What is NIST SP 800-171?
NIST Special Publication 800-171 ("Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations") is the government's playbook for how companies outside the government protect sensitive but unclassified information. Rev 2 sets out 110 security requirements. If you're a defense contractor and your systems store, process, or transmit CUI, you need to implement them.
Here's the thing: NIST wrote this for protecting CUI broadly, but it became a hard contract requirement for defense contractors because DFARS 252.204-7012 requires it. CMMC is how the DoD verifies you're actually doing it. (Mandatory third-party CMMC certification is paused, but the NIST 800-171 obligation itself didn't go anywhere.)
So no, NIST 800-171 isn't optional if you handle CUI on a DoD contract. It comes in through the clauses in your contract. The requirements are specific and testable, which is what makes self-assessment scoring and third-party verification possible.
Why NIST 800-171 Matters for Defense Contractors
Real talk: NIST 800-171 matters because:
- Contract requirement: DFARS 252.204-7012 requires NIST 800-171 on any contractor information system that stores, processes, or transmits covered defense information
- CMMC foundation: CMMC Level 2 certification covers all 110 NIST 800-171 controls
- Real protection: The requirements are aimed at the attacks that actually hit contractors: stolen credentials, ransomware, and data theft
- Contract eligibility: CMMC Level 2 self-assessments, based on NIST 800-171, already appear in DoD solicitations; third-party certification was paused in July 2026 but is likely to return in some form
- Measurable: Each requirement has defined assessment objectives (NIST SP 800-171A), so you can test whether it is actually met
The 14 NIST 800-171 Control Families
The 110 security requirements in Rev 2 are organized into 14 families. Requirement numbers run from 3.1.1 to 3.14.7, where the middle number is the family. Here's what each one covers. (If you've seen "17 families," that's Rev 3, which DFARS 7012 and CMMC don't use yet.)
1. Access Control (AC) — 22 requirements
Who gets to access what, and how you enforce it: authorized users and devices, least privilege, separation of duties, session controls, remote and wireless access, mobile devices, and controlling CUI flow and what gets posted publicly.
Key requirements: 3.1.1 (authorized access), 3.1.2 (transactions and functions), 3.1.4 (separation of duties), 3.1.5 (least privilege), 3.1.12 (monitor and control remote access)
2. Awareness and Training (AT) — 3 requirements
Making sure managers, administrators, and users know the security risks of their work, are trained for their roles, and can recognize and report insider threat indicators.
Key requirements: 3.2.1 (security awareness), 3.2.2 (role-based training), 3.2.3 (insider threat awareness)
3. Audit and Accountability (AU) — 9 requirements
Logging security-relevant events, tying actions to individual users, reviewing and correlating logs, and protecting the logs themselves.
Key requirements: 3.3.1 (create and retain audit logs), 3.3.2 (trace actions to users), 3.3.5 (correlate review and analysis), 3.3.8 (protect audit information)
4. Configuration Management (CM) — 9 requirements
Baselines and inventories, secure configuration settings, change control, least functionality, and controlling what software runs.
Key requirements: 3.4.1 (baselines and inventories), 3.4.2 (security configuration settings), 3.4.3 (change control), 3.4.6 (least functionality), 3.4.8 (application deny/allow listing)
5. Identification and Authentication (IA) — 11 requirements
Identifying and authenticating users, processes, and devices, including multifactor authentication and password rules.
Key requirements: 3.5.1 (identify), 3.5.2 (authenticate), 3.5.3 (multifactor authentication), 3.5.7 (password complexity), 3.5.10 (cryptographically protected passwords)
6. Incident Response (IR) — 3 requirements
An operational capability to prepare for, detect, contain, and recover from incidents, track and report them, and test that capability. The DoD reporting rules come from DFARS 252.204-7012, not NIST: report cyber incidents to DoD within 72 hours of discovery through the DIBNet portal (dibnet.dod.mil), which requires a DoD-approved Medium Assurance Certificate; preserve images of affected systems and relevant monitoring data for at least 90 days; and submit any malicious software you find to the DoD Cyber Crime Center (DC3).
