NIST SP 800-171
A practical introduction to NIST SP 800-171, including who must protect Controlled Unclassified Information, which revision your contract points to, how self-assessments and DoD assessments work, and what compliance takes.
federal · defense
What is NIST SP 800-171
NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, is the security requirement set the federal government points to when it hands sensitive but unclassified information to a contractor and expects it to be protected on the contractor’s own systems. It is written by the National Institute of Standards and Technology (NIST), and it is a slimmed-down, confidentiality-focused subset of the controls federal agencies apply to their own systems under NIST SP 800-53.
The publication exists because Controlled Unclassified Information (CUI) leaves the government constantly: engineering drawings, export-controlled technical data, personnel records, law-enforcement data, and contract deliverables. The CUI Program, run by the National Archives and Records Administration (NARA) under Executive Order 13556 and 32 CFR Part 2002, needed one consistent bar for every agency to require of contractors instead of dozens of agency-specific clauses.
Two revisions matter today. Revision 3 (May 14, 2024) is the current NIST publication. Revision 2 (February 2020) is the one most contracts actually cite, because the Department of Defense pinned its contracts to Rev. 2 and its CMMC program assesses against it. Which one applies to you is decided by your contract, not by NIST’s publication date.
The most common misconception: there is no such thing as being “NIST 800-171 certified.” NIST does not certify, audit, or keep a list. SP 800-171 is a requirements document that becomes binding only when a contract clause says so, and how you prove compliance is set by that clause.
Who NIST SP 800-171 applies to
SP 800-171 applies to a nonfederal organization when:
- a federal contract, grant, or agreement includes a clause requiring it (for defense work, DFARS 252.204-7012; other agencies use their own clauses);
- the organization processes, stores, or transmits CUI on systems it owns or operates, rather than only inside a government system; and
- the requirement flows down from a prime contractor to a subcontractor that will receive CUI.
The surprise case is the subcontractor two or three tiers down. A machine shop that receives a marked drawing, an engineering firm that reviews a specification, or a managed service provider that administers a defense contractor’s network can all be in scope without ever signing a contract with the government. If a prime’s purchase order carries the clause and CUI arrives, the requirement arrived with it.
Company size does not exempt anyone. What changes with size and contract is the assessment type: whether you self-assess, whether DoD may assess you, and whether a contract requires third-party certification under CMMC. What does not change is the requirement to implement the controls.
If you hold only Federal Contract Information (FCI) and no CUI, SP 800-171 does not apply; the 15 basic safeguarding requirements in the FAR (formerly 52.204-21) do. Telling FCI from CUI is the first job, and the CMMC page covers the markings and contract signals to look for.
Who manages and enforces NIST SP 800-171
Three parties, with distinct roles:
NIST writes it. The publication and its companion assessment guide, SP 800-171A, live on the NIST Computer Security Resource Center. NIST publishes revisions on its own schedule and does not decide when agencies must adopt them.
NARA defines CUI. The CUI Registry lists every category of CUI and the law or policy behind it. 32 CFR Part 2002 requires agencies to impose SP 800-171 on contractor systems that handle CUI, which is the legal reason the clauses exist.
Agencies impose and enforce it, through contracts. For the Department of Defense, that is DFARS 252.204-7012, in contracts since 2016 with a compliance deadline of December 31, 2017. DoD later added scored assessments (the DoD Assessment Methodology, with results posted to the Supplier Performance Risk System, SPRS) and, from November 2025, the CMMC program, which makes a verified SP 800-171 assessment a condition of award. Other agencies use SP 800-171 in their own clauses today, and the FAR Council has proposed a government-wide clause that would standardize it (see the version note below).
Enforcement is contractual and, for false statements, legal. A contractor that cannot show implementation can lose eligibility for awards, face contract remedies, and, if it certified compliance it did not have, face False Claims Act liability; the Department of Justice has settled such cases. There is no fine schedule in SP 800-171 itself.
Which revision applies, and who decides
- DoD contracts: Rev. 2. DoD Class Deviation 2024-O0013 (May 2024) directs contracting officers to require Rev. 2 rather than the version in effect at solicitation. CMMC Level 2 is codified against Rev. 2. Since February 1, 2026, a further class deviation replaced the DoD assessment clauses 252.204-7019 and 7020 with 252.240-7997, dropping the stand-alone requirement to upload a Basic self-assessment score while keeping DoD Medium and High assessments; CMMC self-assessments and affirmations in SPRS are unchanged.
