Skip to main content
Category: NIST Standards & Publications

NIST Special Publication 800-171

Also known as: NIST SP 800-171, SP 800-171, 800-171
Simply put

NIST SP 800-171 is a publication from the National Institute of Standards and Technology (NIST) that recommends security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when that information resides in nonfederal systems and organizations. It is generally relevant to organizations, such as contractors, that handle CUI on behalf of federal agencies. Readers should verify how the requirements apply to their specific situation against the current authoritative text.

Formal definition

NIST SP 800-171 is a NIST Special Publication providing recommended security requirements for protecting the confidentiality of CUI resident in nonfederal systems and organizations. It has been issued across multiple revisions maintained by NIST; Revision 2 was published in February 2020 (with an errata/update dated January 28, 2021), and Revision 3 was published in 2024 following an initial public draft in 2023. The publication defines security requirements rather than authorization or contractual mechanisms, and organizations should confirm the applicable revision, tailoring, and any implementing contractual or regulatory obligations (which are outside the scope of the publication itself) against current official sources.

Why it matters

NIST SP 800-171 addresses a gap that federal agencies cannot close on their own: much of the Controlled Unclassified Information (CUI) generated by the government ends up residing in the systems of contractors, universities, and other nonfederal organizations. When that information leaves federal control, the agency still has an interest in protecting its confidentiality. NIST SP 800-171 provides a common baseline of recommended security requirements so that nonfederal organizations handling CUI can protect it in a consistent, expectation-aligned way rather than each agency inventing its own bespoke rules.

For contractors and other nonfederal entities, the practical significance is that these requirements are frequently referenced by implementing regulations and contract terms. It is important to recognize a distinction that experts insist upon: NIST SP 800-171 defines security requirements, not the contractual or regulatory obligation to meet them and not any authorization mechanism. The obligation to comply, how compliance is assessed, and any consequences of noncompliance come from the implementing contract clauses or regulations, which are outside the scope of the publication itself. Readers should confirm those obligations against current official sources rather than assuming the publication alone establishes them.

Because the publication has been issued across multiple revisions, the specific requirements that apply to a given organization depend on which revision is invoked by the relevant contract or regulation. Revision 2 was published in February 2020, with an errata update dated January 28, 2021, and Revision 3 was published in 2024 following an initial public draft in 2023. Organizations should verify which revision applies to their situation, because tailoring and the applicable version can change the concrete requirements in force.

Who it's relevant to

Government contractors handling CUI
Organizations that store, process, or transmit Controlled Unclassified Information on behalf of federal agencies are the primary audience. The recommended requirements in NIST SP 800-171 are commonly referenced as the baseline for protecting CUI confidentiality in nonfederal systems, though the binding obligation and the applicable revision come from the specific contract or regulation, which contractors should verify.
Universities and research institutions
Nonfederal research organizations that handle CUI, for instance, in the course of federally sponsored work, may need to align their systems with these requirements. As one institutional summary describes, 800-171 is often treated as a codification of what a non-Federal computer system must follow to store such information, but the precise scope depends on the applicable version and implementing terms.
Information system security and compliance staff
Security managers and compliance officers responsible for nonfederal systems use NIST SP 800-171 as the reference for the recommended confidentiality protections for CUI. They should track which revision (Revision 2 with its 2021 errata, or Revision 3) applies to a given engagement and distinguish the publication's security requirements from the separate contractual and assessment obligations.
Federal agencies establishing CUI protection expectations
Federal agencies rely on NIST SP 800-171 to communicate a consistent set of recommended security requirements to the nonfederal organizations that handle their CUI, providing a common baseline rather than agency-specific rules. Agencies remain responsible for identifying the applicable revision and the implementing mechanisms through which those requirements are imposed.

Inside NIST SP 800-171

Purpose and Scope
NIST SP 800-171, maintained by NIST, provides recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organizations. It is generally invoked when a nonfederal entity processes, stores, or transmits CUI on behalf of a federal agency. It does not itself address the protection of federal systems, which are typically governed by NIST SP 800-53 under FISMA, and readers should verify applicability against the current authoritative text.
Security Requirement Families
The requirements are organized into families that align conceptually with control families found in NIST SP 800-53 (such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, and system and information integrity). The specific family set and requirement numbering can change across revisions, so the applicable revision should be confirmed.
Basic and Derived Requirements
In most implementations of the earlier revision structure, requirements were expressed as basic security requirements (higher-level objectives) and derived security requirements (more granular requirements supporting them). Practitioners should confirm how these are presented in the revision that applies to their obligation, as the structure has evolved.
Relationship to CUI and Federal Sources
The requirements trace to federal law, regulation, and policy governing CUI, with the CUI program itself administered separately (the CUI registry is maintained by NARA). NIST SP 800-171 focuses on confidentiality of CUI and does not, by itself, establish the marking, dissemination, or legal designation rules for CUI.
Companion Assessment Guidance
NIST SP 800-171A provides procedures for assessing whether the security requirements are satisfied. Assessment against these procedures is distinct from any authorization or contractual acceptance decision, and readers should verify the current version of the assessment guidance.
Revision History
NIST SP 800-171 has been issued across multiple revisions. Revision 2 was published in February 2020, with a subsequent errata update dated January 28, 2021. Because requirement content and numbering can shift between revisions, practitioners should confirm which revision governs their specific obligation.

