NIST CSF / 800-171
Compliance Scanning
Federal contractors and critical infrastructure organizations use the NIST Cybersecurity Framework and SP 800-171 to protect Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to the specific NIST controls and CSF subcategories.
NIST Controls Mapped to ComplianceLayer Modules
Control identifiers reference NIST CSF 2.0 subcategories.
| Control ID | Control Name | Scan Module | What We Check |
|---|---|---|---|
| PR.AA-03 | Users, Services, and Hardware Authenticated | Open Ports / SSL | Authenticate users, services, and hardware. Identifies exposed services without adequate authentication controls, including RDP (3389), SSH (22), VNC, and Telnet (23). |
| PR.AA-05 | Access Permissions and Least Privilege | Security Headers | Manage access permissions and authorizations incorporating least privilege. Validates Permissions-Policy header configuration. |
| PR.IR-01 | Networks Protected from Unauthorized Access | Open Ports | Protect networks and environments from unauthorized logical access. Detects exposed RDP, SMB (445), FTP (21), Telnet (23), database, and administrative ports. |
| PR.DS-01 | Data-at-Rest Protection | Open Ports | Protect the confidentiality, integrity, and availability of data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) that may lack encryption. |
| PR.DS-02 | Data-in-Transit Protection | SSL/TLS / Email / Headers | Protect the confidentiality, integrity, and availability of data-in-transit. Validates HTTPS enforcement, TLS versions and cipher strength, certificates, HSTS, SPF, DKIM, DMARC, and leak protections in CSP, Referrer-Policy, and Permissions-Policy. |
| PR.PS-01 | Secure Configuration Management | Security Headers | Establish and apply configuration management practices. Verifies security header presence and correctness, including Content-Security-Policy script controls. |
| ID.RA-01 | Vulnerability Identification | All Modules | Identify, validate, and record vulnerabilities in assets. 15 scan modules cover the external attack surface with severity ratings and remediation guidance. |
NIST CSF 2.0 is a voluntary framework. These controls reflect NIST-aligned technical practices observable from external scanning. The GOVERN function is not represented — governance cannot be assessed by an external scan. Full compliance with NIST 800-171 requires organizational and administrative controls beyond external scanning.
NIST Compliance Evidence in 3 Steps
Enter your domain
Submit any domain your organization operates. ComplianceLayer scans the full external attack surface across 15 scan modules.
Review NIST mapping
Each finding maps to specific NIST CSF subcategories and 800-171 controls with pass, fail, or partial status.
Export compliance evidence
Download the report for your System Security Plan (SSP), POA&M documentation, or assessor review.
Common questions
Which NIST framework does ComplianceLayer map to?
ComplianceLayer maps to both the NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect) and NIST SP 800-171 control families (Access Control, System and Communications Protection, Risk Assessment). The CSF subcategories and 800-171 controls overlap significantly for externally observable technical controls.
Is ComplianceLayer suitable for NIST 800-171 compliance?
ComplianceLayer covers the externally verifiable technical controls from NIST 800-171 families including AC (Access Control), SC (System and Communications Protection), and RA (Risk Assessment). Full 800-171 compliance requires additional organizational controls, policies, and internal security measures.
How does ComplianceLayer help with NIST CSF Identify and Protect functions?
For the Identify function, ComplianceLayer supports risk identification (ID.RA-01) through external vulnerability scanning. For the Protect function, it checks identity and access management (PR.AA), data security (PR.DS), and platform security configurations (PR.PS) through external scanning of TLS, ports, headers, and email authentication.
Can ComplianceLayer be used for FedRAMP preparation?
FedRAMP is based on NIST SP 800-53 controls. While ComplianceLayer maps to NIST CSF and 800-171 (which share controls with 800-53), FedRAMP requires a comprehensive assessment by a 3PAO. ComplianceLayer reports can provide evidence for the externally testable subset of controls.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. The free tier is here to stay.
All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.