Operating picture · measured 2026-09-15

419 of 39,864 US IT providers show a NIST 800-171 credential — 1.1% of the market.

8,334 US providers name government, defense or the public sector as a market they serve. 347 of them show a NIST 800-171 credential. The standard is the one flowed down to those buyers' suppliers, and 7,987 providers chasing that work do not name it.

95.8%

of providers that market to government and defense show no NIST 800-171 credential

n = 39,864 published US providers. 419 carry a nist_800_171 certification token; 1,207 carry any NIST token (nist, nist_800_171, nist_csf); 1,502 carry a CMMC token (cmmc, cmmc_l2); 2,050 carry at least one of those or a cmmc_compliance service tag. The government group is the 8,334 firms naming government, defense, federal, public_sector or aerospace among their target verticals. Certifications, services and verticals are stored as arrays for all 39,864 firms, so every share here is against the whole directory and a firm that shows nothing counts against the share. Measured 2026-09-15 in one repeatable-read snapshot against signal.mv_ranked_base, the layer this site serves.

Providers showing a NIST 800-171 credentialbase 39,864
1% Show NIST 800-171 (419)Do not show us a NIST 800-171 credential (39,445)
Providers marketing to government against the whole directory
Names government or defense
8,334 firms
Shows NIST 800-171
4.2%
Shows any NIST or CMMC signal
16.3%
Shows any certification
27.7%
Median headcount
15
Whole directory
39,864 firms
Shows NIST 800-171
1.1%
Shows any NIST or CMMC signal
5.1%
Shows any certification
15.6%
Median headcount
9
NIST 800-171 rate, among the eight states with the most holders% of that state's providers
Maryland2.75% of that state's providers
Virginia2.51% of that state's providers
Colorado1.64% of that state's providers
California1.43% of that state's providers
Massachusetts1.37% of that state's providers
Florida1.16% of that state's providers
Texas0.85% of that state's providers
New York0.79% of that state's providers

The published statistic behind this

HIPAA is the most frequently published credential among IT service providers at 3,345 firms, ahead of CMMC at 1,522 and PCI DSS at 1,493.

n = 6,319 providers publishing at least one credential · measured 2026-09-17. The figures on this page are frozen at their own measurement date and are not recomputed from that table.

Certification prevalence

1.1% of the market shows the credential

419 of 39,864 published US providers show a NIST 800-171 credential. 39,445 do not. Widen it as far as the data allows — any NIST token, any CMMC token, or a CMMC compliance service tag — and the group reaches 2,050 firms, or 5.1%. On the widest reading available, 94.9% of the market shows a buyer nothing that maps to the federal control set.

That is thin even against a market that is thin on credentials generally. 6,216 firms, or 15.6%, show a certification of any kind, so 800-171 is claimed by roughly one provider in fifteen of those that show anything at all. The individual pieces: 1,502 firms show CMMC, 1,207 show some NIST framework, and 78 name CMMC compliance as a service line rather than as a credential.

This is a measure of what providers publish, not of what they have implemented. A firm that has done the 800-171 work and never says so is counted in the 98.9%. That cuts one way for the buyer, though: a credential you cannot find before the first call is not doing the job a credential exists to do.

The providers chasing the work are not the ones showing the standard

8,334 providers — 20.9% of the directory — name government, defense, federal, public sector or aerospace among the markets they serve. 347 of those 8,334 show a NIST 800-171 credential. 7,987 do not: 95.8% of the providers marketing themselves to the buyers for whom this standard is a contract term.

The group is genuinely more credentialed than the market around it, and it is worth saying so plainly. A government-targeting provider is four times as likely to show 800-171 as a typical firm here (4.2% against 1.1%), three times as likely to show any NIST or CMMC signal (16.3% against 5.1%), and nearly twice as likely to show a certification of any kind (27.7% against 15.6%). It is also a bigger business: a median of 15 staff over the 7,248 that publish a headcount, against a directory median of 9 over 31,747.

None of that closes the gap. 6,022 of the 8,334 — 72.3% — show no certification whatsoever while naming public-sector work as a market they want. The shortage is not of providers willing to serve the sector. It is of providers willing to publish the thing the sector's contracts ask about.

1,158 providers claim CMMC without naming the standard underneath it

CMMC Level 2 is assessed against the security requirements in NIST SP 800-171; the Department of Defense built the program on that control set rather than a new one. So the two claims are close to the same claim, and how firms publish them is revealing.

1,502 providers show a CMMC token. Only 344 of them also show 800-171 — 22.9%. The other 1,158, or 77.1%, show CMMC and never name the standard it is assessed against. Read the other way, 344 of the 419 firms showing 800-171 also show CMMC, so 82.1% of the 800-171 group treats the two as a pair while the CMMC group mostly does not.

The likeliest explanation is marketing rather than capability: CMMC is the acronym buyers have heard, 800-171 is the document their contract cites. For a buyer that asymmetry is useful. Asking a provider which 800-171 control families they have assessed, and what sits in the plan of action, separates the firms that did the work from the firms that learned the acronym.

