NIST SP 800-171

NIST 800-171: 110 requirements, and the ones that actually fail people.

NIST 800-171 is the standard that says how a company outside the federal government has to protect Controlled Unclassified Information. If you hold a DoD contract with DFARS 252.204-7012 in it, you already owe these 110 requirements — that obligation predates CMMC, is not part of CMMC, and was not touched when CMMC Phase 2 was suspended in July 2026. This page covers the 14 families, how the SPRS score is calculated, where Revision 3 stands, and the handful of requirements that account for most of the failures.

Last reviewed

Where this stands, August 2026

NIST 800-171 is unaffected by the CMMC pause. On 13 July 2026 the Department suspended CMMC Phase 2 and every implementation milestone after it, pending a 60-day reform review reporting in mid-September. What was suspended is the certification machinery. The underlying security requirement — 800-171, imposed through DFARS 252.204-7012 since 2017 — is a contract term you have already signed, and it is still enforceable today. Read the pause as a change to the deadline, not to the work.

What NIST 800-171 is, and who it binds

A federal standard that becomes a private contractual obligation the moment a clause points at it.

NIST Special Publication 800-171 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations — is published by the National Institute of Standards and Technology. On its own it is guidance. It becomes binding when a contract clause references it, and for the defense industrial base that clause is DFARS 252.204-7012, which has required “adequate security” defined as the implementation of 800-171 since 31 December 2017.

That timing matters more than most coverage admits. Companies frequently describe 800-171 as something CMMC brought in. It is the reverse: 800-171 has been a contractual requirement for years, self-attested and largely unverified, and CMMC exists because self-attestation was not producing compliance. When people say CMMC “added” requirements at Level 2, what it added was an assessment. The 110 requirements were already yours.

The trigger is the information, not the size of the company. If Controlled Unclassified Information is processed, stored or transmitted on your systems in the performance of a DoD contract, 800-171 applies to the systems that touch it. A two-person machine shop handling CUI drawings is in scope on the same terms as a prime, which is the single most under-appreciated fact in the defense supply chain.

The 14 families, and where the weight sits families

The 110 NIST 800-171 controls are grouped into 14 families. They are not evenly distributed, and neither is the effort.

FamilyReqsWhat it costs you in practice
Access Control (AC)22The largest family and the one most often over-claimed. Least privilege, separation of duties, remote access control and session lock, evidenced rather than asserted.
System and Communications Protection (SC)16Boundary protection, encryption in transit, and FIPS-validated cryptography — the requirement that most often turns out to be unmet because the product used encryption but not a validated module.
Identification and Authentication (IA)11Multi-factor authentication for all privileged and network access. Rarely a technology problem, frequently a coverage problem: the one legacy system nobody put behind it.
Audit and Accountability (AU)9Logging that is generated, retained, reviewed and protected. Assessors ask who reads the logs and when; “we have them” is not an answer.
Configuration Management (CM)9Baselines, change control, and an accurate inventory. Scoping arguments are won or lost on the inventory.
Media Protection (MP)9Marking, transport, sanitization and disposal — including the CUI that leaves as a PDF attachment.
System and Information Integrity (SI)7Flaw remediation, malicious code protection, monitoring. Patch cadence has to be demonstrable.
Maintenance (MA)6Controlled maintenance, including the supplier engineer with remote access to a machine tool.
Physical Protection (PE)6Access to facilities and equipment. Cheap to satisfy, easy to forget in a distributed workforce.
Security Assessment (CA)4The system security plan and the plan of action. The SSP is the document the whole assessment is run against.
Awareness and Training (AT)3Role-based training with records. Three requirements, and one of the cheapest ways to lose points.
Incident Response (IR)3A tested capability, not a policy. It also has to reconcile with the 72-hour reporting duty in DFARS 252.204-7012.
Risk Assessment (RA)3Periodic assessment and vulnerability scanning, with remediation evidence.
Personnel Security (PS)2Screening, and access removal on termination or transfer.

