NIST Special Publication 800-171
NIST SP 800-171 is a publication from the National Institute of Standards and Technology (NIST) that recommends security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when that information resides in nonfederal systems and organizations. It is generally relevant to organizations, such as contractors, that handle CUI on behalf of federal agencies. Readers should verify how the requirements apply to their specific situation against the current authoritative text.
NIST SP 800-171 is a NIST Special Publication providing recommended security requirements for protecting the confidentiality of CUI resident in nonfederal systems and organizations. It has been issued across multiple revisions maintained by NIST; Revision 2 was published in February 2020 (with an errata/update dated January 28, 2021), and Revision 3 was published in 2024 following an initial public draft in 2023. The publication defines security requirements rather than authorization or contractual mechanisms, and organizations should confirm the applicable revision, tailoring, and any implementing contractual or regulatory obligations (which are outside the scope of the publication itself) against current official sources.
Why it matters
NIST SP 800-171 addresses a gap that federal agencies cannot close on their own: much of the Controlled Unclassified Information (CUI) generated by the government ends up residing in the systems of contractors, universities, and other nonfederal organizations. When that information leaves federal control, the agency still has an interest in protecting its confidentiality. NIST SP 800-171 provides a common baseline of recommended security requirements so that nonfederal organizations handling CUI can protect it in a consistent, expectation-aligned way rather than each agency inventing its own bespoke rules.
For contractors and other nonfederal entities, the practical significance is that these requirements are frequently referenced by implementing regulations and contract terms. It is important to recognize a distinction that experts insist upon: NIST SP 800-171 defines security requirements, not the contractual or regulatory obligation to meet them and not any authorization mechanism. The obligation to comply, how compliance is assessed, and any consequences of noncompliance come from the implementing contract clauses or regulations, which are outside the scope of the publication itself. Readers should confirm those obligations against current official sources rather than assuming the publication alone establishes them.
Because the publication has been issued across multiple revisions, the specific requirements that apply to a given organization depend on which revision is invoked by the relevant contract or regulation. Revision 2 was published in February 2020, with an errata update dated January 28, 2021, and Revision 3 was published in 2024 following an initial public draft in 2023. Organizations should verify which revision applies to their situation, because tailoring and the applicable version can change the concrete requirements in force.
Who it's relevant to
Inside NIST SP 800-171
Common questions
Answers to the questions practitioners most commonly ask about NIST SP 800-171.