- Civilian agencies: whatever the clause says. The FAR Council’s proposed government-wide CUI rule (FAR Case 2026-001, June 23, 2026) would require Rev. 3 for contractor systems; it is not final. See our coverage.
- Your contract: read the clause and any deviation it cites. When in doubt, ask the contracting officer or prime in writing.
What is in scope
SP 800-171 scopes to the system: the components that process, store, or transmit CUI, and the components that provide security for them. The word “system” is deliberately broad. It reaches:
- Where CUI lives and moves: file shares, email, engineering and ERP systems, collaboration tools, backups, printers, and removable media.
- What protects those places: identity systems, firewalls, endpoint tools, logging platforms, and the administrators’ own workstations.
- People: anyone with access to CUI or to the systems that protect it, including contractors and managed service provider staff.
- External services: cloud platforms and service providers that store or process CUI. DoD contracts require cloud services handling covered defense information to meet the FedRAMP Moderate baseline or equivalent, and CMMC scoping pulls those providers into your assessment.
A scope exercise you can run this week:
- Pull every active contract and purchase order and find the safeguarding clauses.
- Ask each contracting officer or prime whether CUI is delivered under it and how it is marked.
- Trace where that CUI enters, is stored, is worked on, is emailed, and is backed up.
- List every system, cloud service, and person on that path.
- Draw the boundary and record what sits outside it and why.
Most contractors reduce scope with an enclave: a segregated environment (a dedicated network segment, a government-community cloud tenant, or a virtual desktop) where all CUI work happens. Enclaves cut the number of systems assessed and are the norm for smaller contractors. They do not remove obligations inside the enclave, and they fail when CUI leaks to personal devices or the corporate email system. The enclave-versus-enterprise decision is one of the first to make, and it drives the cost of everything after it.
What NIST SP 800-171 requires
The requirements are organized into families that mirror SP 800-53. In Revision 2, the version DoD contracts require, there are 110 requirements in 14 families:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
Revision 3 consolidates and realigns the same ground to SP 800-53 Rev. 5: 97 requirements in 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management, and introducing organization-defined parameters (ODPs), blanks the imposing agency fills in (how often to review accounts, how long to keep logs). Fewer numbered requirements does not mean less work; several Rev. 2 requirements were merged into multi-part Rev. 3 requirements.
Both revisions expect a System Security Plan (SSP) describing how each requirement is met and a Plan of Action and Milestones (POA&M) for any that are not. Under DoD’s assessment methodology, the SSP is not optional: without one, the assessment cannot be completed at all.
The documents that matter, and how much weight each carries:
- NIST SP 800-171 Rev. 3 and Rev. 2 are the requirements. Read the one your contract cites. Both are free.
- NIST SP 800-171A is the assessment guide: the objectives an assessor checks for each requirement (320 of them under Rev. 2). It governs the assessor, but reading it tells you exactly what “implemented” means.
- The DoD Assessment Methodology assigns each Rev. 2 requirement a weight of 1, 3, or 5 points. A perfect score is 110; unimplemented requirements subtract their weight, so the floor is -203. This is the number DoD sees in SPRS.
- 32 CFR Part 170 (the CMMC Program rule) and DFARS 252.204-7012 are the DoD rules that make all of the above binding, including the 72-hour cyber incident reporting requirement in 7012.
- NIST SP 800-172 adds enhanced requirements for critical programs; it applies only when a contract says so (CMMC Level 3).
SP 800-171 allows an agency to approve alternative but equally effective measures and to adjudicate requirements as not applicable; under DFARS 7012 those requests go through the contracting officer to the DoD CIO. That is a formal path, not a self-declared exception.
How compliance is validated
SP 800-171 has no certificate of its own. How you prove implementation depends entirely on the clause:
Self-assessment and the SSP
The baseline everywhere is a self-assessment documented in the SSP and POA&M, using SP 800-171A’s objectives. For DoD, you score it with the Assessment Methodology. Under the CMMC clause, a Level 2 self-assessment is that same assessment, entered in SPRS and affirmed annually by a senior official; the affirmation is a legal statement, which is where False Claims Act exposure comes from. Conditional status with a POA&M is allowed only for a limited set of lower-weight requirements and must be closed within 180 days.
