NIST SP 800-172
NIST SP 800-172 is a publication from the National Institute of Standards and Technology (NIST) that sets out enhanced, more advanced security requirements for protecting especially sensitive Controlled Unclassified Information (CUI). It is designed as a supplement to NIST SP 800-171, meaning it is applied on top of, rather than in place of, the base requirements. Its focus is on defending against more capable threats, such as advanced persistent threats.
NIST SP 800-172 is a NIST-issued publication providing recommended enhanced security requirements intended to protect the confidentiality, integrity, and availability of the most sensitive nonfederal Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations. It functions as a supplement to NIST SP 800-171 and is not a standalone control set; the enhanced requirements are selected and applied in addition to the base 800-171 requirements, typically where the risk from advanced persistent threats warrants stronger protections. Practitioners should verify the applicable revision, as the requirements and their organization differ across versions (for example, the 2021 final publication versus the Rev. 3 draft development cycle), and should confirm the current authoritative text at NIST CSRC before relying on specific requirement content. Note that this publication provides recommended security requirements; whether and how these requirements become binding for a given organization generally depends on contractual, agency, or program-specific direction that must be confirmed against current official sources.
Why it matters
The base security requirements in NIST SP 800-171 are designed to protect Controlled Unclassified Information (CUI) in nonfederal systems, but not all CUI carries the same risk. NIST SP 800-172 exists because some CUI is sensitive enough that its compromise could cause serious harm, and because certain adversaries, particularly advanced persistent threats (APTs), bring capabilities that base-level protections are not intended to counter. For organizations handling the most sensitive CUI, the enhanced requirements provide a recommended layer of stronger protections targeted at these more capable threats.
Understanding SP 800-172 correctly matters because it is easy to misapply. It is a supplement to SP 800-171, not a replacement or a standalone control set; the enhanced requirements are meant to be selected and layered on top of the base 800-171 requirements, generally where the risk profile warrants it. Treating 800-172 as an alternative framework, or assuming that adopting it removes the obligation to meet 800-171, would misrepresent how the two publications are intended to work together.
Practitioners should also recognize that SP 800-172 provides recommended security requirements. Whether and how those requirements become binding for a specific organization generally depends on contractual, agency, or program-specific direction, which must be confirmed against current official sources. Additionally, the requirements and their organization have changed across versions, so the applicable revision should be verified before relying on specific requirement content.
Who it's relevant to
Inside SP 800-172
Common questions
Answers to the questions practitioners most commonly ask about SP 800-172.