NIST 800-171: protecting CUI, requirement by requirement
NIST 800-171 is the federal standard for protecting controlled unclassified information wherever it lives outside the government itself: on the systems of a defense contractor, a subcontractor several tiers down the supply chain, a university research lab, or any other nonfederal organization handling CUI under a federal contract or grant. Formally NIST Special Publication 800-171, the standard defines 110 security requirements grouped into fourteen families, and a contractor demonstrates compliance through a self-assessment methodology that produces a numeric score, the same score most defense contractors already post to the Supplier Performance Risk System under existing DFARS clauses, independent of whatever CMMC certification obligation may also apply to the same contract.
What NIST 800-171 is
NIST published the first version of 800-171 in 2015 for a specific reason: controlled unclassified information routinely leaves federal networks and lands on the systems of contractors, grantees, and other nonfederal organizations, and NIST SP 800-53, the government's own control catalog, was written for federal systems, not for a small manufacturer's shop-floor network. 800-171 translates a relevant subset of that federal control set into requirements a nonfederal organization can reasonably implement.
The standard organizes 110 individual requirements into fourteen families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Every requirement maps back to a corresponding NIST SP 800-53 control, so an organization already assessed against that federal control catalog is rarely starting from nothing.
NIST released Revision 3 in 2024, reorganizing and consolidating some requirements, introducing organization-defined parameters that give implementers more flexibility in how a requirement is met, and tightening alignment with the 800-53 moderate baseline. Rev 3's adoption timeline into DoD's own assessment methodology and CMMC is still being finalized as this is written, so confirm which revision a given contract actually requires before assuming Rev 3 already governs your assessment.
Who needs NIST 800-171
800-171 reaches well beyond the Department of Defense. Any nonfederal organization that a federal contract, subcontract, or grant designates as a recipient or handler of controlled unclassified information is in scope, regardless of which agency is on the other end of the relationship.
- Defense contractors and subcontractors handling CUI under DFARS clause 252.204-7012, the clause that has required 800-171 implementation since well before CMMC existed.
- Civilian agency contractors handling CUI under similarly structured clauses at agencies such as NASA, the Department of Energy, or the General Services Administration.
- Universities and research institutions handling CUI as part of federally funded research, particularly export-controlled technical data and unpublished research results.
The trigger is the information, not the industry. A machine shop that never touches a computer network the way a software company does can still be squarely in scope if a technical drawing marked CUI lands in its email inbox, and a cloud vendor whose product happens to store that same drawing inherits the same obligation regardless of how it markets itself.
NIST 800-171 requirements, by requirement family
| Requirement family | Representative concern |
|---|---|
| Access Control | Limiting system access to authorized users and processes |
| Awareness and Training | Ensuring personnel understand CUI-handling responsibilities |
| Audit and Accountability | Creating and retaining logs sufficient to trace actions to individuals |
| Configuration Management | Establishing and enforcing baseline configurations |
| Identification and Authentication | Verifying user and device identity before granting access |
| Incident Response | Establishing capability to detect, report, and respond to incidents |
| Maintenance | Controlling tools, techniques, and personnel used for system maintenance |
| Media Protection | Protecting and sanitizing digital and physical media containing CUI |
| Personnel Security | Screening individuals before granting access, revoking it on departure |
| Physical Protection | Limiting physical access to facilities and equipment |
| Risk Assessment | Periodically assessing risk to CUI and the systems that process it |
| Security Assessment | Periodically assessing whether implemented controls are effective |
| System and Communications Protection | Monitoring and protecting communications at system boundaries |
| System and Information Integrity | Identifying, reporting, and correcting system flaws |
A contractor assesses itself against all 110 requirements using the DoD Assessment Methodology, starting from a maximum score of 110 and subtracting a defined number of points for each requirement not fully implemented. A handful of the highest-weighted requirements, such as multifactor authentication and FIPS-validated cryptography, carry larger point deductions than the rest, which is why a score can drop sharply from a small number of unmet requirements.
The scoring floor is negative: a poorly implemented environment can score as low as negative 203, not zero, because the methodology accounts for entirely missing security domains, not just a partial gap in an otherwise built-out program.