Key requirements: 3.6.1 (incident handling capability), 3.6.2 (track, document, and report incidents), 3.6.3 (test incident response)
7. Maintenance (MA) — 6 requirements
Performing and controlling system maintenance, maintenance tools, sanitizing equipment removed for off-site repair, and supervising maintenance personnel.
Key requirements: 3.7.1 (perform maintenance), 3.7.2 (control maintenance tools), 3.7.5 (MFA for nonlocal maintenance), 3.7.6 (supervise maintenance personnel)
8. Media Protection (MP) — 9 requirements
Protecting paper and digital media containing CUI: access, marking, transport, encryption on portable media, removable media rules, and sanitization before disposal.
Key requirements: 3.8.1 (protect media), 3.8.3 (sanitize or destroy), 3.8.6 (encrypt CUI on portable media in transport), 3.8.7 (control removable media)
9. Personnel Security (PS) — 2 requirements
Screening people before they get access to CUI, and protecting CUI when people leave or transfer.
Key requirements: 3.9.1 (screen individuals), 3.9.2 (protect CUI during terminations and transfers)
10. Physical Protection (PE) — 6 requirements
Limiting physical access, protecting and monitoring the facility, escorting visitors, keeping access logs, managing keys and badges, and securing alternate work sites.
Key requirements: 3.10.1 (limit physical access), 3.10.2 (protect and monitor the facility), 3.10.3 (escort visitors), 3.10.4 (physical access logs), 3.10.5 (manage physical access devices), 3.10.6 (alternate work sites)
11. Risk Assessment (RA) — 3 requirements
Periodically assessing risk, scanning for vulnerabilities, and remediating them.
Key requirements: 3.11.1 (periodic risk assessment), 3.11.2 (vulnerability scanning), 3.11.3 (remediate vulnerabilities)
12. Security Assessment (CA) — 4 requirements
Periodically assessing your controls, tracking fixes in a plan of action, monitoring controls on an ongoing basis, and maintaining your System Security Plan (SSP).
Key requirements: 3.12.1 (assess controls), 3.12.2 (plans of action), 3.12.3 (monitor controls), 3.12.4 (system security plan)
13. System and Communications Protection (SC) — 16 requirements
Boundary protection, secure architecture, deny-by-default network traffic, encryption in transit and at rest, and FIPS-validated cryptography.
Key requirements: 3.13.1 (boundary protection), 3.13.2 (secure architecture), 3.13.6 (deny by default), 3.13.8 (encryption in transit), 3.13.11 (FIPS-validated cryptography), 3.13.16 (CUI at rest)
14. System and Information Integrity (SI) — 7 requirements
Fixing flaws, malicious code protection, acting on security alerts, and monitoring systems for attacks and unauthorized use.
Key requirements: 3.14.1 (flaw remediation), 3.14.2 (malicious code protection), 3.14.3 (security alerts and advisories), 3.14.6 (monitor for attacks), 3.14.7 (identify unauthorized use)
NIST 800-171 Revision 2 vs. Revision 3
In 2024, NIST published Revision 3 of 800-171. The changes are significant, but here's the practical part: DFARS 252.204-7012 and CMMC Level 2 still assess against Revision 2 (110 requirements). Rev 3 is on the horizon, not required yet.
| Aspect | Revision 2 | Revision 3 |
|---|---|---|
| Total Requirements | 110 requirements in 14 families | 97 requirements in 17 families (consolidated and restructured) |
| New Families | None | Adds Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR) |
| Key Changes | Original version | Introduces organization-defined parameters (ODPs), so some values are set by the agency or organization rather than fixed in the text; withdraws or merges some Rev 2 requirements |
| Status for Defense Contractors | Still the version DFARS 7012 and CMMC Level 2 use | Published 2024; referenced in the proposed FAR CUI rule (June 2026), not yet required |
| CMMC Alignment | CMMC Level 2 uses Rev 2 | Not yet adopted by CMMC |
What to do about Rev 3: Build your program on Rev 2 today, since that's what DFARS 7012, SPRS and CMMC Level 2 measure. Keep an eye on Rev 3: a proposed FAR CUI rule published June 23, 2026 (comments closed July 23, 2026) would extend CUI safeguarding to civilian-agency contractors and reference NIST SP 800-171 Rev 3. It's a proposal, not a final rule.
