Compliance Scanning

NIST CSF / 800-171
Compliance Scanning

Federal contractors and critical infrastructure organizations use the NIST Cybersecurity Framework and SP 800-171 to protect Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to the specific NIST controls and CSF subcategories.

Control Mapping

NIST Controls Mapped to ComplianceLayer Modules

Control identifiers reference NIST CSF 2.0 subcategories.

Control IDControl NameScan ModuleWhat We Check
PR.AA-03Users, Services, and Hardware AuthenticatedOpen Ports / SSLAuthenticate users, services, and hardware. Identifies exposed services without adequate authentication controls, including RDP (3389), SSH (22), VNC, and Telnet (23).
PR.AA-05Access Permissions and Least PrivilegeSecurity HeadersManage access permissions and authorizations incorporating least privilege. Validates Permissions-Policy header configuration.
PR.IR-01Networks Protected from Unauthorized AccessOpen PortsProtect networks and environments from unauthorized logical access. Detects exposed RDP, SMB (445), FTP (21), Telnet (23), database, and administrative ports.
PR.DS-01Data-at-Rest ProtectionOpen PortsProtect the confidentiality, integrity, and availability of data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) that may lack encryption.
PR.DS-02Data-in-Transit ProtectionSSL/TLS / Email / HeadersProtect the confidentiality, integrity, and availability of data-in-transit. Validates HTTPS enforcement, TLS versions and cipher strength, certificates, HSTS, SPF, DKIM, DMARC, and leak protections in CSP, Referrer-Policy, and Permissions-Policy.
PR.PS-01Secure Configuration ManagementSecurity HeadersEstablish and apply configuration management practices. Verifies security header presence and correctness, including Content-Security-Policy script controls.
ID.RA-01Vulnerability IdentificationAll ModulesIdentify, validate, and record vulnerabilities in assets. 15 scan modules cover the external attack surface with severity ratings and remediation guidance.

NIST CSF 2.0 is a voluntary framework. These controls reflect NIST-aligned technical practices observable from external scanning. The GOVERN function is not represented — governance cannot be assessed by an external scan. Full compliance with NIST 800-171 requires organizational and administrative controls beyond external scanning.

How It Works

NIST Compliance Evidence in 3 Steps

01

Enter your domain

Submit any domain your organization operates. ComplianceLayer scans the full external attack surface across 15 scan modules.

02

Review NIST mapping

Each finding maps to specific NIST CSF subcategories and 800-171 controls with pass, fail, or partial status.

03

Export compliance evidence

Download the report for your System Security Plan (SSP), POA&M documentation, or assessor review.

FAQ

Common questions

Which NIST framework does ComplianceLayer map to?

ComplianceLayer maps to both the NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect) and NIST SP 800-171 control families (Access Control, System and Communications Protection, Risk Assessment). The CSF subcategories and 800-171 controls overlap significantly for externally observable technical controls.

Is ComplianceLayer suitable for NIST 800-171 compliance?

ComplianceLayer covers the externally verifiable technical controls from NIST 800-171 families including AC (Access Control), SC (System and Communications Protection), and RA (Risk Assessment). Full 800-171 compliance requires additional organizational controls, policies, and internal security measures.

How does ComplianceLayer help with NIST CSF Identify and Protect functions?

For the Identify function, ComplianceLayer supports risk identification (ID.RA-01) through external vulnerability scanning. For the Protect function, it checks identity and access management (PR.AA), data security (PR.DS), and platform security configurations (PR.PS) through external scanning of TLS, ports, headers, and email authentication.

Can ComplianceLayer be used for FedRAMP preparation?

FedRAMP is based on NIST SP 800-53 controls. While ComplianceLayer maps to NIST CSF and 800-171 (which share controls with 800-53), FedRAMP requires a comprehensive assessment by a 3PAO. ComplianceLayer reports can provide evidence for the externally testable subset of controls.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. The free tier is here to stay.

10 free scans per monthAPI key in 30 secondsCancel anytime

All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.