The NIST 800-171 self-assessment process, step by step
Unlike a CMMC Level 2 certification, a standard 800-171 obligation does not require a third-party assessor by default; the organization runs its own self-assessment and posts the result.
- Identify the systems and boundary that handle CUI: Map exactly where controlled unclassified information is received, stored, processed, or transmitted, since the assessment boundary follows the data, not the org chart; two to six weeks for a first pass.
- Map the fourteen requirement families to the environment: Confirm which of the 110 requirements are relevant given the boundary defined in the prior step, and document the organization-defined parameters where the standard allows flexibility.
- Assess current implementation state per requirement: Evaluate each requirement as fully implemented, partially implemented, planned, or not implemented, backed by evidence rather than intent; typically the longest step, four to ten weeks.
- Score the environment: Apply the DoD Assessment Methodology's point deductions to produce the numeric score, from a maximum of 110 down to as low as negative 203 for a poorly built-out program.
- Document the System Security Plan and POA&M: Write the SSP describing how each requirement is implemented, and the Plan of Action and Milestones for anything not yet in place, with realistic completion dates rather than placeholders.
- Submit the score to SPRS: Post the score, assessment date, and system security plan location to the Supplier Performance Risk System, required before contract award under DFARS 252.204-7019 for covered DoD contracts.
- Refresh the assessment when the environment changes materially: A self-assessment is generally treated as current for up to three years, but a significant change to the environment, such as a new system or a major architecture shift, warrants an earlier refresh rather than waiting out the clock.
How long does NIST 800-171 take and what does it cost?
800-171 is usually cheaper and faster than a CMMC Level 2 certification because there is no C3PAO fee by default, but the underlying implementation work, closing the same 110 requirements, is nearly identical in scope.
A focused, well-scoped small business starting close to zero commonly completes boundary definition through SPRS submission in two to six months. Larger or more complex environments, particularly those with legacy systems that need replacement or significant architecture changes to support logging and access control requirements, can run nine months to over a year.
If an organization runs the self-assessment entirely in-house, the direct cost is internal labor rather than a third-party fee. Advisory support to build the SSP, run the assessment, and document a defensible POA&M typically runs $15,000 to $60,000 for a small business, more for a larger or more complex environment. A formal government-led DIBCAC High assessment, reserved for the highest-priority programs rather than a routine 800-171 obligation, is a separate and less common path with its own cost structure.
ACTA is licensed per environment, and every engagement starts with a conversation. ACTA's own contribution is to the assessment, scoring, and documentation work described above, generated from the live environment rather than a point-in-time review.
Common failure points
Most 800-171 problems trace back to the assessment being treated as a paperwork exercise rather than an operational discipline.
- Self-scoring optimistically, rounding a partially implemented requirement up to fully implemented, which surfaces later in a DoD spot check or a CMMC C3PAO review of the same environment.
- Treating the score posted to SPRS as the end of the obligation rather than a snapshot that needs to stay current as the environment changes.
- Inconsistent CUI marking and flow-down practices, so the boundary the assessment is supposed to cover is unclear from the start.
- A System Security Plan written once at kickoff and never updated as systems, vendors, or architecture change.
- Misapplying the standard's organization-defined parameters, assuming more flexibility than the specific contract clause actually allows.
- Waiting for the Rev 3 transition to fully settle before doing anything, when the current revision's obligations still apply today.
How ACTA automates NIST 800-171
ACTA's federal pack library includes NIST 800-171 alongside FedRAMP, CMMC, and the DoD Cloud Computing SRG, and every pack ships with every license: an organization managing CUI obligations under more than one contract vehicle is not paying separately for each one. The pack is editable YAML, so the 110 requirements map to a specific environment's actual configuration rather than a generic narrative.
ACTA can provision the CUI boundary itself as code, on AWS commercial, AWS GovCloud, Microsoft GCC High, Azure, Google Cloud, or bare metal, with a small environment standing up in roughly 25 minutes, which matters for 800-171 specifically because so much of the assessment burden is proving what the environment actually looks like today, not what a document from a year ago claimed.
