Compliance & StandardsGlossary

What Is NIST SP 800-171?

Also known as: NIST 800-171, SP 800-171

Definition

NIST SP 800-171 is the National Institute of Standards and Technology publication that defines the security requirements for protecting Controlled Unclassified Information in nonfederal systems, and it is the technical baseline behind DFARS 252.204-7012 and CMMC Level 2.

NIST SP 800-171 Explained

The publication exists to answer a narrow question: when the federal government hands sensitive but unclassified information to a private company, what must that company do to protect it? Rather than impose the full federal control catalog of NIST SP 800-53, 800-171 tailors it down to the requirements that address confidentiality of CUI in a nonfederal environment. Revision 2, published in early 2020, organizes 110 security requirements into 14 families including access control, audit and accountability, configuration management, identification and authentication, incident response, and system and communications protection.

Each requirement is written as a capability rather than a product. Requirement 3.5.3 calls for multifactor authentication for local and network access to privileged accounts and network access to nonprivileged accounts; it does not name a vendor. This flexibility is genuine but it shifts burden onto the contractor to document how a given implementation satisfies the intent. The System Security Plan is where that mapping lives, and assessors spend most of their time comparing SSP claims against configuration evidence and log output.

DoD scores implementation numerically. Starting from 110, each unimplemented requirement subtracts 1, 3, or 5 points depending on its assessed impact, producing a score that can fall as low as negative 203. That score is posted in the Supplier Performance Risk System under DFARS 252.204-7019 and 7020. Multifactor authentication, FIPS-validated cryptography, and audit logging carry 5-point weights, which is why a company can implement most requirements and still post a badly negative score.

Revision 3, released in May 2024, restructures the document: families expand to 17, some requirements are withdrawn or merged, organization-defined parameters appear throughout, and the total requirement count drops modestly while several requirements become more demanding. Adoption is not automatic - the contractual baseline follows what DFARS and the CMMC rule reference, and DoD has anchored to Revision 2 during the CMMC rollout. Contractors should track which revision their specific contract clause invokes rather than assuming the newest publication governs.

The companion assessment methodology in NIST SP 800-171A defines assessment objectives, and NIST SP 800-172 adds enhanced requirements for defending against advanced persistent threats, which feed CMMC Level 3. A persistent misconception is that 800-171 protects only IT systems. It applies to any system that processes, stores, or transmits CUI, which in a manufacturing environment reaches CNC controllers holding controlled programs, CMM inspection workstations, engineering file servers, and the ERP database itself.

Why It Matters

  • It is the technical content behind both DFARS 252.204-7012 and CMMC Level 2, so implementing it once satisfies the substance of both obligations.
  • The weighted SPRS score is visible to contracting officers and primes, making it a de facto qualification criterion during source selection.
  • Requirements reach operational technology such as CNC controllers and inspection workstations, not just corporate laptops and email.
  • Documented, current System Security Plans and POA&Ms are the artifacts assessors examine first, and their absence stalls assessments regardless of actual security posture.

In Practice

Score arithmetic explains a lot of surprise. A supplier implemented 101 of 110 requirements and expected a score near 100. The nine gaps included multifactor authentication, FIPS-validated encryption at rest, and audit record review - all 5-point items - plus several 3-point items, producing a posted score in the low 60s. Prioritizing by weight rather than by count moved them above 100 in one quarter without touching most of the remaining backlog.

Frequently Asked Questions

How many controls are in NIST SP 800-171?

Revision 2 contains 110 security requirements grouped into 14 families. Revision 3, published in 2024, reorganizes the material into 17 families with a slightly different requirement count and introduces organization-defined parameters. Defense contracts currently anchor to the revision named in the applicable DFARS clause, which for most active contracts remains Revision 2.

Is NIST SP 800-171 the same as CMMC?

No, but they are tightly coupled. NIST SP 800-171 is the set of security requirements. CMMC is the DoD program that verifies those requirements are actually implemented. CMMC Level 2 maps to all 110 requirements of SP 800-171, so a contractor that genuinely meets 800-171 has already done the technical work CMMC Level 2 assesses.

Working with NIST SP 800-171 in a live environment? Our engineers do this every day - and our AI agents automate most of it.