How NIST 800-171 Maps to CMMC Certification
CMMC Level 2 certification is essentially a third-party audit of all 110 NIST 800-171 controls (currently voluntary while Phase 2 is paused; most contractors self-assess for now). When a C3PAO (Certified Third-Party Assessor Organization) conducts a CMMC Level 2 assessment, they are verifying that your organization has implemented and is maintaining all 110 NIST controls.
The alignment:
- NIST 800-171 = the blueprint: The 110 controls define what you must implement
- CMMC Level 2 = the verification: A self-assessment today, or a C3PAO assessment if you choose (or your prime asks), confirms you've implemented all 110 controls correctly
- DFARS = the mandate: DFARS 252.204-7012 requires NIST 800-171 compliance, 7019/7020 require an SPRS score, and the CMMC clause adds the assessment requirement where it's in your contract
NIST 800-171 Control Implementation: Recommended Priority Order
Implementing all 110 requirements at once is impractical. Prioritize by risk, point weight, and effort. The week ranges below are a typical sequence, not a rule:
Phase 1: Critical Controls (Weeks 1–8)
These controls prevent the most common attacks (ransomware, credential theft, data exfiltration):
- 3.12.4 (System Security Plan): Document your boundary and how each requirement is met. Without an SSP, DoD treats the assessment as incomplete
- 3.13.1 (Boundary Protection): Firewalls and segmentation separating CUI systems from public networks
- 3.13.8 (Encryption in Transit): Cryptographic protection for CUI in transit (e.g., TLS 1.2+)
- 3.13.11 and 3.13.16 (FIPS-Validated Crypto, CUI at Rest): Encrypt CUI at rest using FIPS-validated cryptography
- 3.5.3 (Multifactor Authentication): MFA for local and network access to privileged accounts, and for network access to non-privileged accounts
- 3.14.1 (Flaw Remediation): Identify, report, and correct flaws in a timely manner. NIST doesn't set a day count, so define your own timeframes (30 days for critical patches is common practice) and stick to them
- 3.14.2 (Malicious Code Protection): Antivirus/EDR at the appropriate points in your environment
- 3.6.1 and 3.6.2 (Incident Handling and Reporting): Incident response procedures, plus 72-hour DoD reporting under DFARS 7012 (get your Medium Assurance Certificate before you need it)
- 3.14.6 (Monitor for Attacks): SIEM or similar for detecting intrusions and anomalies
Phase 2: High-Impact Controls (Weeks 9–16)
These close out the core of your program (and, like all 110, they count toward your SPRS score):
- 3.1.1 and 3.1.5 (Authorized Access, Least Privilege): User account lifecycle, role-based access, privilege management
- 3.3.1 and 3.3.5 (Audit Logging and Review): Create and retain logs, and review them for anomalies
- 3.12.1 and 3.12.3 (Assess and Monitor Controls): Periodic assessment plus ongoing monitoring
- 3.4.3 (Change Control): Formal change management process for system changes
- 3.10.1–3.10.5 (Physical Protection): Lock down server rooms, restrict physical access, escort visitors, keep access logs
- 3.11.1 (Risk Assessment): Periodic risk assessment and mitigation planning
Phase 3: Remaining Controls (Weeks 17–24)
Complete the remaining requirements to reach 110:
- Awareness and Training (AT)
- Remaining Access Control (AC) controls
- Remaining Audit (AU) controls
- Media Protection (MP)
- Personnel Security (PS)
- Configuration Management (CM)
- Maintenance (MA)
- Remaining requirements in IA, IR, RA, CA, SC, and SI
NIST 800-171 Self-Assessment: SPRS Scoring Explained
Your SPRS score comes from the DoD Assessment Methodology (v1.2.1). A Basic assessment is a self-assessment you post in SPRS (through the PIEE portal), as DFARS 252.204-7019/-7020 require. Medium and High assessments are done by DoD (DIBCAC). The same scoring is used for CMMC Level 2.
