What Is NIST SP 800-171? The Plain-English Guide for Contractors
NIST SP 800-171 is a federal publication that spells out 110 security requirements for protecting Controlled Unclassified Information on non-government computer systems. Its full name is “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.” It was written by the National Institute of Standards and Technology (NIST), the federal agency that sets US technology and security standards.
The document doesn’t apply to every business. It applies to companies that handle CUI, meaning sensitive-but-unclassified government information, as part of a federal contract. Think technical drawings, specifications, or other data the government controls but hasn’t classified.
If your company just picked up a contract clause that mentions “NIST 800-171,” this guide walks through what the document actually requires, where it came from, how it becomes legally binding, and how it connects to CMMC. You do not need a security background to follow it.
A Brief History of NIST SP 800-171
NIST published the original version of SP 800-171 in June 2015. Revision 1 followed in December 2016, adding clarifying language and assessment procedures. Neither version is what’s enforced today.
Revision 2 arrived in February 2020, and it’s still the version that matters. It’s the version DFARS contract clauses require. It’s also the version CMMC Level 2 is built on. When people say “800-171,” Revision 2 is almost always what they mean.
NIST has since moved on. Revision 3 reorganizes the requirement structure, and it’s commonly described as roughly 97 base requirements with more granular sub-requirements attached. But it is not the version your contract enforces. As of this writing, the CMMC Program’s rule still points to Revision 2. Adopting Revision 3 would require its own separate rulemaking, and that hasn’t happened.
| Version | Published | Status Today |
|---|---|---|
| Original | June 2015 | Superseded |
| Revision 1 | December 2016 | Superseded |
| Revision 2 | February 2020 | Currently enforced; the basis for CMMC Level 2 |
That last row trips people up. A vendor or consultant citing “the newest version” of 800-171 is often talking about Revision 3, even though your actual contract obligation is Revision 2. When you’re scoping compliance work, confirm which revision the conversation is actually about.
Is NIST SP 800-171 a Law?
No. NIST SP 800-171 is technical guidance, not legislation. NIST wrote it as a reference standard. On its own, publishing it creates no legal obligation for anyone.
It becomes binding only when a federal contract clause cites it. Two clauses do that citing, and they don’t point to the same standard.
FAR 52.204-21 is the lighter one. It requires just 15 basic safeguarding requirements, and it applies when a contract involves Federal Contract Information (FCI) only, not CUI. This is the tier that later became CMMC Level 1.
DFARS 252.204-7012 is the heavier clause. It requires the full 110 requirements of NIST SP 800-171 whenever a contract involves CUI or “covered defense information.” If that clause is in your contract, compliance with NIST SP 800-171 is not optional. It’s a term you already agreed to when you signed.
One more distinction worth knowing: NIST SP 800-171 isn’t legally exclusive to the Department of War. Any federal agency that shares CUI with a nonfederal system can write it into a contract. In practice, the large majority of 800-171 obligations today trace back to DoD procurement, but the standard itself isn’t DoD-only on paper.
The 110 Requirements Across 14 Control Families
NIST SP 800-171 Revision 2’s 110 security requirements are grouped into 14 control families. Each family targets one slice of your security posture, from who can log in to how you respond when something goes wrong.
| Control Family | What It Covers in Practice |
|---|---|
| Access Control | Who can reach CUI, and what they’re allowed to do once they’re in |
| Awareness and Training | Staff can recognize CUI and know how to handle it |
| Audit and Accountability | System logs exist, and someone actually reviews them |
| Configuration Management | Systems are set up securely, and changes get tracked |
| Identification and Authentication | Every user and device proves who it is before getting access |
| Incident Response | A documented plan exists for when something goes wrong |
| Maintenance | Routine upkeep doesn’t quietly open new security gaps |
| Media Protection | Storage devices carrying CUI are controlled and properly sanitized when retired |
| Personnel Security | Background screening and offboarding are tied to CUI access |
| Physical Protection | Physical spaces housing CUI systems are locked down |
| Risk Assessment | Known threats to CUI are identified and tracked over time |
| Security Assessment | Controls get tested, not just written down |
| System and Communications Protection | Data is encrypted, and network boundaries are enforced |
| System and Information Integrity | Systems stay patched and get monitored for compromise |
Most of the practical work clusters around a few of these families. Access control, identification and authentication, and system and communications protection tend to require the most technical lift, since they touch how every user, device, and connection is set up. The others, like personnel security and physical protection, often already exist in some form and mostly need documentation to match.
None of the 14 families stand alone. An assessor, or your own self-assessment, checks them as a set. A strong access control setup with no audit logging still fails the audit and accountability family, even if logins are locked down tight.
Who Has to Comply With NIST SP 800-171
Most people assume this rule only applies to Department of War contractors. It doesn’t. Any nonfederal organization that handles CUI under a federal contract can be covered, no matter which agency wrote that contract.

In practice, the obligation reaches further than most owners expect:
- Prime contractors and subcontractors at any tier, if CUI passes through their systems
- Companies working with federal agencies outside the Department of War that write NIST SP 800-171 into a contract
- Vendors who don’t think of themselves as “defense contractors” at all, like transportation and logistics firms
Take trucking and logistics. A carrier hauling freight for a defense prime might assume this rule doesn’t touch it. If the cargo or its paperwork counts as CUI, it does.
The same flow-down obligation reaches any subcontractor further down the chain, even one that has never dealt with the government directly. A prime cannot legally hand CUI-relevant work to a subcontractor that hasn’t met the required security level. One non-compliant vendor can put the prime’s own contract at risk.
