NIST CSF / 800-171
Compliance Scanning
Federal contractors and critical infrastructure organizations use the NIST Cybersecurity Framework and SP 800-171 to protect Controlled Unclassified Information (CUI). ComplianceLayer maps external scan findings to the specific NIST controls and CSF subcategories.
NIST Controls Mapped to ComplianceLayer Modules
Controls reference both NIST CSF subcategories (PR.xx, DE.xx, ID.xx) and NIST SP 800-171/800-53 control identifiers (AC-xx, SC-xx).
| Control ID | Control Name | Scan Module | What We Check |
|---|---|---|---|
| PR.AC-4 | Access Permissions Managed | Security Headers | Manage access permissions incorporating least privilege. Validates Permissions-Policy header configuration. |
| PR.AC-5 | Network Integrity Protection | Open Ports | Protect network integrity with segmentation and access controls. Detects exposed RDP, SMB, database, and administrative ports. |
| PR.AC-7 | Authentication Mechanisms | Open Ports / SSL | Authenticate users, devices, and processes. Identifies services exposed without adequate authentication controls. |
| AC-17 | Remote Access | Open Ports | Establish and manage remote access controls. Detects exposed RDP (3389), SSH (22), VNC, and Telnet (23) services. |
| PR.DS-1 | Data-at-Rest Protection | Open Ports | Protect data-at-rest. Identifies exposed database ports (MySQL 3306, PostgreSQL 5432) that may lack encryption. |
| PR.DS-2 | Data-in-Transit Protection | SSL/TLS / Email | Protect data-in-transit. Validates HTTPS enforcement, TLS configuration, HSTS, SPF, DKIM, and DMARC. |
| PR.DS-5 | Data Leak Protection | Security Headers | Implement protections against data leaks. Checks CSP, Referrer-Policy, and Permissions-Policy headers. |
| PR.DS-6 | Integrity Checking | Security Headers | Use integrity checking mechanisms to verify software and data. Validates Content-Security-Policy for script integrity. |
| PR.IP-1 | Baseline Configurations | Security Headers | Establish and maintain baseline configurations. Verifies security header presence and configuration correctness. |
| PR.PT-4 | Communications Protection | Open Ports | Protect communications and control networks. Detects exposed SMB (445), Telnet (23), and FTP (21) services. |
| PR.AT-1 | Security Awareness | Provide security awareness training. DMARC policy enforcement indicates anti-phishing awareness measures. | |
| SC-8 | Transmission Confidentiality | SSL/TLS | Protect confidentiality and integrity of transmitted information. Validates TLS versions, cipher suites, and certificates. |
| SC-13 | Cryptographic Protection | SSL/TLS | Implement NIST-approved cryptography. Checks for weak ciphers, deprecated TLS 1.0/1.1, and key strength. |
| DE.CM-8 | Vulnerability Scans | All Modules | Perform vulnerability scans. ComplianceLayer runs 16 modules covering the external attack surface continuously. |
| ID.RA-1 | Risk Identification | All Modules | Identify and document asset vulnerabilities. Aggregated findings with severity ratings and remediation guidance. |
NIST CSF is a voluntary framework. These controls reflect NIST-aligned technical practices observable from external scanning. Full compliance with NIST 800-171 requires organizational and administrative controls beyond external scanning.
NIST Compliance Evidence in 3 Steps
Enter your domain
Submit any domain your organization operates. ComplianceLayer scans the full external attack surface across 16 modules.
Review NIST mapping
Each finding maps to specific NIST CSF subcategories and 800-171 controls with pass, fail, or partial status.
Export compliance evidence
Download the report for your System Security Plan (SSP), POA&M documentation, or assessor review.
Common questions
Which NIST framework does ComplianceLayer map to?
ComplianceLayer maps to both the NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect) and NIST SP 800-171 control families (Access Control, System and Communications Protection, Risk Assessment). The CSF subcategories and 800-171 controls overlap significantly for externally observable technical controls.
Is ComplianceLayer suitable for NIST 800-171 compliance?
ComplianceLayer covers the externally verifiable technical controls from NIST 800-171 families including AC (Access Control), SC (System and Communications Protection), and RA (Risk Assessment). Full 800-171 compliance requires additional organizational controls, policies, and internal security measures.
How does ComplianceLayer help with NIST CSF Identify and Protect functions?
For the Identify function, ComplianceLayer provides risk identification (ID.RA-1) through vulnerability scanning. For the Protect function, it validates access control (PR.AC), data security (PR.DS), and baseline configurations (PR.IP) through external scanning of TLS, ports, headers, and email authentication.
Can ComplianceLayer be used for FedRAMP preparation?
FedRAMP is based on NIST SP 800-53 controls. While ComplianceLayer maps to NIST CSF and 800-171 (which share controls with 800-53), FedRAMP requires a comprehensive assessment by a 3PAO. ComplianceLayer reports can provide evidence for the externally testable subset of controls.
Start scanning your first
domain in 60 seconds.
No credit card. No sales call. No setup. Free tier is permanent.
All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.