NIST SP 800-171

CG

Chad Griffith, Founder & CEO

FileFlo — AI compliance document intelligence for DOT, OSHA, and EPA regulated businesses. LinkedIn · About

Last reviewed · By Chad Griffith

NIST Special Publication 800-171 ('Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations') is the National Institute of Standards and Technology publication that defines the cybersecurity requirements applicable to nonfederal systems handling Controlled Unclassified Information (CUI). The current revision (Revision 2, published February 2020) contains 110 security requirements organized into 14 control families. NIST 800-171 is the technical standard underlying both DFARS 252.204-7012 (the contract clause requiring CUI safeguarding) and CMMC Level 2 certification.

Frequently Asked Questions

What are the 14 control families in NIST 800-171?

Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System and Communications Protection (SC), and System and Information Integrity (SI).

What is the difference between NIST 800-171 r2 and r3?

Revision 2 (current as of 2026 for compliance purposes) contains 110 security requirements with the structure used in CMMC 2.0. Revision 3 (May 2024) reorganized the document, increased the number of requirements, and added structure changes. The DoD has not yet transitioned CMMC to r3 — CMMC 2.0 still references r2. Contractors should implement r2 for CMMC compliance until DoD officially transitions.

Who is responsible for implementing NIST 800-171 in cloud environments?

Implementation responsibility follows the cloud shared responsibility model. The cloud service provider (CSP) implements infrastructure-level controls under their FedRAMP Moderate or equivalent authorization. The contractor (customer) remains responsible for application-level and data-level controls. Both responsibilities must be documented in the SSP.

How is NIST 800-171 scored?

DoD assessment methodology assigns weighted point values to each control. Contractors start with a maximum score of 110 and lose points for missing or partially-implemented controls. Most controls are weighted at 1, 3, or 5 points depending on importance. The DoD Assessment Methodology guide details the scoring approach used in self-assessments and C3PAO assessments.

Authoritative sources

Related terms

FileFlo classifies and tracks compliance documents against rule packs that map directly to the regulators referenced above. Run a free CFR-cited audit →