Compliance Scanning

NIST CSF / 800-171
Compliance Scanning

Federal contractors and critical infrastructure organizations use the NIST Cybersecurity Framework and SP 800-171 to protect Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to the specific NIST controls and CSF subcategories.

Control Mapping

NIST Controls Mapped to ComplianceLayer Modules

Controls reference both NIST CSF subcategories (PR.xx, DE.xx, ID.xx) and NIST SP 800-171/800-53 control identifiers (AC-xx, SC-xx).

Control IDControl NameScan ModuleWhat We Check
PR.AC-4Access Permissions ManagedSecurity HeadersManage access permissions incorporating least privilege. Validates Permissions-Policy header configuration.
PR.AC-5Network Integrity ProtectionOpen PortsProtect network integrity with segmentation and access controls. Detects exposed RDP, SMB, database, and administrative ports.
PR.AC-7Authentication MechanismsOpen Ports / SSLAuthenticate users, devices, and processes. Identifies services exposed without adequate authentication controls.
AC-17Remote AccessOpen PortsEstablish and manage remote access controls. Detects exposed RDP (3389), SSH (22), VNC, and Telnet (23) services.
PR.DS-1Data-at-Rest ProtectionOpen PortsProtect data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) that may lack encryption.
PR.DS-2Data-in-Transit ProtectionSSL/TLS / EmailProtect data-in-transit. Validates HTTPS enforcement, TLS configuration, HSTS, SPF, DKIM, and DMARC.
PR.DS-5Data Leak ProtectionSecurity HeadersImplement protections against data leaks. Checks CSP, Referrer-Policy, and Permissions-Policy headers.
PR.DS-6Integrity CheckingSecurity HeadersUse integrity checking mechanisms to verify software and data. Validates Content-Security-Policy for script integrity.
PR.IP-1Baseline ConfigurationsSecurity HeadersEstablish and maintain baseline configurations. Verifies security header presence and configuration correctness.
PR.PT-4Communications ProtectionOpen PortsProtect communications and control networks. Detects exposed SMB (445), Telnet (23), and FTP (21) services.
PR.AT-1Security AwarenessEmailProvide security awareness training. DMARC policy enforcement indicates anti-phishing awareness measures.
SC-8Transmission ConfidentialitySSL/TLSProtect confidentiality and integrity of transmitted information. Validates TLS versions, cipher suites, and certificates.
SC-13Cryptographic ProtectionSSL/TLSImplement NIST-approved cryptography. Checks for weak ciphers, deprecated TLS 1.0/1.1, and key strength.
DE.CM-8Vulnerability ScansAll ModulesPerform vulnerability scans. ComplianceLayer runs 16 modules covering the external attack surface continuously.
ID.RA-1Risk IdentificationAll ModulesIdentify and document asset vulnerabilities. Aggregated findings with severity ratings and remediation guidance.

NIST CSF is a voluntary framework. These controls reflect NIST-aligned technical practices observable from external scanning. Full compliance with NIST 800-171 requires organizational and administrative controls beyond external scanning.

How It Works

NIST Compliance Evidence in 3 Steps

01

Enter your domain

Submit any domain your organization operates. ComplianceLayer scans the full external attack surface across 16 modules.

02

Review NIST mapping

Each finding maps to specific NIST CSF subcategories and 800-171 controls with pass, fail, or partial status.

03

Export compliance evidence

Download the report for your System Security Plan (SSP), POA&M documentation, or assessor review.

FAQ

Common questions

Which NIST framework does ComplianceLayer map to?

ComplianceLayer maps to both the NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect) and NIST SP 800-171 control families (Access Control, System and Communications Protection, Risk Assessment). The CSF subcategories and 800-171 controls overlap significantly for externally observable technical controls.

Is ComplianceLayer suitable for NIST 800-171 compliance?

ComplianceLayer covers the externally verifiable technical controls from NIST 800-171 families including AC (Access Control), SC (System and Communications Protection), and RA (Risk Assessment). Full 800-171 compliance requires additional organizational controls, policies, and internal security measures.

How does ComplianceLayer help with NIST CSF Identify and Protect functions?

For the Identify function, ComplianceLayer provides risk identification (ID.RA-1) through vulnerability scanning. For the Protect function, it validates access control (PR.AC), data security (PR.DS), and baseline configurations (PR.IP) through external scanning of TLS, ports, headers, and email authentication.

Can ComplianceLayer be used for FedRAMP preparation?

FedRAMP is based on NIST SP 800-53 controls. While ComplianceLayer maps to NIST CSF and 800-171 (which share controls with 800-53), FedRAMP requires a comprehensive assessment by a 3PAO. ComplianceLayer reports can provide evidence for the externally testable subset of controls.

Other compliance frameworks

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.