CUI · NIST SP 800-171 · CMMC 2.0

Your CUI controls, answered by the architecture.

NIST SP 800-171 applies to your organization — not to a product. But a sealed appliance you physically control removes the vendor chain, the shared platform, and (when air-gapped) the network itself from the picture — so a number of controls are met by design rather than by paperwork. Here is how the responsibility splits, and the clean answers for the four families an appliance touches most directly.

Not a cloud “inheritance” model

You own the boundary. We supply the mechanisms.

With a cloud service you inherit — and must keep evidencing — someone else’s authorization for the controls they run. An appliance in your own facility flips that: there is no third party in the data path to certify, and the controls that matter are implemented on hardware you hold. That is a simpler, stronger story to an assessor than pointing at a provider’s package.

Shared-responsibility matrix

Where each of the 14 families lands.

Assumes the air-gapped posture recommended for controlled data. Every family still belongs in your System Security Plan — this shows what FileFerret implements for you and what stays yours to run.

  • Provided The appliance implements it as delivered — cite FileFerret as the mechanism and keep its records as evidence.
  • Shared FileFerret provides the mechanism; you configure, operate, and document it.
  • Customer Satisfied by your organization, facility, people, or policy. FileFerret plays little or no role.
Control familyResponsibilityHow it’s met
Access Control3.1 Provided Role-based access with per-client walls; multi-factor authentication enforced for administrator and privileged accounts, available for every user. You provision people and assign roles.
Awareness & Training3.2 Customer Your security-awareness program. We train your administrators and operators at install.
Audit & Accountability3.3 Provided A tamper-evident, write-once activity log records every login, search, file open, and support action — traceable to a named person. You set retention and review cadence.
Configuration Management3.4 Provided A sealed, single-purpose appliance ships hardened; only signed updates can change it, and users cannot install software. Least-functionality by construction.
Identification & Authentication3.5 Provided Every person has a unique identity on the appliance; multi-factor authentication is enforced for privileged accounts. No shared logins required.
Incident Response3.6 Customer Your incident-response plan. The activity log and health alerts feed your detection and reporting.
Maintenance3.7 Shared Support reaches a constrained console that cannot open a client file. Access is one-time, dual-approval, least-privilege, and fully recorded. In the air-gapped posture, remote maintenance does not exist.
Media Protection3.8 Shared Client data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We provide a documented drive-sanitization procedure for decommission; you own the physical media and execute it.
Personnel Security3.9 Customer Your screening and your access-revocation-on-departure processes.
Physical Protection3.10 Customer The appliance sits in a facility you control. Physical access, escort, and monitoring are yours — deliberately, and a strength for controlled data.
Risk Assessment3.11 Customer Your risk-management program. We supply the security posture of the appliance and its components for your scope.
Security Assessment3.12 Customer Your System Security Plan, POA&M, and assessment cadence. Our control-mapping package is an input to it.
System & Communications Protection3.13 Provided A self-contained enclave: no inbound ports, encryption in transit and at rest, and — in the air-gapped posture — no path off the box at all. No shared, multi-tenant platform.
System & Information Integrity3.14 Shared Flaws are remediated through signed updates we security-review before release. You layer your network monitoring and endpoint controls around the appliance.

A “Provided” or “Shared” marking does not remove a family from your plan — you still describe how it is met and name the mechanism. FileFerret shrinks the work and supplies the evidence; it does not sign your attestation.

The four an appliance answers cleanly

Access control, audit, configuration, media.

Access control (§ 3.1 / 3.5)

Only provisioned people get in, each under a unique identity, and each client’s material lives behind its own wall. Multi-factor authentication is enforced for administrator and privileged accounts and available for every user. Least privilege is the default, and every privileged action is written to the audit log.

Audit logging (§ 3.3)

A write-once, tamper-evident log captures every login, search, and file open — and every support action we ever take — each traceable to a named person. Records cannot be silently altered or deleted, so you can answer “who touched what, and when” with evidence an assessor accepts.

Configuration management (§ 3.4)

The appliance is sealed and single-purpose: it ships hardened, only signed updates can change it, and there is no path for a user to install arbitrary software. That makes least-functionality and software allow-listing true by construction, not by a setting someone has to maintain.