How NIST SP 800-171 Compliance Gets Verified
NIST wrote a companion document, SP 800-171A, that lays out how each of the 110 requirements actually gets checked. Most contractors use it to self-assess rather than hire an outside auditor.
Separate from CMMC, DFARS 252.204-7019 and 252.204-7020 already require a current assessment score. That score gets posted to the Supplier Performance Risk System (SPRS), and it applies whether or not CMMC is mentioned in the contract.
DFARS 252.204-7019 and 252.204-7020 already require a current NIST SP 800-171 score in SPRS, no more than 3 years old, independent of whether the contract mentions CMMC at all.
| SPRS Detail | What It Means |
|---|---|
| Score range | Starts at 110 (all requirements met); can go as low as -203 |
| Assessment basis | NIST SP 800-171A methodology, most often self-assessed |
| Where it’s posted | Supplier Performance Risk System (SPRS) |
| Refresh requirement | Must not be older than 3 years |
| Below-max score | Requires a Plan of Action and Milestones (POA&M) |
A score below 110 isn’t automatically disqualifying. It just means gaps exist, and you need a documented plan for closing them. For the full breakdown of how that score gets calculated, see our companion guide on what an SPRS score means.
How NIST SP 800-171 Relates to CMMC
NIST SP 800-171 and CMMC often get treated as the same thing. They’re related, but not identical. NIST SP 800-171 is the technical standard. CMMC is the verification program built on top of it.
CMMC Level 2 requires the same 110 requirements from NIST SP 800-171 Revision 2 covered above. If your contract requires CMMC Level 2, meeting NIST SP 800-171 is effectively how you get there. For the full picture of how the levels stack up, see our guide to CMMC’s three levels.
Compliance at Level 2 gets checked one of two ways: your own self-assessment, or an assessment from a Certified Third-Party Assessment Organization, an accredited body authorized to issue the official certification.
Independent of any of that, the SPRS obligation under DFARS 252.204-7019 and 252.204-7020 already existed. It predates CMMC entirely. A contractor can owe a current SPRS score on a contract that never mentions CMMC by name.
Manufacturers face their own wrinkles around what counts as CUI on the shop floor. That’s covered in our guide to CMMC for manufacturers.
See Where You Stand
Not sure whether your CUI exposure puts you at Level 1 or Level 2? Take the free 2-minute CMMC Risk-Check: answer a few plain-English questions about your systems and CUI exposure, and get your readiness level plus the gaps to close. No sign-up is needed to see your result.
Take the free 2-minute CMMC Risk-Check
How LeadingIT Helps You Meet NIST SP 800-171
LeadingIT is a managed IT and cybersecurity provider based in Woodstock and Manteno, Illinois.

For a company working toward NIST SP 800-171, we operate the technical backbone an assessment actually checks:
- Access control and unique-user authentication with multifactor authentication
- Encryption of CUI at rest and in transit
- Centralized audit logging
- Configuration management and patching
- Security awareness training and incident response planning
- The documentation an assessor will ask to see: a system security plan and a POA&M
We also help scope which systems actually touch CUI. That keeps the compliance boundary from ballooning to your whole company.
If you want to talk through your specific CUI exposure, contact us and we’ll walk through it together.
Related Guides
- CMMC for Manufacturers: What Defense Suppliers Need to Know
- What Is a C3PAO? A Guide to CMMC Assessors
- What Is an SPRS Score? A Plain-English Guide
- What Is CUI? Controlled Unclassified Information for Defense Suppliers
- CMMC Levels 1, 2, and 3 Explained
- CMMC for Transportation & Logistics
Frequently Asked Questions
NIST SP 800-171 is a federal document that lists 110 security requirements for protecting Controlled Unclassified Information on non-government computer systems. The National Institute of Standards and Technology wrote it. It becomes a real obligation only when a federal contract clause requires it, most often DFARS 252.204-7012.
Any nonfederal company that handles CUI as part of a federal contract needs to comply, not just Department of War contractors. Other federal agencies can also require it in their own contracts. Obligations flow down the supply chain too, so subcontractors handling CUI are covered even if they never deal directly with the government.
No. NIST SP 800-171 is technical guidance, not legislation, so publishing it alone creates no legal requirement. It becomes binding only when a contract clause like DFARS 252.204-7012 cites it. Once that clause is in your contract, following the 110 requirements is a term you already agreed to.
NIST SP 800-171 is the technical standard. CMMC is the verification program built around it. CMMC Level 2 requires the same 110 requirements from NIST SP 800-171 Revision 2, checked either by self-assessment or by a Certified Third-Party Assessment Organization. The underlying SPRS scoring obligation already existed before CMMC and applies independently of it.
Compliance gets checked against NIST SP 800-171A, the companion document that lays out the assessment methodology requirement by requirement. Most contractors self-assess and post a score to the Supplier Performance Risk System. The score can’t be more than 3 years old, and anything below the maximum requires a documented Plan of Action and Milestones.
An SPRS score measures how many of the 110 NIST SP 800-171 requirements a company has actually implemented. It starts at a maximum of 110 and can go as low as -203 depending on what’s missing. Contractors handling CUI have to keep a current score posted in the Supplier Performance Risk System.
Revision 2, published in February 2020. NIST finalized Revision 3 in May 2024, but the CMMC Program’s rule still points to Revision 2 as of this writing. Adopting Revision 3 for CMMC purposes would need its own separate rulemaking that hasn’t happened yet.
Ready to Put NIST SP 800-171 Into Practice?
Reading the requirement is one thing. Implementing it across your systems, staff, and documentation is another. LeadingIT’s NIST SP 800-171 and CMMC compliance services handle that implementation as part of ongoing managed IT, not a one-time project.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
