Skip to main content
Category: NIST Standards & Publications

NIST SP 800-172

Also known as: SP 800-172, NIST Special Publication 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information, 800-172
Simply put

NIST SP 800-172 is a publication from the National Institute of Standards and Technology (NIST) that sets out enhanced, more advanced security requirements for protecting especially sensitive Controlled Unclassified Information (CUI). It is designed as a supplement to NIST SP 800-171, meaning it is applied on top of, rather than in place of, the base requirements. Its focus is on defending against more capable threats, such as advanced persistent threats.

Formal definition

NIST SP 800-172 is a NIST-issued publication providing recommended enhanced security requirements intended to protect the confidentiality, integrity, and availability of the most sensitive nonfederal Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations. It functions as a supplement to NIST SP 800-171 and is not a standalone control set; the enhanced requirements are selected and applied in addition to the base 800-171 requirements, typically where the risk from advanced persistent threats warrants stronger protections. Practitioners should verify the applicable revision, as the requirements and their organization differ across versions (for example, the 2021 final publication versus the Rev. 3 draft development cycle), and should confirm the current authoritative text at NIST CSRC before relying on specific requirement content. Note that this publication provides recommended security requirements; whether and how these requirements become binding for a given organization generally depends on contractual, agency, or program-specific direction that must be confirmed against current official sources.

Why it matters

The base security requirements in NIST SP 800-171 are designed to protect Controlled Unclassified Information (CUI) in nonfederal systems, but not all CUI carries the same risk. NIST SP 800-172 exists because some CUI is sensitive enough that its compromise could cause serious harm, and because certain adversaries, particularly advanced persistent threats (APTs), bring capabilities that base-level protections are not intended to counter. For organizations handling the most sensitive CUI, the enhanced requirements provide a recommended layer of stronger protections targeted at these more capable threats.

Understanding SP 800-172 correctly matters because it is easy to misapply. It is a supplement to SP 800-171, not a replacement or a standalone control set; the enhanced requirements are meant to be selected and layered on top of the base 800-171 requirements, generally where the risk profile warrants it. Treating 800-172 as an alternative framework, or assuming that adopting it removes the obligation to meet 800-171, would misrepresent how the two publications are intended to work together.

Practitioners should also recognize that SP 800-172 provides recommended security requirements. Whether and how those requirements become binding for a specific organization generally depends on contractual, agency, or program-specific direction, which must be confirmed against current official sources. Additionally, the requirements and their organization have changed across versions, so the applicable revision should be verified before relying on specific requirement content.

Who it's relevant to

Contractors and organizations handling high-sensitivity CUI
Nonfederal organizations that store, process, or transmit especially sensitive CUI may be directed to implement the enhanced requirements in addition to their existing NIST SP 800-171 obligations. These organizations should confirm, through the applicable contract or program direction, whether 800-172 requirements apply to them and, if so, which subset and which revision are in scope.
Information system security managers and compliance staff
Personnel responsible for implementing and documenting security requirements need to understand that 800-172 layers on top of 800-171 and does not stand alone. They should verify the applicable revision against the current authoritative text at NIST CSRC and avoid treating the enhanced requirements as a substitute for the base requirements.
Assessors and auditors
Those evaluating an organization's security posture against enhanced requirements should confirm which revision governs an engagement, since the requirements and their organization differ across versions. They should also distinguish the recommended nature of the publication from any binding effect that arises only through contractual, agency, or program-specific direction.
Federal agency and program stakeholders
Agencies and program offices that identify CUI warranting stronger protection against advanced persistent threats may reference 800-172 when specifying requirements. They are typically the source that determines whether and how the enhanced requirements become applicable to a given organization, and should confirm current guidance at authoritative sources.

Inside SP 800-172

Enhanced Security Requirements
NIST SP 800-172 provides enhanced security requirements that supplement the requirements in NIST SP 800-171. These are intended for CUI associated with critical programs or high value assets where the risk of advanced persistent threats (APTs) warrants protection beyond the baseline. Practitioners should verify which requirements apply to their systems against the current authoritative text, as applicability is generally determined by the CUI category and the sponsoring agency or contract.
Focus on Advanced Persistent Threats
The enhanced requirements are designed to strengthen the ability of systems to withstand, respond to, and recover from attacks by adversaries with sophisticated levels of expertise and significant resources, commonly characterized as APTs. This APT-focused orientation distinguishes SP 800-172 from the broader baseline protections in SP 800-171.
Supplemental, Not Standalone
SP 800-172 is intended to be applied in addition to, not in place of, the requirements in NIST SP 800-171. It generally presumes that the baseline SP 800-171 requirements are already implemented, and it is applied selectively based on risk rather than as a blanket baseline.
Relationship to NIST SP 800-53
The enhanced requirements draw from the broader control catalog maintained by NIST in SP 800-53. SP 800-172 tailors and expresses selected protections in a form directed at protecting CUI in nonfederal systems and organizations. The reader should confirm the specific mappings and derivations against the current official publication.
Companion Assessment Guidance
NIST publishes companion assessment procedures (SP 800-172A) to support evaluation of the enhanced security requirements. Practitioners should distinguish the requirements document from its assessment companion and verify the current revision of each against official NIST sources.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-172.

