Trust & Data Handling
NIST SP 800-171: the standard behind Plavidian's security program
Plavidian's security program is built on NIST Special Publication 800-171, the federal standard for protecting sensitive government information held on nonfederal systems. This page explains what that standard is, how it differs from commercial frameworks like SOC 2, and exactly where Plavidian stands against it, with numbers rather than adjectives.
Where We Stand
Assessed against all 110 requirements
On July 29, 2026, Plavidian Connect was assessed against all 110 security requirements of NIST SP 800-171 rev. 2 and scored under the Department of Defense Assessment Methodology, the government's own published scoring system for this standard (a documented self-assessment). The result: 104 out of a possible 110, with 108 of 110 requirements implemented and the remaining two scheduled on dated milestones (December 2026 and 2027).
The assessment is documented in the summary format DFARS 252.204-7019 and 252.204-7020 require for the DoD's Supplier Performance Risk System (SPRS), and it also covers all 15 basic safeguarding requirements of FAR 52.204-21, the pass/fail basis of CMMC Level 1, every one of which is met. The full System Security Plan, the milestone plan, and the assessment worksheet are available to clients and their consultants under NDA at info@plavidian.com.
The Standard
A government-defined security standard
NIST Special Publication 800-171 is a cybersecurity standard developed by the National Institute of Standards and Technology, an agency of the United States Department of Commerce. It was created to protect Controlled Unclassified Information, or CUI, when that sensitive government information is stored or processed within nonfederal organizations and information systems.
Its requirements address access control, authentication, audit logging, configuration management, incident response, system integrity, risk assessment, personnel security, physical protection, and the safeguarding of communications and stored information. This is not simply a commercial security checklist: NIST SP 800-171 is part of the federal government's framework for protecting sensitive information handled outside government systems, and NIST publishes a companion assessment methodology specifying how implementation of the requirements is evaluated.
Frameworks Compared
How NIST SP 800-171 differs from SOC 2
SOC 2 is a respected independent-attestation framework developed by the American Institute of Certified Public Accountants. In a SOC 2 examination, a CPA evaluates an organization's controls against the Trust Services Criteria included within the agreed scope of the examination. The two are not identical certifications or directly interchangeable standards.
The important distinction is that NIST SP 800-171 establishes government-defined, prescriptive security requirements specifically designed to protect sensitive government information. A SOC 2 report evaluates controls selected within the scope of a particular examination, and that scope can vary among organizations. For customers, this means Plavidian's security program is built around requirements intended for environments entrusted with sensitive government information, not merely around a general commercial assurance checklist.
NIST SP 800-171
- Developed by the U.S. government through NIST
- Designed specifically to protect Controlled Unclassified Information
- Establishes 110 defined security requirements
- Supported by a published government assessment methodology
- Frequently relevant to federal contractors and organizations handling sensitive government information
SOC 2
- Developed by the AICPA
- Evaluates controls against selected Trust Services Criteria
- Conducted as an independent CPA attestation
- Scope can differ by organization and engagement
- May cover security, availability, processing integrity, confidentiality, and privacy
Plavidian's approach
Plavidian has chosen NIST SP 800-171 as the foundation of its security program because it provides a government-defined and prescriptive framework designed for protecting sensitive information, and because its published assessment methodology lets us measure ourselves against it and show the number.
Who Benefits
A higher security baseline for all customers
Plavidian applies this security-focused approach to the systems and processes used to support political, nonprofit, government, and commercial customer projects. The objective is a strong and consistent security baseline for information such as customer mailing lists, voter and constituent records, artwork and production files, account and contact information, proofs and approval records, postal documentation, production-verification records, and reports and invoices.
Plavidian's use of NIST SP 800-171 as its guiding security framework does not mean that every customer file is Controlled Unclassified Information. It means that Plavidian has chosen to structure its security program around a government-developed framework intended for protecting information requiring significant safeguards, and that voter, donor, and constituent files receive that handling whether or not a designation applies.
Documentation
Every claim on this page has paper behind it
Published
The assessment result and date, the scoring methodology used, the standards met, and the enhancement roadmap with its milestones, here and on our Security and Data Handling page, kept current the same day anything changes.
Available on request
The version-dated System Security Plan with cryptographic inventory, the milestone plan, the July 29, 2026 assessment worksheet, and completed vendor security questionnaires, answered against the plan rather than from memory. Under NDA: info@plavidian.com.
Plavidian maintains documentation supporting its security program and continues to review its controls as systems, risks, customer requirements, and government standards evolve.
