NSAuditor AI Enterprise Adds NIST SP 800-171 Rev 2 — Eight Compliance Frameworks From One Scan

NSAuditor has added NIST SP 800-171 Rev 2 to NSAuditor AI Enterprise, bringing the local-first security scanner to eight compliance frameworks from a single agentless, read-only scan. The framework arrived in Enterprise Edition 0.40.0 and is live in the current 0.40.1 release.

The addition is aimed squarely at the defense industrial base. NIST SP 800-171 Rev 2 is the requirement set that CMMC Level 2 assessments are conducted against, and it is scoped here as evidence substrate for CMMC Level 2 preparation — material a contractor brings into an assessment, not a verdict about its outcome.

Mapped at the level an assessment is scored at

SP 800-171A breaks each of the 110 requirements into determination statements, and an assessor scores every one of them. NSAuditor maps at that level: each mapped requirement publishes the full list of its determination statements alongside the subset the scan supplies examine-method material for — 81 of 172 across the 51 mapped requirements. Where a requirement is partial, the output names which of three shortfalls it is.

All 110 requirements are enumerated with no declared subset. Every requirement is classified and every out-of-scope group carries a written reason, including five families that are operator-side in their entirety: awareness and training, incident-response execution, maintenance, personnel security and physical protection.

Eight frameworks, one scan

NIST SP 800-171 Rev 2 joins SOC 2, HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8 and GDPR Article 32 — the last as Security-of-Processing infrastructure substrate rather than GDPR compliance. Each framework produces its own evidence pack with a SHA-256 chain of custody and an explicit out-of-scope column, and all eight route from one scan across AWS, Azure, GCP and on-premises networks.

Scope, stated up front

  • The engine informs a contractor’s System Security Plan and POA&M; those remain operator artifacts.
  • Certification is a per-contractor C3PAO assessment outcome and stays with the assessor.
  • CUI scope remains the operator’s assertion — the scanner reads infrastructure configuration and cannot see CUI or an enclave boundary. Its offline operation fits enclave deployments.
  • Rev 2 is pinned deliberately, because CMMC assesses Rev 2 by rule.

One practical note for anyone writing about both standards: NIST SP 800-171 requirement ids collide exactly with PCI DSS sub-requirement ids, so 3.5.1 names a real requirement in each. Always qualify the citation.

Availability

Enterprise Edition 0.40.1 is live, paired with Community Edition 0.2.45 and agent-skill package 0.2.43. The Community Edition floor is raised to 0.2.45 this cycle, because framework-name validation lives in Community Edition. The plugin catalog is unchanged at 28 Enterprise plugins, 55 overall.

npm install -g nsauditor-ai@0.2.45 @nsasoft/nsauditor-ai-ee@0.40.1

Details: nsauditor.com/ai/docs/800-171/