Who said rely on that alone?
Anyway, if a company in the US is doing defense work, compliance to NIST 800-171 is required per DFARS 252.204-7012, and some customers may flow down additional requirements. In my company, our IT manager is the expert and responsible for ensuring compliance. In a smaller company I worked for in the past, we contracted an outside expert.