NIST SP 800-171: Protecting Controlled Unclassified Information
NIST SP 800-171 specifies security requirements for protecting Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organizations. It is the foundational standard for any company that handles CUI as part of government contracts, particularly within the Department of Defense supply chain.
What NIST 800-171 Covers
The standard defines 110 security requirements derived from NIST SP 800-53 Moderate baseline controls, organized into 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.
Revision 3 aligned the requirements more closely with NIST SP 800-53 Rev 5 and introduced organization-defined parameters that allow tailoring to specific contexts.
Who Needs NIST 800-171
Any organization that processes, stores, or transmits CUI under a federal contract must comply with NIST 800-171. This affects hundreds of thousands of companies in the defense industrial base, including small machine shops, software developers, engineering firms, and research institutions.
DFARS clause 252.204-7012 makes compliance a contractual requirement for defense contractors. Non-defense agencies are increasingly including similar requirements in their contracts as well.
Relationship to CMMC
The Cybersecurity Maturity Model Certification (CMMC) program uses NIST 800-171 as its foundation. CMMC Level 2 directly maps to all 110 NIST 800-171 requirements. The key difference is verification — while NIST 800-171 historically relied on self-assessment, CMMC introduces third-party certification for certain contract levels.
Implementation Approach
- Identify CUI — Determine what CUI you handle and where it flows in your environment
- Scope your boundary — Define the systems and networks that process CUI
- Gap assessment — Compare current controls against all 110 requirements
- Create a System Security Plan (SSP) — Document how each requirement is met
- Develop a Plan of Action and Milestones (POA&M) — Address gaps with timelines
- Implement controls — Deploy technical and procedural safeguards
- Conduct self-assessment — Score your implementation using the NIST 800-171 DoD Assessment Methodology
- Submit score to SPRS — Report your score to the Supplier Performance Risk System
Key Requirement Families Explained
Access Control (22 requirements) — Limit system access to authorized users, processes acting on behalf of authorized users, and devices. Requirements span user account management, least-privilege enforcement, session controls, remote access restrictions, and wireless access policies. This is the most extensive family and frequently the one with the most gaps at assessment time.
Audit and Accountability (9 requirements) — Create and retain audit logs to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity. For CUI environments, log retention, log protection, and log review processes must all be formally documented and operational.
Configuration Management (9 requirements) — Establish and maintain baseline configurations for your information technology (hardware, software, firmware). Configuration management discipline prevents unauthorized changes from creating security vulnerabilities in CUI-handling systems.
Identification and Authentication (11 requirements) — Identify information system users, processes, and devices, and authenticate (prove) the identity of those users, processes, and devices. Multi-factor authentication for privileged and remote accounts is a significant requirement here, and one of the most commonly cited gaps in self-assessments.
System and Communications Protection (16 requirements) — Monitor, control, and protect communications at external and internal boundaries. This covers network segmentation, encrypted transmission of CUI, architectural separation of CUI from non-CUI systems, and denial-of-service protection.
The SPRS Score and What It Means
Organizations subject to DFARS 252.204-7012 must assess their implementation using the DoD Assessment Methodology and report a score to the Supplier Performance Risk System (SPRS). The maximum possible score is 110 points (one point per fully implemented requirement). Incomplete requirements are assigned negative values proportional to their criticality.
A score below 110 does not automatically disqualify a contractor, but contracting officers can and do use SPRS scores in source selection decisions. Organizations with low scores should expect additional scrutiny and may be required to demonstrate a credible Plan of Action and Milestones (POA&M) before award.
Falsifying SPRS scores carries significant legal risk. The Department of Justice has pursued False Claims Act cases against contractors who submitted inaccurate self-assessments. Accurate self-assessment, even with a below-110 score, is legally and strategically preferable to inflated claims.
NIST 800-171 Revision 3 Changes
Revision 3, published in 2024, introduced several notable changes:
- Aligned more closely with NIST SP 800-53 Revision 5 control language and structure
- Added organization-defined parameters to many requirements, allowing context-specific tailoring
- Introduced a small number of new requirements addressing supply chain risk, system recovery, and advanced persistent threat (APT) indicators
- Strengthened incident reporting and evidence preservation requirements
Organizations with existing SSPs based on Revision 2 should map their documentation to Revision 3 and update accordingly. CMMC assessments for Level 2 are transitioning to Revision 3 alignment.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| CUI scoping and boundary definition | $5,000 | $20,000 |
| Gap assessment | $10,000 | $40,000 |
| SSP development | $8,000 | $30,000 |
| Control implementation | $15,000 | $200,000 |
| Self-assessment preparation | $5,000 | $20,000 |
| C3PAO assessment (for CMMC Level 2) | $30,000 | $150,000 |
| Total (self-assessment path) | $43,000 | $310,000 |
Timeline: 4 to 18 months. Small defense contractors with limited IT infrastructure trend toward the lower end. Large manufacturers with complex multi-site environments take considerably longer.
How NIST 800-171 Compares to Related Frameworks
NIST 800-171 vs. CMMC Level 2 — Approximately 95% overlap. All 110 NIST 800-171 requirements are directly embedded in CMMC Level 2. The key difference is verification: NIST 800-171 relies on self-assessment; CMMC requires third-party certification for contracts involving sensitive CUI. See /frameworks/security-governance/cmmc.
NIST 800-171 vs. NIST 800-53 Moderate — About 80% overlap. 800-171 is derived from the 800-53 Moderate baseline but scoped specifically for nonfederal systems handling CUI. It is a more accessible subset for contractors who are not federal agencies.
NIST 800-171 vs. ISO 27001 — Approximately 65% overlap. ISO 27001-certified organizations have a meaningful head start on 800-171, but the CUI-specific requirements (particularly around documentation format and SPRS reporting) require additional work.
How Automation Helps
The NIST 800-171 documentation burden — SSP, POA&M, evidence records for all 110 requirements — is substantial for organizations without dedicated compliance staff. Automation tools that continuously collect evidence from your CUI environment and map it to requirement families significantly reduce the preparation time for both self-assessments and C3PAO audits.
LowerPlane supports NIST 800-171 Revision 3 as part of its 50-plus framework library. At $4,000/year entry pricing with a free tier, it provides evidence automation and SSP management tailored to defense contractor needs. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.
Frequently Asked Questions
What is CUI and how do I know if I have it? Controlled Unclassified Information is information the U.S. government requires to be safeguarded under law, regulation, or policy, but which is not classified. If your contract includes DFARS clause 252.204-7012 or your Statement of Work references CUI, you almost certainly handle it. The National Archives CUI Registry lists all recognized CUI categories.
Do subcontractors need to comply with NIST 800-171? Yes. Prime contractors are responsible for flowing down NIST 800-171 requirements to subcontractors who handle CUI. If you receive CUI from a prime, you have the same compliance obligations as the prime. This affects every tier of the defense supply chain.
What happens if I fail to report my SPRS score? Failing to submit a SPRS score when required is a contractual violation under DFARS 252.204-7020. Contracting officers cannot award or continue certain contracts without an active SPRS submission. Reporting an honest score below 110, with a credible POA&M, is far better than no submission.
Is NIST 800-171 Revision 3 retroactive? Existing contracts referencing specific revision numbers are not automatically updated. New contracts and contract renewals will reference the current revision. Review your contract language to determine which revision applies to your obligations.