Media protection (§ 3.8)

Client data is encrypted at rest (AES-256) and in transit (TLS 1.2+), and stays inside your walls. Diagnostics that leave for support are scrubbed of client content, and we provide a documented sanitization procedure so drives are cleared or destroyed before disposal or return.

Customer responsibility  Media Protection § 3.8.3

Decommission & media sanitization — your procedure.

Sanitizing a drive at end-of-life is a step you perform in your own facility (you, or an IT-asset-disposal provider under your supervision) — FileFerret never takes custody of your media. We supply the procedure, the on-appliance tooling, and a certificate template so you can execute and evidence it cleanly. This procedure is aligned to NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization.

  1. Step 1

    Classify the media

    Decide the sanitization level by where the drive is going: Clear (stays inside your boundary for reuse), Purge (leaves your boundary — return, resale, transfer), or Destroy (highest assurance, or a drive that cannot be purged). These are the NIST SP 800-88 categories.

  2. Step 2

    Cryptographic erase

    Because all client data is encrypted at rest, the appliance’s decommission function destroys the on-device encryption keys — rendering everything stored on the drive unrecoverable in one operation.

  3. Step 3

    Firmware sanitize

    For the Purge path on drives that support it, issue the drive’s built-in secure-erase / sanitize command so residual data is cleared at the hardware level, not just logically deleted.

  4. Step 4

    Verify

    Confirm the sanitization actually succeeded — a verification pass, not an assumption. NIST SP 800-88 requires verification; never skip it, and record the result.

  5. Step 5

    Destroy if required

    For the Destroy path — the strictest mandates, or any drive that cannot be sanitized in place — physically destroy the media (shred, disintegrate, or degauss to the method appropriate for that media type).

  6. Step 6

    Certify & retain

    Complete a Certificate of Sanitization — media identity, method, tool, date, operator, and verification result — and keep it as evidence for your System Security Plan and any assessment. We provide the certificate template.

Why an encrypted appliance makes this clean

With client data encrypted at rest, a cryptographic erase — destroying the keys — is enough to make the data unrecoverable, so a full Purge is fast and verifiable. Physical destruction remains available for the strictest mandates. Either way, you leave with a signed certificate for your records.

The retained Certificate of Sanitization is the evidence an assessor looks for under 3.8.3 (sanitize or destroy media before disposal or reuse). Keep one per drive with your SSP.

Questions an assessor asks

Straight answers for your review.

Does any Controlled Unclassified Information leave our boundary?

No. Indexing, search, and the AI that writes answers all run on the appliance inside your network. Identity, configuration, and keys are held on the appliance too — nothing calls home. In the air-gapped posture there is no path off the box at all.

Do we inherit controls from a cloud provider we now have to evidence?

No. There is no external cloud provider, no shared multi-tenant platform, and no sub-processor chain in the data path. You own the boundary end to end; FileFerret supplies the on-appliance mechanisms and the evidence.

How is vendor support access controlled and supervised?

There is no standing support account. Access is one-time, requires both your approval and our identity, is scoped to the minimum needed, and expires on its own. It reaches a console that cannot read a client file; anything more is a screen-share with your admin’s hands on the keyboard. Every action is written to the log you hold.

Can vendor support read our client data?

No. The support console is built so it cannot open or export a client document, read index content, or see what was searched. That boundary is the design, not a promise.

How do we know the audit log wasn’t tampered with?

It is write-once and tamper-evident. Records cannot be silently changed or deleted — including by an administrator or by us — and our own support sessions are recorded to the same log.

Which version of NIST 800-171 does this cover?

This reflects the revision referenced by DFARS 252.204-7012 and CMMC 2.0 Level 2. A newer revision reorganizes and adds requirements; tell us which one your contract names and we will map to it. Please confirm your obligations with your assessor and counsel.

A control-mapping package for your SSP

We provide a per-control mapping across all 110 requirements — responsibility, the implementing mechanism, and the evidence to cite — ready to fold into your System Security Plan. Request it for your assessment →

This page is a general readiness summary, not a certification, an assessment, or legal advice, and it does not by itself satisfy any requirement. NIST SP 800-171 applies to your organization and information system; applicability depends on your boundary, posture, and contract. Confirm your obligations with your assessor and counsel.

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.