The credential clusters where the contracts are

By share of each state's providers, Maryland leads at 2.75% — 31 of 1,127 — and Virginia follows at 2.51%, 51 of 2,033. Both sit at roughly two and a half times the national rate of 1.05%. Colorado is third at 1.64%, 14 of 853.

The states with the most providers are unremarkable on this measure. California has the most holders in absolute terms, 55, but that is 1.43% of its 3,858 firms — the largest provider base in this chart carrying a rate barely above the national one. Texas, with 3,514 providers, shows 30, or 0.85%, and New York 16 of 2,014, or 0.79%. Both sit below the national rate, and Texas alone has more providers than Maryland and Virginia combined.

That pattern follows federal contracting rather than anything about IT. The 800-171 credential is concentrated in the states where defense and civilian agency work is concentrated, which is a reasonable sanity check on the measurement: a credential tied to federal contracts should cluster around federal contracts, and it does.

What this number can't tell you

  • ·This measures what providers publish about themselves, not what they have implemented or been assessed against. A provider that meets NIST 800-171 and never names it is counted in the 98.9%.
  • ·Certification tokens are matched exactly against a controlled vocabulary, not by substring. The 800-171 group is the nist_800_171 token alone; the wider NIST group unions nist, nist_800_171 and nist_csf; the CMMC group unions cmmc and cmmc_l2. Matching loosely on "nist" or "171" would pull in unrelated strings, and counting a single spelling would understate each group.
  • ·Certifications are stored as an array for all 39,864 published firms, so unlike several older cards on this site these shares are not floors from partial field coverage. They remain floors in the other sense: a firm that holds a credential and does not publish it is indistinguishable here from one that does not hold it.
  • ·The government group is defined by self-declared target verticals — government, defense, federal, public_sector or aerospace. It mixes federal contracting with state, municipal and school-district work. NIST 800-171 governs controlled unclassified information in federal contracts, so it is not a contract requirement for every firm in that 8,334, and the 95.8% should be read as a publication gap across a broad group rather than as 7,987 firms out of compliance.
  • ·That CMMC Level 2 is assessed against the NIST SP 800-171 control set is an external fact about the Department of Defense program, not something measured here. Only the token counts are ours.
  • ·The state chart shows the rate within each state among the eight states holding the most 800-171 credentials. It is not the eight highest rates in the country — a small state with few providers and two holders would outrank Maryland and is not shown.
  • ·Median headcount is over the firms in each group that publish one — 7,248 of the 8,334 government-targeting firms and 31,747 of the whole directory — and self-published headcounts are not audited.
  • ·State counts are provider headquarters, not the places a provider serves or holds contracts in.
  • ·Rating values are not plotted anywhere in this card. google_rating bunches at the top of its range, so a percentile of it would mislead; where visibility is mentioned it is the share of firms with any rating, not the rating itself.
  • ·Measured at a base of 39,864 published firms on 2026-09-15. Older cards on this site are frozen at earlier bases — 39,722 for the 2026-09-11 cohort and 39,351 for 2026-09-03 — and were not rebased for this one. A card's base is stated on its own face by design.

What to do about it

  • Buying federal or defense-adjacent work: 20.9% of this market says it serves government and 4.2% of those show 800-171, so the vertical claim narrows almost nothing. Ask for the System Security Plan, the current SPRS score, and which of the 800-171 control families sit unresolved in the plan of action. A provider that has done the work can answer all three in a sentence.
  • Buying from a provider that shows CMMC: 1,158 firms show CMMC without naming 800-171. Ask which level, assessed by whom, and on what date — CMMC covers self-assessment and third-party assessment, and those are different assurances.
  • Selling into the public sector: 6,022 of the 8,334 providers naming this market show no certification at all. Publishing an 800-171 status and an SPRS score puts a firm in the 4.2% before a buyer has read a word of the sales copy, and it is the cheapest differentiator available in a market where 95.8% of the competition is silent on it.

Questions this finding answers

How many US MSPs can show a NIST 800-171 credential?
8,334 US providers name government, defense or the public sector as a market they serve. 347 of them show a NIST 800-171 credential. The standard is the one flowed down to those buyers' suppliers, and 7,987 providers chasing that work do not name it.
How was this measured?
n = 39,864 published US providers. 419 carry a nist_800_171 certification token; 1,207 carry any NIST token (nist, nist_800_171, nist_csf); 1,502 carry a CMMC token (cmmc, cmmc_l2); 2,050 carry at least one of those or a cmmc_compliance service tag. The government group is the 8,334 firms naming government, defense, federal, public_sector or aerospace among their target verticals. Certifications, services and verticals are stored as arrays for all 39,864 firms, so every share here is against the whole directory and a firm that shows nothing counts against the share. Measured 2026-09-15 in one repeatable-read snapshot against signal.mv_ranked_base, the layer this site serves.
What can't this number tell you?
This measures what providers publish about themselves, not what they have implemented or been assessed against. A provider that meets NIST 800-171 and never names it is counted in the 98.9%.

Where does your firm sit on this?

Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.

Claim your MSP ▸

Related markets

More findings

◂ All 39 findings