NIST Special Publication 800-171 is a US National Institute of Standards and Technology publication that sets the security requirements for protecting controlled unclassified information (CUI) when it is held outside the federal government, such as by contractors, suppliers, universities and service providers. CUI is government information that needs protection but is not classified. Federal contracts, most visibly Defense Department contracts, require organizations that handle CUI to meet these requirements. This entry is general information, not legal advice; confirm what applies to you with your contracting officer, counsel or assessor.
At a glance
- It is a requirements catalog for CUI in nonfederal systems, grouped into families such as access control, incident response and media protection.
- Contracts make it mandatory; NIST itself does not enforce or certify.
- Defense contractors document their implementation in a system security plan and track gaps in a plan of action.
- CMMC Level 2 verifies these requirements for defense contracts.
- More than one revision exists; your contract determines which one you are measured against.
What problem it solves
The government shares sensitive information with thousands of private companies to get work done: drawings, specifications, logistics data, research results. Once that information leaves government systems, it needs a consistent minimum level of protection, or the weakest supplier becomes the easiest target.
NIST SP 800-171 gives that minimum. It tells a contractor what safeguards to have in place, in terms that fit a commercial IT environment, so a 200-person machine shop and a large integrator are measured against the same baseline. For buyers, it also sets clear expectations for cloud, email and managed service providers that will touch CUI.
How it works
Identify CUI and scope. The organization finds where CUI is stored, processed and transmitted, and which systems, people and providers can reach it. Many organizations isolate CUI in an enclave to reduce scope.
Implement requirements. Requirements cover areas such as access control, awareness training, audit logging, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Document. A system security plan describes the environment and how each requirement is met; a plan of action lists gaps and target dates.
Assess and report. Defense contractors assess against the requirements using a standard scoring method and report results in Defense Department systems; under CMMC, some contracts require a third-party or government assessment.
Use providers carefully. Under Defense Department contracts that include DFARS 252.204-7012, external cloud providers that store, process or transmit covered defense information are expected to meet security requirements equivalent to the FedRAMP Moderate baseline. Other CUI contracts depend on their own agency clauses. Providers often supply a responsibility matrix.
Revisions and assessment types
NIST SP 800-171 has no levels of its own. Its structure is the revision you are measured against and how compliance is checked, shown here in general terms.
| Item | When it applies | How it is validated | Typical evidence |
|---|---|---|---|
| Revision 2 requirements | Defense contracts and CMMC assessments have continued to cite this revision | Self-assessment or CMMC assessment, per contract | System security plan, assessment score, plan of action |
| Newer revision | Published by NIST; adopted where a contract or agency cites it | As the contract specifies | System security plan mapped to the cited revision |
| Self-assessment | Contracts that accept a self-assessment | Contractor scores itself using the standard method | Score reported to the Defense Department, with affirmation |
| Third-party assessment (CMMC Level 2) | Defense contracts that require certification | Certified third-party assessment organization | CMMC certificate of status |
| Enhanced requirements (NIST SP 800-172, CMMC Level 3) | Especially sensitive programs | Government assessment | Government-issued status |
When it matters for buyers
- When a contract includes CUI clauses. Your environment, and providers in scope, generally need to support the requirements.
- When choosing cloud email, file sharing or backup. For defense contracts with DFARS 252.204-7012, check FedRAMP Moderate certification or equivalency for the exact service; for others, check what your contract’s clauses require.
- When outsourcing IT or security. An MSP with administrative access is part of your scope.
- When building an enclave. A separate tenant or private cloud environment can limit scope and cost.
- When ITAR or EAR data is involved. Export-control rules add where-and-who restrictions on top of these requirements.
Our governance, risk and compliance overview covers advisors and platforms that manage system security plans and assessments.
Questions to ask vendors
- Will your service store, process or transmit our CUI, and which requirements do you meet on our behalf?
- Which FedRAMP class, or documented FedRAMP Moderate equivalency, do you hold for the specific service we would buy?
- Can you provide a customer responsibility matrix and supporting evidence?
- How do you handle incident reporting to us, given our contract reporting obligations?
- Where are our data and backups stored, and who can access them?
- Which revision of NIST SP 800-171 do your documents map to?
How it differs from the NIST Cybersecurity Framework
The NIST Cybersecurity Framework (NIST CSF) is voluntary guidance describing security outcomes for any organization. NIST SP 800-171 is a specific set of requirements for protecting CUI, made mandatory through contracts. The CSF helps plan and communicate a whole program; 800-171 defines what a CUI environment must have in place. CMMC is how the Defense Department verifies 800-171 for its contractors, while FISMA governs security for federal agencies’ own systems. CUI that is also export-controlled brings in ITAR or the EAR.
