Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What Is NIST 800-171?

The control set for protecting controlled unclassified information, and the backbone of CMMC Level 2.

NIST SP 800-171 is a publication from the National Institute of Standards and Technology that defines the security requirements for protecting Controlled Unclassified Information (CUI) when it is stored or processed on systems outside the federal government. It is the standard defense contractors have been required to follow under DFARS clause 252.204-7012 since 2017, and it is the control set behind CMMC Level 2.

What it contains

110 security requirements grouped into 14 families:

  • Access Control
  • Awareness and Training
  • Audit and Accountability
  • Configuration Management
  • Identification and Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical Protection
  • Risk Assessment
  • Security Assessment
  • System and Communications Protection
  • System and Information Integrity

What the requirements look like in practice

Multi-factor authentication for network and privileged access. Least-privilege accounts. Logging that can reconstruct who did what. Encryption of CUI in transit and at rest. Patching and vulnerability scanning. An incident response capability. Security awareness training. A written System Security Plan (SSP) describing how each requirement is met, and a Plan of Action and Milestones (POA&M) for gaps.

Revisions

NIST published Revision 3 in 2024, which reorganized and consolidated requirements. The CMMC program currently assesses against Revision 2, so contractors should confirm which revision their contracts and assessors reference.

Scoring and SPRS

Contractors self-score against the 110 requirements using the DoD assessment methodology and report the score to the Supplier Performance Risk System (SPRS). A perfect score is 110; unmet requirements subtract points. Primes and the DoD can see this score.

Relationship to other frameworks

800-171 is a subset tailored from the larger NIST SP 800-53 catalog. It overlaps heavily with the CIS Controls and the NIST Cybersecurity Framework, so a business already aligned to those has a head start. See what is the NIST Cybersecurity Framework, what is CMMC and CMMC levels explained.

Mentis Group implements 800-171 controls and maintains the evidence for defense-supply-chain clients through Enhanced Cybersecurity and our recurring framework audits.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.