What Is NIST Special Publication 800-171?

Also called: NIST SP 800-171, NIST 800-171

Related problems: A government contract says we must protect controlled unclassified information; Need a system security plan and an assessment score for a defense customer; Not sure which of our systems and providers handle CUI

NIST Special Publication 800-171 is a US National Institute of Standards and Technology publication that sets the security requirements for protecting controlled unclassified information (CUI) when it is held outside the federal government, such as by contractors, suppliers, universities and service providers. CUI is government information that needs protection but is not classified. Federal contracts, most visibly Defense Department contracts, require organizations that handle CUI to meet these requirements. This entry is general information, not legal advice; confirm what applies to you with your contracting officer, counsel or assessor.

At a glance

  • It is a requirements catalog for CUI in nonfederal systems, grouped into families such as access control, incident response and media protection.
  • Contracts make it mandatory; NIST itself does not enforce or certify.
  • Defense contractors document their implementation in a system security plan and track gaps in a plan of action.
  • CMMC Level 2 verifies these requirements for defense contracts.
  • More than one revision exists; your contract determines which one you are measured against.

What problem it solves

The government shares sensitive information with thousands of private companies to get work done: drawings, specifications, logistics data, research results. Once that information leaves government systems, it needs a consistent minimum level of protection, or the weakest supplier becomes the easiest target.

NIST SP 800-171 gives that minimum. It tells a contractor what safeguards to have in place, in terms that fit a commercial IT environment, so a 200-person machine shop and a large integrator are measured against the same baseline. For buyers, it also sets clear expectations for cloud, email and managed service providers that will touch CUI.

How it works

Identify CUI and scope. The organization finds where CUI is stored, processed and transmitted, and which systems, people and providers can reach it. Many organizations isolate CUI in an enclave to reduce scope.

Implement requirements. Requirements cover areas such as access control, awareness training, audit logging, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

Document. A system security plan describes the environment and how each requirement is met; a plan of action lists gaps and target dates.

Assess and report. Defense contractors assess against the requirements using a standard scoring method and report results in Defense Department systems; under CMMC, some contracts require a third-party or government assessment.

Use providers carefully. Under Defense Department contracts that include DFARS 252.204-7012, external cloud providers that store, process or transmit covered defense information are expected to meet security requirements equivalent to the FedRAMP Moderate baseline. Other CUI contracts depend on their own agency clauses. Providers often supply a responsibility matrix.

Revisions and assessment types

NIST SP 800-171 has no levels of its own. Its structure is the revision you are measured against and how compliance is checked, shown here in general terms.

Item When it applies How it is validated Typical evidence
Revision 2 requirements Defense contracts and CMMC assessments have continued to cite this revision Self-assessment or CMMC assessment, per contract System security plan, assessment score, plan of action
Newer revision Published by NIST; adopted where a contract or agency cites it As the contract specifies System security plan mapped to the cited revision
Self-assessment Contracts that accept a self-assessment Contractor scores itself using the standard method Score reported to the Defense Department, with affirmation
Third-party assessment (CMMC Level 2) Defense contracts that require certification Certified third-party assessment organization CMMC certificate of status
Enhanced requirements (NIST SP 800-172, CMMC Level 3) Especially sensitive programs Government assessment Government-issued status

When it matters for buyers

  • When a contract includes CUI clauses. Your environment, and providers in scope, generally need to support the requirements.
  • When choosing cloud email, file sharing or backup. For defense contracts with DFARS 252.204-7012, check FedRAMP Moderate certification or equivalency for the exact service; for others, check what your contract’s clauses require.
  • When outsourcing IT or security. An MSP with administrative access is part of your scope.
  • When building an enclave. A separate tenant or private cloud environment can limit scope and cost.
  • When ITAR or EAR data is involved. Export-control rules add where-and-who restrictions on top of these requirements.

Our governance, risk and compliance overview covers advisors and platforms that manage system security plans and assessments.

Questions to ask vendors

  • Will your service store, process or transmit our CUI, and which requirements do you meet on our behalf?
  • Which FedRAMP class, or documented FedRAMP Moderate equivalency, do you hold for the specific service we would buy?
  • Can you provide a customer responsibility matrix and supporting evidence?
  • How do you handle incident reporting to us, given our contract reporting obligations?
  • Where are our data and backups stored, and who can access them?
  • Which revision of NIST SP 800-171 do your documents map to?

How it differs from the NIST Cybersecurity Framework

The NIST Cybersecurity Framework (NIST CSF) is voluntary guidance describing security outcomes for any organization. NIST SP 800-171 is a specific set of requirements for protecting CUI, made mandatory through contracts. The CSF helps plan and communicate a whole program; 800-171 defines what a CUI environment must have in place. CMMC is how the Defense Department verifies 800-171 for its contractors, while FISMA governs security for federal agencies’ own systems. CUI that is also export-controlled brings in ITAR or the EAR.

Frequently Asked Questions

What is controlled unclassified information (CUI)?
CUI is government information that is sensitive enough to need protection under law, regulation or policy but is not classified. Examples can include certain technical, export-controlled, legal or privacy information. Your contract and the government's CUI markings tell you what is CUI.
Which revision of NIST SP 800-171 applies to us?
NIST has published a newer revision, but Defense Department contracts and CMMC assessments have continued to reference the earlier Revision 2 requirements. Check which revision your contract cites and confirm with your contracting officer or assessor.
Is there a NIST SP 800-171 certification?
Not from NIST. NIST publishes the requirements but does not certify companies. For defense contractors, the CMMC program provides self-assessment, third-party or government assessment against them, depending on the contract.
Does NIST SP 800-171 apply to companies outside defense?
It can. It applies wherever a federal contract or agreement requires nonfederal organizations to protect CUI, which includes some civilian agency contracts, research grants and universities. It is most widely enforced in the defense supply chain.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.