the artifacts an assessment is conducted against. It emits no MET or NOT MET determination and no score of any kind. And CUI scope remains the operator’s assertion: the scanner reads infrastructure configuration, cannot distinguish FCI from CUI, and cannot see an enclave boundary. Its offline operation fits enclave deployments; fitting inside a boundary is not defining one.
How to run it
nsauditor-ai scan --host aws --compliance nist-800-171 --env org.env --out ./evidence
Or take all eight in a single pass:
nsauditor-ai scan --host aws \
--compliance soc2,hipaa,nist-csf,pci-dss,iso-27001,cis-v8,gdpr,nist-800-171 \
--env org.env --out ./evidence
One finding stream, separate per-framework artifacts, each with a SHA-256 chain-of-custody sidecar that verifies offline. RFC 3161 trusted timestamping is available and is opt-in via NSAUDITOR_TSA_URL, never a default — and in EE 0.40.2 the timestamp path reads the authority’s status from its own response before anything reaches disk, so only a token the authority actually granted is ever recorded.
Availability
The version to install today is EE 0.40.2, which requires Community Edition 0.2.45 or newer — a real floor, because framework-name validation lives in Community Edition and an older build rejects nist-800-171 by name.
npm install -g nsauditor-ai@0.2.46 @nsasoft/nsauditor-ai-ee@0.40.2 nsauditor-ai-agent-skill@0.2.44
The plugin catalog is unchanged at 28 Enterprise auditors — 27 cloud auditors plus a Zero Trust posture assessment scored from a network-host scan — 55 plugins overall. Enterprise is restricted distribution and resolves for entitled accounts; Community Edition and the agent skill are public.
Coverage page: nsauditor.com/ai/docs/800-171/ · Enterprise: nsauditor.com/ai/enterprise/