Government assessments
DoD’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) performs Medium assessments (a review of your SSP) and High assessments (an on-site or virtual verification of evidence) at DoD’s discretion. Their scores post to SPRS and override your own. DIBCAC also performs CMMC Level 3 assessments.
Third-party certification (CMMC)
For DoD contracts that require it, an authorized CMMC Third-Party Assessment Organization (C3PAO) assesses your Rev. 2 implementation and certification status posts to SPRS, valid for three years with annual affirmations. Find authorized C3PAOs in the Cyber AB marketplace. As of July 13, 2026, DoD has suspended the rollout phase that would have required C3PAO assessments in more contracts; self-assessment requirements remain in force. See the CMMC page for how levels, assessments, and the rollout fit together.
What a result is, and is not
Every one of these is a point-in-time record of a specific system boundary. A score in SPRS, a DIBCAC result, or a CMMC certificate describes the scoped environment on the assessment date. Add a site, move CUI to a new tool, or drop a control and the record no longer describes you, whatever the expiry says. Anyone selling an “800-171 certificate” outside these mechanisms is selling paper.
The NIST SP 800-171 compliance process
A first cycle usually runs:
- Confirm the obligation. Identify every contract with a safeguarding clause, which revision it requires, and what assessment type and reporting it demands.
- Find the CUI and draw the boundary. Trace flows, decide enclave or enterprise, and list systems, services, and people inside.
- Assess each requirement against SP 800-171A’s objectives. Record implemented, partially implemented, or not implemented, with evidence.
- Write the SSP and POA&M. The SSP describes how each requirement is met; the POA&M lists gaps with owners and dates.
- Remediate, closing high-weight gaps first if DoD scoring applies.
- Score and report whatever the contract requires: the DoD Assessment score and CMMC status in SPRS, or an agency-specific attestation.
- Maintain. Update the SSP with every change, run recurring controls, and calendar the annual affirmation.
Who decides, and what to ask them
Your real obligation is set by whoever wrote the clause into your contract: for a prime, the contracting officer; for a subcontractor, the prime’s contracts or supplier-security team, which is passing down its own obligation. Their name is on the contract or purchase order. If the ask arrived as a supplier questionnaire, the questionnaire’s sender is the right first contact.
Ask, and keep the answers in writing:
- Does this contract deliver CUI to us, or only FCI? How will it be marked, and which CUI categories?
- Which clause and revision apply (DFARS 7012 with the Rev. 2 deviation, a CMMC clause and level, an agency clause citing Rev. 3), and which assessment type: self, DIBCAC, or C3PAO?
- What must be posted or delivered, where, and by when: a score in SPRS, a CMMC status, an affirmation, an SSP on request?
- Are POA&Ms acceptable at award, and for how long?
- Which cloud services we use must meet FedRAMP Moderate or equivalent, and will they accept a provider’s attestation?
- What happens if we cannot meet a requirement: is there a path to request an alternative measure or non-applicability?
Answers differ between primes and between agencies, and the written one is the one that counts.
Reality check: scoping and remediation consume the calendar. Writing an SSP for an already-controlled enclave takes weeks; building the enclave, moving CUI into it, and standing up logging, multifactor authentication, and encryption takes months. DoD’s own estimate for implementing the requirements at a small business is well over a thousand staff hours in the first year.
Cost, time, and internal effort
SP 800-171 has no assessor fee for the most common path. Most contracts are satisfied by a self-assessment, so this page carries no headline cost range; the effort meter and the scenarios below do the work instead.
What the paths cost:
- Self-assessment: internal time only. DoD models the assessment and affirmation activity for a Level 2 self-assessment at about $34,000 over three years for a small entity, which is labor, not a fee.
- Readiness or gap assessment from a consultant: commonly $3,500 to $20,000, scaling with headcount, sites, and how much of an SSP already exists.
- DIBCAC Medium or High assessment: no fee, at DoD’s initiative.
- CMMC Level 2 C3PAO certification, where a DoD contract requires it: roughly $30,000 to $60,000 for the assessor, covered in How much does CMMC cost?
The larger number is almost always implementation, which sits outside every figure above. The government’s own model for a small business implementing Rev. 2 from a typical starting point is about 1,560 staff hours plus $27,500 in hardware and software in the first year, then roughly 1,040 hours and $5,000 a year to maintain. Industry ranges for outsourced help put SSP, POA&M, and policy writing at $12,000 to $60,000 and remediation anywhere from $10,000 to several hundred thousand, depending on what has to be built.
