Nsasoft has added NIST SP 800-171 Rev 2 to NSAuditor AI Enterprise as its eighth compliance framework, aimed squarely at defense-industrial-base contractors assembling evidence ahead of a CMMC Level 2 assessment.
It is scoped precisely: evidence substrate for CMMC Level 2 preparation, never a CMMC certification — certification is a per-contractor C3PAO outcome, and the engine determines nothing and scores nothing.
The design decision worth reporting is the level at which coverage is claimed. SP 800-171A decomposes each of the 110 Rev 2 requirements into determination statements, and an assessor scores every one. NSAuditor AI publishes at that level: each of the 51 mapped requirements carries its full objective list beside the subset the scan supplies examine-method material for — 69 of 172 determination statements — and every “partial” names which shortfall it is rather than leaving a contractor to guess.
The headline coverage figure is deliberately unflattering and deliberately published: 2 covered, 49 partial, 59 out of scope across all 110 requirements, with no declared subset and a written reason on every out-of-scope group. Five families are operator-side in their entirety — awareness and training, incident-response execution, maintenance, personnel security and physical protection. A requirement counts as covered only when every one of its objectives is technical system state a scan reads directly, which is a materially harder bar than most tooling applies.
Rev 2 is pinned on purpose, because CMMC assesses Rev 2 by rule; Rev 3 is a separate 97-requirement universe with organization-defined parameters.
For DIB contractors the practical draw is consolidation. --compliance nist-800-171 joins seven existing framework names, and all eight route from a single agentless, read-only scan across AWS, Azure, GCP and on-prem networks: SOC 2, HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as Security of Processing infrastructure substrate only and never GDPR compliance, and NIST SP 800-171 Rev 2. Each framework gets its own evidence pack with a SHA-256 chain-of-custody sidecar that verifies offline.
The scanner runs on the operator’s own infrastructure with read-only credentials enforced in the product’s own code, and ships a published register of every outbound path it can make, each with its trigger and its off switch — a fit for contractors operating inside restricted enclaves. It informs the System Security Plan and the POA&M and never produces them, and CUI scope remains the operator’s assertion: the scanner reads infrastructure configuration and cannot see an enclave boundary.
The current release is EE 0.40.2, which requires Community Edition 0.2.45 or newer — a real floor, because framework-name validation lives in Community Edition. The plugin catalog is unchanged at 28 Enterprise auditors, 27 of them cloud, 55 overall.
npm install -g nsauditor-ai@0.2.46 @nsasoft/nsauditor-ai-ee@0.40.2 nsauditor-ai-agent-skill@0.2.44
Coverage detail: nsauditor.com/ai/docs/800-171/




