NIST 800-171

framework · cybersecurity · regulatory-standard

NIST publication specifying security requirements for protecting controlled unclassified information in nonfederal systems; foundational to CMMC.

NIST Special Publication 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) is the foundational federal standard for protecting Controlled Unclassified Information (CUI) in nonfederal information systems, originally published in June 2015 with substantial subsequent revisions (Rev. 1 December 2016, Rev. 2 February 2020, Rev. 3 May 2024). The standard implements the protection requirements of Executive Order 13556 (November 2010, establishing the CUI program) and 32 CFR Part 2002 (governing CUI marking and handling). NIST 800-171 specifies 14 control families — Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity — derived substantially from NIST SP 800-53 (the foundational federal-system control catalog) but tailored to nonfederal-system context. NIST 800-171 compliance is required for Department of Defense (DoD) contractors and substantially mandated for civilian federal contractors handling CUI through the Cybersecurity Maturity Model Certification (CMMC) and other contractual requirements.

Originators

National Institute of Standards and Technology (NIST), particularly NIST Computer Security Resource Center; Foundational publication June 2015 implementing Executive Order 13556 (November 2010) and 32 CFR Part 2002; Subsequent revisions: Rev. 1 (December 2016), Rev. 2 (February 2020), Rev. 3 (May 2024); Companion NIST SP 800-171A (Assessing Security Requirements for CUI) providing assessment guidance; intellectual antecedents in NIST SP 800-53 (federal-system control catalog), NIST Cybersecurity Framework (2014), broader US federal cybersecurity tradition, ISO 27001/27002 international standard; Subsequent integration with: Cybersecurity Maturity Model Certification (CMMC, DoD-mandated), DFARS 252.204-7012 (DoD Defense Federal Acquisition Regulation Supplement clause requiring NIST 800-171 compliance), CUI Federal Acquisition Regulation (FAR) clause development (ongoing through 2025) high

Year / Decade

2015 (foundational publication); subsequent revisions through 2024 current Rev. 3; ongoing development high

Primary sources

NIST (June 2015, multiple revisions through May 2024 Rev. 3). Special Publication 800-171: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST (multiple editions). Special Publication 800-171A: Assessing Security Requirements for Controlled Unclassified Information, Executive Order 13556 (November 2010, foundational CUI program establishment), DFARS 252.204-7012 (Department of Defense Defense Federal Acquisition Regulation Supplement clause requiring NIST 800-171 compliance, multiple revisions) high

Core components

Primary use case

Foundational federal cybersecurity standard for Controlled Unclassified Information protection in nonfederal systems; applied principally in: Department of Defense contractor cybersecurity (substantial DIB Defense Industrial Base contractor implementation through DFARS 252.204-7012 mandate), federal civilian contractor cybersecurity (FAR clause development substantially expanding CUI protection requirements 2024-2025), CMMC compliance (Department of Defense Cybersecurity Maturity Model Certification program references NIST 800-171 controls), state and local government cybersecurity programs adopting NIST 800-171 as reference, broader US enterprise cybersecurity particularly for organizations handling federal data; academic and professional reference in cybersecurity, federal acquisition, and information-security management literature; core teaching in cybersecurity certification programs (CompTIA Security+, ISC² CISSP, ISACA CISM, ISC² CCSP) for control-framework knowledge; complementary to NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001/27002, CMMC, FAR/DFARS regulatory framework; substantial commercial cybersecurity-consulting, managed-service-provider, and technology-vendor infrastructure organized around NIST 800-171 compliance support.

Common criticisms

Lineage

Child of
NIST 800-53
Siblings
NIST Cybersecurity Framework, CMMC, NIST Risk Management Framework
Derived from
NIST 800-53