NIST SP 800-171 is a cybersecurity standard published by the National Institute of Standards and Technology (NIST) that establishes requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. The current mandatory version, Revision 2, contains 110 security requirements across 14 control families.
Key takeaways
- NIST SP 800-171 Revision 2 establishes 110 security requirements across 14 control families for protecting Controlled Unclassified Information (CUI) in nonfederal systems.
- Revision 2 remains the mandatory standard; NIST published Revision 3 in May 2024, but the DoD has kept Rev 2 as the compliance baseline through a class deviation, with formal transition not expected before late 2026 at the earliest.
- The Audit and Accountability and System and Information Integrity control families require operational evidence of functioning controls, not just documented policies.
- Organizations must document their 800-171 implementation in a System Security Plan (SSP) and maintain a Plan of Action and Milestones (POA&M) for any gaps.
What is Controlled Unclassified Information (CUI)?
CUI is information the US government creates or possesses that requires safeguarding under law, regulation, or government-wide policy, but isn’t classified. The term was established by Executive Order 13556 (2010) to standardize how the government and its partners handle sensitive but unclassified information. NIST SP 800-171 establishes requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems.
CUI spans categories including technical data on defense systems, personally identifiable information (PII), law enforcement sensitive information, financial data, health information, and research data. For contractors, CUI is typically identified in contracts and agreements with federal agencies.
The key distinction is that classified information requires a security clearance; CUI is sensitive but unclassified. It doesn’t require a clearance to handle, but it does require the specific protective measures that 800-171 defines.
What are the 110 NIST SP 800-171 requirements?
NIST SP 800-171 Revision 2 organizes its 110 security requirements into 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Audit and Accountability (AU) and System and Information Integrity (SI) are the families most directly supported by continuous monitoring and detection capabilities. AU requires creating, protecting, retaining, and analyzing audit logs. SI requires malicious code protection, security alert monitoring, and detection of attacks and unauthorized use. Incident Response (IR) requires an operational incident handling capability with tested procedures and documented response—a capability organizations must own and maintain as part of their own compliance program, though monitoring and detection tools can support the operational work of running it.
In each of these families, assessors test for operational evidence that controls are functioning, not just that policies exist on paper. A logging policy without active log analysis doesn’t satisfy AU requirements. A written incident response plan that hasn’t been exercised doesn’t satisfy IR requirements.
How NIST SP 800-171 assessments work
NIST SP 800-171 assessments evaluate an organization’s implementation of the 110 requirements. NIST 800-171A, a companion document, provides the specific assessment procedures—interview questions, tests, and document reviews—that assessors use to determine whether each requirement is met.
Organizations document their implementation in a System Security Plan (SSP), which describes the scope of the assessment, how each requirement is met, and where deficiencies exist. A Plan of Action and Milestones (POA&M) documents remediation plans for requirements that aren’t yet fully implemented.
For scoring, each requirement is weighted on a DoD-developed scale with a maximum of 110 points. Organizations must submit their score to the SPRS database, where DoD contracting officers can access it during source selection.
What’s the status of NIST SP 800-171 Revision 3?
NIST published Revision 3 in May 2024, restructuring the standard to align more closely with NIST SP 800-53 Rev 5. Revision 3 reduces the top-level requirement count from 110 to 97 but adds three new control families (Planning, System and Services Acquisition, and Supply Chain Risk Management) and significantly more detailed assessment criteria.
Revision 3 isn’t the compliance standard yet. The DoD issued a class deviation keeping DFARS 252.204-7012 tied to Revision 2 indefinitely, and has stated it will incorporate Revision 3 only through future rulemaking. Current estimates put that transition at late 2026 to 2027 at the earliest. Organizations should continue building toward Revision 2 today, while watching for DoD rulemaking that would set a firm Revision 3 transition timeline.
Frequently asked questions
What is NIST SP 800-171?
NIST SP 800-171 is a cybersecurity standard published by the National Institute of Standards and Technology (NIST) that establishes 110 security requirements (under the currently mandatory Revision 2) for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It applies primarily to federal contractors and defense supply chain participants who handle CUI under DFARS clause 252.204-7012.
Who needs to comply with NIST SP 800-171?
NIST SP 800-171 applies to nonfederal organizations that process, store, or transmit CUI on behalf of the federal government. This primarily includes defense contractors and subcontractors with DFARS-covered contracts, federal civilian agency contractors whose contracts involve CUI, research institutions handling federally funded CUI data, and defense industrial base supply chain participants at multiple tiers.
How many requirements are in NIST SP 800-171?
NIST SP 800-171 Revision 2, the currently mandatory version, contains 110 security requirements organized across 14 control families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.
How is NIST SP 800-171 compliance assessed?
Organizations document their implementation in a System Security Plan (SSP) and score themselves against the 110 requirements using NIST’s scoring methodology, submitting the score to the DoD’s SPRS database. NIST 800-171A provides companion assessment procedures that define what evidence satisfies each requirement.
Is NIST SP 800-171 Revision 3 in effect yet?
No. NIST published Revision 3 in May 2024, but the DoD has kept Revision 2 as the mandatory compliance standard through a class deviation and has said it will move to Revision 3 only through future rulemaking, with a transition not expected before late 2026 at the earliest. Organizations should continue implementing Revision 2 today.

