HomeGlossaryNIST SP 800-171
Glossary

What Is NIST SP 800-171?

NIST SP 800-171 sets the security requirements for Controlled Unclassified Information in contractor systems: 110 in Rev. 2, the version DoD assesses today.

Definition

What is NIST SP 800-171?

NIST SP 800-171 is the National Institute of Standards and Technology's set of security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems, such as a defense contractor's network. Revision 2 has 110 requirements in 14 families. Revision 3, published in May 2024, has 97 in 17 families, but Defense Department assessments still use Revision 2.

NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, gives federal agencies a set of recommended security requirements to write into their contracts with the companies that hold government information. CUI is information the government creates or possesses, or that a company creates or possesses for it, that a law, regulation or government-wide policy requires to be safeguarded, such as technical drawings a prime contractor marks CUI before sending them to a supplier. The requirements cover every component of a contractor's system that processes, stores or transmits CUI, plus the components that protect them. For Revision 3, NIST started from the moderate baseline of NIST SP 800-53 controls and removed those that are mainly the government's responsibility or unrelated to confidentiality.

The requirements reach private companies through contract clauses. In defense work, DFARS 252.204-7012 requires a contractor's systems to meet the version of SP 800-171 in effect when the solicitation was issued, or as the contracting officer authorizes, to report cyber incidents within 72 hours, and to use cloud services that meet requirements equivalent to the FedRAMP Moderate baseline. DFARS 252.204-7019 makes a current NIST SP 800-171 DoD Assessment, no more than three years old with its summary score posted in the Supplier Performance Risk System (SPRS), a condition of being considered for award. DFARS 252.204-7020 defines the contractor's Basic self-assessment and the Medium and High assessments the government performs. Clauses 7012 and 7020 flow down to subcontractors, and CMMC Level 2 is built on the same 110 requirements.

Revision 2, dated February 2020 with updates through January 28, 2021, holds 110 requirements in 14 families, from Access Control to System and Information Integrity. Revision 3, published in May 2024, supersedes it at NIST. It has 97 requirements in 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management, and it introduces organization-defined parameters: values such as how long an account may sit inactive before it is disabled, which the agency sets or, where the agency does not, the contractor must set. The Defense Department has not moved to Revision 3. As of October 1, 2026, the DoD CIO's CMMC pages say the Department enforces NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments, and the CMMC rule at 32 CFR Part 170 incorporates Revision 2 by reference.

Three documents carry most of the weight. The system security plan (SSP), requirement 3.12.4 in Revision 2, describes the system boundary, its environment and how each requirement is implemented. The plan of action and milestones (POA&M) answers requirement 3.12.2 by listing each gap and the date it will be closed. The SPRS score summarizes the result: under the CMMC scoring rule the maximum is 110, each requirement not met subtracts 1, 3 or 5 points, and the total can fall below zero. NetSys's CMMC compliance service maps where CUI lives, builds an enclave that meets the requirements, writes the SSP from the configuration it deployed and prepares the self-assessment score. NetSys is not a C3PAO and certifies no one.

NIST SP 800-171 vs NIST SP 800-53 vs CMMC Level 2

How the three relate, as of October 1, 2026
NIST SP 800-171NIST SP 800-53CMMC Level 2
What it isSecurity requirements for protecting CUI in nonfederal systemsA catalog of security and privacy controls for information systems and organizationsA Defense Department program that checks contractors meet NIST SP 800-171
Who uses itContractors and subcontractors whose contracts involve CUIFederal agencies, where it is mandatory; FedRAMP cloud providers; others voluntarilyDefense contractors and subcontractors whose contracts require Level 2
Size110 requirements in 14 families (Rev. 2); 97 in 17 families (Rev. 3)20 control families, with baselines published separately in SP 800-53BThe 110 requirements of Rev. 2
Current versionRev. 3 (May 2024) at NIST; DoD enforces Rev. 2Rev. 5 (September 2020), updated to Release 5.2.0 (August 2025)32 CFR Part 170, with Phase II suspended since July 13, 2026
How it is checkedA NIST SP 800-171 DoD Assessment scored out of 110 and posted in SPRSAssessed with SP 800-53A under NIST's Risk Management FrameworkA self-assessment every three years with an annual affirmation

Why it matters for a small business

If your business makes parts, drawings or software for a defense prime, the CUI that arrives with the purchase order brings NIST SP 800-171 with it, through clauses that flow down to subcontractors. A missing or stale SPRS score can keep you out of an award whatever your price. The July 13, 2026 suspension of CMMC Phase II paused third-party certification, not the requirements: the Department still enforces Revision 2 through self-assessments and select government-led assessments. For a small firm the affordable path is a tight scope, with the CUI held in an enclave that only the few people who need it can reach, built and documented before a contract renewal depends on it.

Common Questions

NIST SP 800-171: FAQs

How many controls are in NIST 800-171?

Revision 2 has 110 security requirements in 14 families, and Revision 3 has 97 in 17 families. NIST calls them requirements rather than controls because each is drawn from NIST SP 800-53 controls. Revision 3 withdrew or merged some Revision 2 requirements and added the Planning, System and Services Acquisition, and Supply Chain Risk Management families. Defense Department assessments still count the 110 Revision 2 requirements.

Is NIST 800-171 the same as CMMC?

No. NIST SP 800-171 is the set of security requirements, and CMMC is the Defense Department program that checks whether a contractor meets them. CMMC Level 2 covers the 110 requirements of Revision 2. Since Phase II was suspended on July 13, 2026, Level 2 is met with a self-assessment every three years and an annual affirmation, and DFARS 252.204-7012 still applies. This is general information, not legal advice.

Does NIST 800-171 apply to small businesses?

Yes, when the business handles CUI under a contract that requires it; company size is no exemption. DFARS 252.204-7012 and 252.204-7020 flow down to subcontractors, so a machine shop that receives CUI drawings from a prime must meet the requirements on the systems that touch them. Keeping CUI inside a small enclave, used by the few people who need it, is how most small firms keep the work affordable.

Which revision of NIST 800-171 does DoD use?

Revision 2. As of October 1, 2026, the DoD CIO's CMMC pages say the Department enforces NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments, and the CMMC rule incorporates Revision 2 by reference. Revision 3, published in May 2024, is NIST's current version, so read each contract's clauses before building to it, and recheck if the Department announces a change.

What is an SPRS score for NIST 800-171?

It is the summary score of a NIST SP 800-171 DoD Assessment, posted in the Supplier Performance Risk System. Under the CMMC scoring rule the maximum is 110, and each requirement not met subtracts 1, 3 or 5 points, so a score can be negative. DFARS 252.204-7019 requires a current score, no more than three years old, before an offer can be considered where 800-171 applies.

What is the difference between an SSP and a POA&M?

A system security plan (SSP) describes the system's boundary, its environment and how each requirement is implemented, while a plan of action and milestones (POA&M) lists the gaps and when each will be closed. Under the CMMC rule the SSP must exist at assessment and cannot sit on a POA&M. A POA&M needs a score of at least 88 of 110, may list only one-point requirements and non-validated encryption, and must be closed within 180 days.

Handling CUI under a defense contract?

Find out how much of your business is in scope.

Tell us how controlled unclassified information arrives, who opens it and where it is stored. A NetSys engineer will sketch the enclave boundary, outline the NIST SP 800-171 gaps and explain what your self-assessment needs. We are not a C3PAO. Agreements run month to month.