NIST 800-171
NIST publication specifying security requirements for protecting controlled unclassified information in nonfederal systems; foundational to CMMC.
NIST Special Publication 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) is the foundational federal standard for protecting Controlled Unclassified Information (CUI) in nonfederal information systems, originally published in June 2015 with substantial subsequent revisions (Rev. 1 December 2016, Rev. 2 February 2020, Rev. 3 May 2024). The standard implements the protection requirements of Executive Order 13556 (November 2010, establishing the CUI program) and 32 CFR Part 2002 (governing CUI marking and handling). NIST 800-171 specifies 14 control families — Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity — derived substantially from NIST SP 800-53 (the foundational federal-system control catalog) but tailored to nonfederal-system context. NIST 800-171 compliance is required for Department of Defense (DoD) contractors and substantially mandated for civilian federal contractors handling CUI through the Cybersecurity Maturity Model Certification (CMMC) and other contractual requirements.
Core components
- 14 control families (Rev. 3): (1) Access Control (AC)
- (2) Awareness and Training (AT)
- (3) Audit and Accountability (AU)
- (4) Configuration Management (CM)
- (5) Identification and Authentication (IA)
- (6) Incident Response (IR)
- (7) Maintenance (MA)
- (8) Media Protection (MP)
- (9) Personnel Security (PS)
- (10) Physical Protection (PE)
- (11) Risk Assessment (RA)
- (12) Security Assessment (CA)
- (13) System and Communications Protection (SC)
- (14) System and Information Integrity (SI)
- Approximately 110 specific security requirements (Rev. 2
- Rev. 3 reorganized to Organizational-Level Control and Technical Control structure)
- Derivation from NIST SP 800-53: NIST 800-171 controls are tailored from the more comprehensive NIST 800-53 catalog with simplifications appropriate for nonfederal-system context (removing federal-specific controls, simplifying implementation guidance)
- Controlled Unclassified Information (CUI) categorization: information that requires safeguarding consistent with applicable laws, regulations, and government-wide policies but is not classified — categories defined in CUI Registry (e.g., Critical Infrastructure, Defense, Export Control, Financial, Geodetic Product Information, Immigration, Intelligence, International Agreements, Law Enforcement, Legal, Natural and Cultural Resources, NATO, Nuclear, Patent, Privacy, Procurement and Acquisition, Proprietary Business Information, Provisional, Statistical, Tax, Transportation)
- System Security Plan (SSP) requirement: documented implementation of each requirement
- Plan of Actions and Milestones (POA&M): documented remediation plan for unmet requirements
- Companion NIST SP 800-171A: assessment methodology for evaluating compliance
- DFARS 252.204-7012 integration: DoD contractor self-assessment and incident-reporting requirements
- CMMC integration: Cybersecurity Maturity Model Certification levels reference NIST 800-171 controls
- CMMC 2.0 (2021 onward) reduced from five levels to three levels with NIST 800-171 as Level 2 reference
- Application contexts: Department of Defense contractor cybersecurity, federal civilian contractor cybersecurity (substantially through FAR clause development), state and local government adoption (substantial CIS Critical Security Controls mapping), broader nonfederal-system cybersecurity reference
Primary use case
Foundational federal cybersecurity standard for Controlled Unclassified Information protection in nonfederal systems; applied principally in: Department of Defense contractor cybersecurity (substantial DIB Defense Industrial Base contractor implementation through DFARS 252.204-7012 mandate), federal civilian contractor cybersecurity (FAR clause development substantially expanding CUI protection requirements 2024-2025), CMMC compliance (Department of Defense Cybersecurity Maturity Model Certification program references NIST 800-171 controls), state and local government cybersecurity programs adopting NIST 800-171 as reference, broader US enterprise cybersecurity particularly for organizations handling federal data; academic and professional reference in cybersecurity, federal acquisition, and information-security management literature; core teaching in cybersecurity certification programs (CompTIA Security+, ISC² CISSP, ISACA CISM, ISC² CCSP) for control-framework knowledge; complementary to NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001/27002, CMMC, FAR/DFARS regulatory framework; substantial commercial cybersecurity-consulting, managed-service-provider, and technology-vendor infrastructure organized around NIST 800-171 compliance support.
Common criticisms
- NIST 800-171 implementation has produced substantial compliance burden for DoD and federal contractors — particularly small-and-medium DIB contractors who have documented difficulty implementing 110 security requirements (Rev. 2) at the cost levels their contracts support, with industry surveys documenting that many contractors are non-compliant or only partially compliant despite contractual requirements
- the historical self-assessment structure under DFARS 252.204-7012 has been argued by cybersecurity-policy critics to produce optimistic self-reporting that external assessment would not support — substantial contractor self-scoring inflation has been documented in DoD Supplier Performance Risk System (SPRS) data, leading to CMMC introduction as third-party assessment supplement
- CMMC implementation has itself faced substantial controversy — the original CMMC (2020) was substantially restructured to CMMC 2.0 (2021) reducing maturity levels from five to three after substantial industry objections
- ongoing CMMC 2.0 rule-making (finalized December 2024 with phased implementation) has produced substantial compliance-timing uncertainty for DIB contractors
- the relationship between NIST 800-171 and broader NIST SP 800-53 produces implementation complexity — organizations handling both CUI and federal-system data must navigate parallel control catalogs with non-identical requirements
- Rev. 3 (May 2024) represents substantial framework restructuring (Organizational-Level vs Technical Control categories rather than 14 family categorization of Rev. 1 and Rev. 2) that produces transition burden for organizations updating existing implementations
- CUI program implementation has been documented as inconsistent across federal agencies — different agencies marking substantially different information categories as CUI, producing contractor uncertainty about what specific information requires NIST 800-171 protection
- the standard's emphasis on preventive controls has been argued by some cybersecurity practitioners to underweight detection and response capabilities that modern threat-actor sophistication requires
- integration with cloud-service-provider environments produces shared-responsibility-model complexity that NIST 800-171 addresses incompletely, with FedRAMP authorization providing partial complement for cloud-based CUI handling
- small-business adverse-impact concerns have been substantively documented — NIST 800-171 compliance costs may produce DIB-contractor consolidation by pricing out smaller contractors.
Lineage
- Child of
- NIST 800-53
- Siblings
- NIST Cybersecurity Framework, CMMC, NIST Risk Management Framework
- Derived from
- NIST 800-53