Common questions

Answers to the questions practitioners most commonly ask about NIST SP 800-171.

Does complying with NIST SP 800-171 mean my system is secure?
No. Compliance and security are distinct. NIST SP 800-171 establishes a set of security requirements intended to protect Controlled Unclassified Information (CUI) in nonfederal systems, but implementing those requirements does not guarantee a system is secure against all threats. Meeting the requirements demonstrates that specific safeguards are in place as documented; it does not substitute for ongoing risk management, monitoring, and defense against evolving adversary capabilities. Treat 800-171 as a baseline for protecting CUI, not as a comprehensive measure of security posture.
Is NIST SP 800-171 the same thing as CMMC, or does one replace the other?
They are related but not the same, and they are maintained by different bodies. NIST SP 800-171 is a security requirements publication issued and maintained by NIST. CMMC is a certification and assessment framework associated with the DoD. CMMC generally draws on the security requirements found in NIST SP 800-171, but CMMC adds an assessment and certification structure that 800-171 by itself does not impose. Neither replaces the other: 800-171 defines requirements, while CMMC provides a mechanism for assessing and verifying implementation. Because CMMC has undergone phased rollout and revisions, readers should confirm the current CMMC requirements and how they map to the applicable revision of 800-171 against official DoD sources.
Which revision of NIST SP 800-171 applies to my organization?
The applicable revision depends on what your contract, agreement, or governing authority specifies. Revision 2 was published in February 2020, with an errata update dated January 28, 2021. NIST has continued to develop the publication, so a later revision may apply depending on the timeframe and the terms flowed down to you. Because contractual language may reference a specific revision, and because agency tailoring can affect which requirements apply, verify the exact revision cited in your applicable contract or directive against the current authoritative text rather than assuming the latest version automatically governs.
How does a System Security Plan (SSP) relate to NIST SP 800-171 compliance?
In most implementations, a System Security Plan documents how each of the security requirements is met, including the system boundary, environment, and any planned actions to address requirements not yet fully implemented. Organizations generally pair the SSP with plans of action that describe how and when open items will be remediated. These documents are commonly central to demonstrating the status of implementation. This entry does not cover the specific format, contractual submission obligations, or scoring conventions that a particular agency or program may impose, which you should confirm against current official guidance.
What is the difference between a self-assessment against NIST SP 800-171 and a third-party assessment?
A self-assessment is an organization's own evaluation of whether it meets the security requirements, typically documented in its SSP and associated plans. A third-party or independent assessment involves an external party evaluating implementation. Assessment, in either form, is distinct from any authorization or certification decision. The type of assessment required, and whether independent assessment is mandated, depends on the applicable contractual or program requirements, which have evolved and should be verified against current authoritative sources.
Does NIST SP 800-171 apply to information other than Controlled Unclassified Information (CUI)?
NIST SP 800-171 is generally scoped to protecting CUI when it resides in or transits nonfederal systems and organizations. It is not intended to govern classified systems, which fall under separate national security requirements, and federal systems themselves are typically addressed by other frameworks. Determining what qualifies as CUI in your environment, and where the requirements apply, depends on the categorization performed under the governing authority. This entry does not resolve CUI categorization for any specific data set, which must be confirmed against applicable official guidance and contract terms.

Common misconceptions

Meeting NIST SP 800-171 is the same as achieving CMMC certification or satisfying DFARS clause 252.204-7012.
NIST SP 800-171 is a NIST-maintained set of security requirements, whereas CMMC is a Department of Defense assessment and certification framework and DFARS clause 252.204-7012 is a contract clause. They are related but distinct; the requirements in 800-171 are drawn upon by DoD mechanisms, but implementing 800-171 does not automatically satisfy every contractual, assessment, or certification obligation. Confirm the specific requirement against current DoD and contract sources.
NIST SP 800-171 applies to federal information systems and replaces NIST SP 800-53.
NIST SP 800-171 is intended for CUI in nonfederal systems and organizations, while NIST SP 800-53 provides controls generally used for federal systems under FISMA and the RMF. They serve different scopes and are not interchangeable.
A completed assessment against NIST SP 800-171 requirements is equivalent to an authorization or a guarantee of security.
Assessment (for example, using NIST SP 800-171A) determines whether requirements are satisfied at a point in time; it is not an authorization decision and does not, on its own, establish that a system is secure. Compliance with a requirement set is not the same as security, and posture must be maintained over time.

Best practices

Confirm which revision of NIST SP 800-171 governs your obligation before scoping work, since requirement content and numbering can differ across revisions (for example, Revision 2 published February 2020 with a January 28, 2021 errata update).
Define and document the boundary of systems that process, store, or transmit CUI so that the requirements are applied only where CUI actually resides, and verify CUI designations against authoritative sources rather than assuming.
Use the companion assessment guidance (NIST SP 800-171A) to evaluate each requirement, and keep assessment results distinct from any authorization or contractual acceptance decision.
Do not treat a NIST SP 800-171 assessment as equivalent to CMMC certification or to satisfying a specific DFARS clause; verify each contractual and assessment obligation against current DoD and contract sources.
Maintain evidence and re-evaluate on an ongoing basis rather than treating a one-time assessment as durable, since security posture and applicable requirements can change.
Cross-check terminology and requirement mappings against the current official NIST publication, because guidance evolves and agency-specific tailoring may apply.