The page’s effort range is directional, not a quote. The best predictors are whether an enclave can contain the CUI, how far your identity, logging, and endpoint controls already are from the requirements, and how many cloud and managed services touch CUI.
Time follows the same pattern. A contractor with an existing enclave and mature controls can complete a credible self-assessment in one to two months. A first implementation at a company with no segregation and no SSP is commonly a six-to-eighteen-month project.
Maintaining compliance
The clause does not stop applying after the SSP is written. Recurring work, drawn from the requirements themselves and the DoD reporting rules:
- Keep the SSP current. Every system, vendor, or process change inside the boundary should update it; assessors read the SSP first.
- Work the POA&M. Closed items need evidence; new gaps get dates and owners.
- Run the periodic controls: vulnerability scanning and remediation, log review, account and privilege reviews, awareness training, and at least annual risk assessment and control assessment (requirements 3.11 and 3.12 in Rev. 2). The free risk assessment tool on this site produces a risk register in the browser without sending data anywhere, which covers the documented risk assessment many small contractors lack.
- Affirm annually in SPRS for every CMMC status you hold, and re-score if anything material changed.
- Report incidents affecting covered defense information to DoD within 72 hours under DFARS 7012, and preserve images and logs for 90 days.
- Watch the revision. A move from Rev. 2 to Rev. 3 in your contracts changes numbering, adds families, and introduces parameters your SSP must state.
Scope changes silently: a new engineering tool, a new subcontractor receiving drawings, a new office, or a help-desk vendor with admin rights. Put a CUI question into procurement, onboarding, and change management so the boundary is reviewed before the assessor, or the incident, finds the gap.
How to get started
If SP 800-171 has just landed on your desk, begin with five concrete actions:
- Confirm the obligation in writing. Ask your contracting officer or prime whether CUI is delivered, which clause and revision apply, and what must be reported where and by when.
- Find the CUI. Trace where marked information enters, is worked on, and is stored, including email and backups. If you cannot find any, ask again; the answer may be FCI only.
- Decide enclave or enterprise. Draw the boundary around the smallest environment that can realistically hold all CUI work.
- Assess and write the SSP. Walk the 110 Rev. 2 requirements (or the 97 in Rev. 3 if your clause says so) against SP 800-171A’s objectives, record evidence, and list gaps in a POA&M. If DoD scoring applies, compute the score; it will be lower than you expect.
- Fix the heavy items first. Five-point requirements (multifactor authentication, encryption of CUI, patching, logging) move the score most and are what DIBCAC and C3PAOs test hardest.
For official starting points, use NIST’s SP 800-171 page for the publication and assessment guide, the DoD CIO CMMC documentation for the scoring methodology and scoping guidance, and the NARA CUI Registry to identify categories and markings.
The first goal is not 110 implemented requirements. It is knowing which contracts deliver CUI, where that CUI actually lives, and what your contract wants you to report. Once those three facts are written down, the SSP is a documentation project and the gaps are a budget line, not a mystery.
Version history
| Version | Status | Released | Effective | Retired | Summary |
|---|---|---|---|---|---|
| Rev. 3 | current | May 14, 2024 | May 14, 2024 | n/a | Realigned to SP 800-53 Rev. 5. 97 requirements in 17 families, new organization-defined parameters, and a companion SP 800-171A Rev. 3. DoD contracts continue to require Rev. 2 under a class deviation; a proposed FAR clause (June 2026) would require Rev. 3 government-wide. |
| Rev. 2 | current | Feb 21, 2020 | Feb 21, 2020 | n/a | 110 requirements in 14 families. Still the revision required by DFARS 252.204-7012 (Class Deviation 2024-O0013) and assessed by CMMC Level 2. Scored with the DoD Assessment Methodology and SP 800-171A (320 assessment objectives). |
| Rev. 1 | retired → Rev. 2 | Dec 20, 2016 | Dec 31, 2017 | Feb 21, 2020 | The revision most contractors first implemented to meet the DFARS 252.204-7012 deadline of December 31, 2017. Added the System Security Plan and POA&M as explicit expectations. |
| Original | retired → Rev. 1 | Jun 18, 2015 | Jun 18, 2015 | Dec 20, 2016 | First publication, written at the request of the CUI Program to give agencies a consistent set of confidentiality requirements for contractor systems. |
New versions are announced in news. Follow this standard to get notified.