NIST SP 800-171 Revision 2, the revision in force for DoD work as at 23 August 2026. Counts total 110.

NIST SP 800-171 Revision 2 or Revision 3?

The question that gets answered wrongly more often than any other on this subject.

NIST published NIST SP 800-171 Revision 3 in May 2024. It reorganizes the standard into 17 families and 97 requirements, and introduces organization-defined parameters — values the organization sets rather than inherits. Read on its own, Revision 3 is the current version of the publication.

For DoD work it is not the version that counts. The Department has not authorized Revision 3 for assessments, SPRS scoring or certification; DoD contracts continue to be assessed against Revision 2 and its 110 requirements, held in place by a class deviation issued in 2024. An interim rule to move CMMC assessments onto Revision 3 was on the Department’s regulatory agenda for July 2026 and has not been finalized as at 23 August 2026.

The practical instruction is therefore unusually simple, and worth stating plainly because a lot of published advice gets it backwards: build to Revision 2. If a consultant is scoping your program against 97 requirements and organization-defined parameters, they are working to a standard your assessor will not use. Track Revision 3, because the transition is coming and the delta is manageable if you know it — but do not implement to it yet.

The SPRS score, and why it can go negative

A single number in a government database that decides whether you are eligible to be awarded work.

DFARS 252.204-7019 and 252.204-7020 require a self-assessment against 800-171 and the posting of the resulting score to the Supplier Performance Risk System, SPRS. The scoring method starts at 110 — every requirement implemented — and subtracts points for each one that is not. Deductions are weighted by impact: 5 points for the requirements whose absence exposes the network most directly, 3 points for significant exposure, and 1 point for the rest.

Because the weights are uneven, the floor is not zero. A company that has implemented nothing scores −203. Negative scores are common, they are visible to contracting officers, and they are visible to primes assessing you as a subcontractor. This is the mechanism that quietly turned a compliance exercise into a competitive one: your score is a number a customer can compare against another supplier’s.

Two things follow. First, an honest low score is safer than an optimistic high one — the score is an attestation, and a knowingly false attestation is a False Claims Act exposure, a theory the Department of Justice has already used against contractors. Second, the score is a point-in-time claim about a live environment. It decays. The gap between the number in SPRS and the state of the network is exactly the gap continuous monitoring exists to close.

A NIST 800-171 compliance checklist that survives contact checklist

Not the 110 — those are in the standard. These are the seven things that decide whether the 110 go well.

  • Find the CUI before you design anything
    Where it arrives, where it lands, who forwards it, which contractual clause made it CUI. Almost every over-scoped, over-priced 800-171 program starts with skipping this and defending the whole estate by default.
  • Decide the boundary, then make it real
    An enclave that holds CUI and nothing else is usually cheaper than compliance across the business — but only if the segmentation is genuine and you can show it. A boundary drawn on a diagram and not in the network is worse than no boundary.
  • Write the System Security Plan first, not last
    The SSP is the artifact the assessment runs against. Written afterwards it describes what you wish you had; written first it is the plan. Every requirement needs a stated implementation, an owner and evidence.
  • Score yourself honestly and post it
    Run the scoring method, take the deductions you have earned, and post to SPRS. A candid 62 with a credible plan of action reads better to a prime than a 110 that collapses under one question.
  • Fix the 5-point requirements before anything else
    They cost the most points and, under CMMC, they cannot be deferred on a plan of action. Multi-factor authentication and FIPS-validated cryptography are where this bites hardest.
  • Collect evidence continuously, not at assessment time
    Screenshots, configuration exports, training records, log review notes — dated. Reconstructing twelve months of evidence in the fortnight before an assessment is the single most reliable way to fail one.
  • Flow it down, and verify what comes back
    If your subcontractors touch CUI, they owe the same 110. Collecting their attestation is the minimum; confirming it against what their perimeter actually shows is the part that protects you. The flow-down duty itself sits in DFARS 252.204-7012.