Does implementing NIST SP 800-172 replace or supersede NIST SP 800-171?
No. SP 800-172 provides enhanced security requirements that are intended to supplement, not replace, the requirements in SP 800-171. In most implementations, SP 800-172 requirements are applied only to a subset of systems or CUI associated with high-value assets or critical programs where the risk of advanced persistent threats justifies additional protection. An organization generally must still meet the applicable SP 800-171 requirements as the foundational baseline; SP 800-172 is layered on top where the awarding agency or contract specifies it. Readers should verify the specific requirements invoked by their contract or agency against the current authoritative text.
Are the enhanced requirements in NIST SP 800-172 mandatory for every organization that handles CUI?
Not automatically. SP 800-172 requirements generally apply only when an agency or contracting authority explicitly selects them, typically for CUI or systems judged to face advanced persistent threats. Unlike a broadly applied baseline, these enhanced requirements are selectively invoked rather than imposed on all CUI environments. Whether they apply to a given organization depends on the terms of the specific contract, agreement, or agency direction. Because applicability is scoped and can vary by program, readers should confirm the exact requirements imposed on them against current official sources and their contractual language rather than assuming universal applicability.
How does an organization determine which SP 800-172 enhanced requirements apply to its systems?
Selection of enhanced requirements is generally driven by the agency, program office, or contracting authority rather than chosen unilaterally by the contractor. In most implementations, the awarding organization identifies the specific CUI, systems, or high-value assets that warrant enhanced protection and designates which requirements apply. Organizations should look to contract language, agency guidance, and any accompanying implementation direction to scope applicability. Because tailoring and selection practices vary across agencies and programs, readers should confirm the precise set of applicable requirements against current authoritative and contractual sources.
How does SP 800-172 relate to an SP 800-171 assessment?
SP 800-172 addresses enhanced requirements that build on the SP 800-171 foundation, and assessing those enhanced requirements is a distinct activity from assessing the underlying SP 800-171 requirements. NIST publishes companion assessment guidance for the enhanced requirements to support evaluation of implementation. Organizations should note that assessment against these requirements is not the same as authorization, and demonstrating implementation does not by itself confer any approval to operate. Readers should verify the current assessment methodology and any program-specific expectations against official sources.
Can implementing SP 800-172 requirements substitute for a security program that also addresses SP 800-171?
No. Because SP 800-172 is designed as a supplement, its enhanced requirements presume that the applicable SP 800-171 requirements are already in place. Implementing enhanced requirements in isolation, without the foundational baseline, would generally leave gaps that the enhanced measures were not designed to cover. Organizations should treat SP 800-172 as an added layer for higher-risk scenarios and confirm that both the baseline and enhanced requirements applicable to their environment are addressed. Specific scoping and layering should be verified against current authoritative guidance and contract terms.
Where should an organization look to confirm the current requirements and companion assessment guidance for SP 800-172?
Organizations should consult the current published version of SP 800-172 and its companion assessment publication issued by NIST, along with any agency- or program-specific direction that selects and tailors the requirements. Because publication revisions can change requirement text, structure, and assessment procedures over time, readers should confirm they are working from the applicable revision rather than an outdated draft or superseded version. This entry describes the concept and role of the document and does not substitute for the current official text, which readers should verify directly.

Common misconceptions

SP 800-172 replaces SP 800-171 as the CUI protection standard.
SP 800-172 supplements SP 800-171 rather than replacing it. It provides enhanced requirements applied on top of the baseline, generally for higher-risk CUI subject to advanced persistent threats. Organizations still need to satisfy the underlying SP 800-171 requirements where applicable.
Every organization handling CUI must implement all SP 800-172 enhanced requirements.
The enhanced requirements are generally applied selectively based on the risk to specific critical programs or high value assets, and their applicability is typically driven by the sponsoring agency or the contract. Readers should confirm which requirements apply to their environment against current official guidance and contractual terms rather than assuming universal applicability.
Meeting SP 800-172 requirements means a system is authorized or fully secure.
Implementing enhanced security requirements addresses compliance objectives but does not by itself constitute an authorization, and compliance is not the same as security. Assessment against these requirements is distinct from any authorization decision, and protections should be maintained through ongoing monitoring rather than treated as a one-time achievement. Verify current authorization and assessment expectations against applicable authoritative sources.

Best practices

Confirm that baseline NIST SP 800-171 requirements are implemented before layering on SP 800-172 enhanced requirements, since the enhanced set is intended to supplement rather than stand alone.
Verify which enhanced requirements apply to your specific systems by consulting the sponsoring agency, applicable contract terms, and the CUI categories involved, rather than applying all requirements uniformly.
Pair the requirements document with the companion assessment procedures (SP 800-172A) when planning evaluations, keeping the requirements and assessment guidance clearly distinct.
Always check the current revision and status of SP 800-172 and its assessment companion against official NIST sources before relying on specific requirement text, as revisions change over time.
Treat the enhanced requirements as APT-focused protections for critical programs and high value assets, and document the risk rationale used to determine where they apply.
Do not treat implementation of these requirements as equivalent to security or authorization; maintain protections through continuous monitoring and confirm authorization expectations separately against applicable guidance.