Scoring methodology:
- Start at 110: the maximum score, with all 110 requirements implemented
- Subtract for each requirement not implemented: 5, 3, or 1 points depending on its weight. There's no fractional credit for "mostly done," and a POA&M doesn't earn points back
- A few partial-credit rules: 3.5.3 (MFA) costs 3 instead of 5 if MFA covers remote and privileged access but not general users; 3.13.11 costs 3 instead of 5 if you encrypt but the cryptography isn't FIPS-validated
- Lowest possible score: -203
- Freshness: your posted score must be no more than 3 years old
- CMMC Level 2 thresholds: Final status = 110. Conditional status with a POA&M requires at least 88/110 (80%), only certain 1-point requirements may be on the POA&M (with limited exceptions), and those items must be closed within 180 days
Scoring example:
- 3.13.1 (Boundary Protection) implemented = no deduction
- 3.5.3 (MFA) in place for remote and privileged access, not yet for general users = -3
- 3.13.11 encryption in use but not FIPS-validated = -3
- 3.1.9 (logon banners) not implemented = -1
- Total example: 110 - 7 = 103. Above 88, but because 3.5.3 is a 5-point requirement that can't go on a CMMC POA&M, it has to be closed before Conditional Level 2 status is possible
Cost and Timeline Estimates
Rough planning ranges, not quotes, and they don't include a C3PAO assessment fee. Your real number depends on how much of your environment touches CUI, how far you're starting from, and how much you do in-house.
| Organization Size | Typical Timeline to L2 Ready | Estimated Cost |
|---|---|---|
| Small (10–25 employees) | 16–20 weeks | $40,000–$75,000 |
| Mid-market (26–100 employees) | 20–26 weeks | $80,000–$150,000 |
| Large (101–500 employees) | 26–32 weeks | $180,000–$350,000 |
| Enterprise (500+ employees) | 32–52 weeks | $400,000–$800,000+ |
Common NIST 800-171 Implementation Gaps
- Weak boundary protection: CUI systems still connected to public networks without firewall/segmentation
- No MFA: Systems relying on single-factor (password-only) authentication
- Unencrypted CUI: Sensitive data stored or transmitted without encryption
- No incident response capability: No tested plan, no way to spot an incident, and no Medium Assurance Certificate ready for 72-hour DIBNet reporting
- Unpatched systems: No defined patch timeframes, or critical vulnerabilities left open well past them
- No SSP maintained: Controls exist but were never documented in a System Security Plan
- Weak access controls: Users have overly broad permissions; no separation of duties
- Inflated SPRS score: Posting a score the evidence can't back up, which creates False Claims Act exposure
Want a rough SPRS number? Use our SPRS Score Calculator to estimate your score against the 110 requirements using the DoD Assessment Methodology.
Key Resources
- NIST SP 800-171 Rev 2 (Official) — The version DFARS 7012, SPRS and CMMC Level 2 assess against
- NIST SP 800-171 Rev 3 (Official) — Latest NIST revision, not yet required for DoD contracts
- SPRS Score Calculator — Estimate your score using the DoD Assessment Methodology
- NIST 800-171 Implementation Guide — Detailed roadmap and phased approach
- DFARS Compliance Guide — How NIST 800-171 satisfies DFARS requirements
- CMMC Certification Overview — How NIST 800-171 compliance is verified (C3PAO certification currently voluntary)
Disclosure: Defense Compliance.ai contains affiliate links to compliance software and assessment tools. We recommend tools we've independently vetted; affiliate commissions help fund this resource.