NIST 800-171 vs CMMC

Same requirements. Different question.

The cleanest way to hold the two apart: 800-171 is the standard, CMMC is the verification. CMMC Level 2 does not invent security requirements — it is the same 110 requirements from Revision 2, assessed and given a status that DoD records. CMMC Level 1 is a different and much smaller set, the 15 basic safeguarding requirements from FAR 52.204-21, and applies where only Federal Contract Information is involved. CMMC Level 3 adds 24 requirements selected from NIST SP 800-172 on top of Level 2.

So the honest answer to “should we wait for CMMC to settle before doing 800-171?” is no, and not for motivational reasons. The reform review announced in July 2026 is a review of how compliance is verified and how much that verification costs. Nothing in the memo suspends DFARS 252.204-7012, and the Department has been explicit that it is reducing certification burden rather than lowering the security baseline. A company that spends the pause implementing 800-171 is ready for whatever the task force recommends. A company that spends it waiting is not.

For how the levels differ and which one a given contract will demand, see CMMC levels. For what an assessment involves once you are in one, see the CMMC audit.

The half of 800-171 that is not about your network

Your compliance is assessed on your systems. Your risk is not confined to them.

CUI does not stop at your boundary. It goes to the design partner, the test house, the machine shop, the logistics provider — and each of those is a system you are required to flow requirements down to and are not permitted to inspect. What you get back is an attestation and, if you ask well, an SPRS score.

An attestation is a claim about a network on the day it was written. Between that day and the incident, the supplier stands up a new remote access gateway, exposes an RDP port during a migration, lets a certificate lapse, or is acquired by a company with a different security culture. None of that reaches you through the attestation process, and all of it is visible from outside.

That is the case for monitoring the defense supply chain continuously rather than annually: not to replace the paperwork, which is contractually required, but to know when the paperwork has stopped being true. RiskXchange rates suppliers from the outside, without their cooperation, and tells you when something changes — supplier risk management covers how that works in practice.

NIST 800-171 questions.

How many controls are in NIST 800-171?
110 security requirements across 14 families, in Revision 2 — the revision DoD assesses against. Revision 3, published in May 2024, restructures these into 97 requirements across 17 families, but has not been authorized for DoD assessments as at August 2026.
Who has to comply with NIST 800-171?
Any non-federal organization that processes, stores or transmits Controlled Unclassified Information under a contract that requires it — most commonly through DFARS 252.204-7012 for DoD work. It applies at every tier of the supply chain, not only to prime contractors.
Is NIST 800-171 the same as CMMC?
No. NIST 800-171 is the standard; CMMC is the program that verifies it. CMMC Level 2 assesses the same 110 requirements. CMMC Level 1 is a smaller set of 15 requirements from FAR 52.204-21, and Level 3 adds 24 requirements selected from NIST SP 800-172.
What is a good SPRS score?
110 is full implementation. 88 or above is the threshold CMMC uses for a conditional Level 2 status, being 80% of the maximum. Scores can be negative — the floor is −203 — because unimplemented requirements are weighted 1, 3 or 5 points by impact rather than counted equally.
Did the CMMC pause in July 2026 suspend NIST 800-171?
No. The suspension covers CMMC Phase 2 and the implementation milestones after it. DFARS 252.204-7012, and the 800-171 requirements it imposes, are unchanged and remain enforceable contract terms.
Do subcontractors have to meet NIST 800-171?
Yes, where they handle CUI in performance of the contract. The requirement flows down through every tier, and the prime is responsible for ensuring it has. A subcontractor handling only Federal Contract Information has a lighter obligation.

Your suppliers attested. Is it still true?

Book a 30-minute call and we will rate one of your CUI-handling suppliers from the outside — no questionnaire, no cooperation required, and no wait for their next attestation cycle.