ACTA runs on goRapide, BMD's deterministic causal engine, with no LLMs, no agents, and no probabilistic components anywhere in the compliance path. Scoring the same environment twice, whether for an internal refresh, a prime's flow-down verification request, or a later CMMC Level 2 effort built on the same 110 requirements, produces the identical score and the identical evidence both times, with an inspectable causal chain behind every point deducted.
From that live environment, ACTA generates the System Security Plan, the SPRS scoring package, POA&M, control narratives, and evidence binder, and continuous monitoring afterward tracks credential health, evidence freshness, and drift from previously passing requirements, refreshing a stale posture to current in two clicks rather than waiting for the next scheduled refresh cycle to notice it slipped.
NIST 800-171 and adjacent frameworks
800-171's 110 requirements are the technical core of CMMC Level 2: the certification program does not change what is required, it changes who verifies that the requirements are met. An organization that keeps a disciplined, current 800-171 self-assessment is already most of the way to Level 2 readiness if a contract later requires it.
Level 2 specifically, including the self-assessment versus C3PAO-certification split and the rules governing open POA&M items, is covered in full on the CMMC Level 2 page.
800-171 also has a cloud-hosting counterpart rather than a competitor: an organization storing CUI in a cloud environment still needs to confirm that cloud's own authorization under the DoD Cloud Computing SRG, since protecting the information and authorizing the infrastructure that hosts it are evaluated on separate tracks even when the same data drives both.
For how 800-171 relates to the federal control catalog it draws from and the wider set of frameworks a contractor or grantee is likely to encounter, see the full compliance framework library.
Frequently asked questions
What are the fourteen NIST 800-171 requirement families?
Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity, totaling 110 individual requirements across the fourteen families combined.
How is a NIST 800-171 self-assessment scored?
The DoD Assessment Methodology starts at a maximum of 110 points and subtracts a defined amount for each requirement not fully implemented, with the highest-weighted requirements carrying the largest deductions. A poorly built-out environment can score as low as negative 203, since the methodology also penalizes entirely missing security domains.
Is NIST 800-171 the same as CMMC?
No. NIST 800-171 is the underlying control standard, 110 requirements across fourteen families. CMMC Level 2 uses those same 110 requirements but adds a certification and assessment structure, most often an independent C3PAO assessment, on top of what 800-171 alone requires.
What changed in NIST 800-171 Revision 3?
Rev 3, released in 2024, reorganized and consolidated some requirements, introduced organization-defined parameters for more implementation flexibility, and tightened alignment with the NIST SP 800-53 moderate baseline. Its adoption timeline into DoD's assessment methodology and CMMC was still being finalized as this was written, so confirm current status.
Who does NIST 800-171 apply to?
Any nonfederal organization, a defense contractor, a civilian agency contractor, a subcontractor several tiers down the supply chain, a university, or a research institution, that a federal contract or grant designates as a handler of controlled unclassified information, regardless of which federal agency the relationship traces back to.
How often do I need to reassess against NIST 800-171?
A self-assessment is generally treated as current for up to three years, but a material change to the environment, a new system, a significant architecture shift, or a new vendor handling CUI, warrants an earlier refresh rather than waiting for the three-year mark.
What is the connection between NIST 800-171 and DFARS?
DFARS clause 252.204-7012 requires covered defense contractors to implement NIST 800-171 and report cyber incidents within 72 hours. Clauses 252.204-7019 and 252.204-7020 require posting a current assessment score to SPRS before award and allow the government to verify that assessment.
What is the lowest possible NIST 800-171 self-assessment score?
Negative 203. The scoring methodology does not stop at zero for a completely unimplemented program; it continues to subtract points for entirely missing security domains, which is why a small number of foundational gaps can produce a sharply negative result.
Do I need a third party to assess NIST 800-171?
Not by default. A standard 800-171 obligation is satisfied by a self-assessment the organization runs itself and posts to SPRS. A third-party assessment becomes relevant only if a specific contract requires CMMC Level 2 certification or, rarely, a government-led DIBCAC assessment for the highest-priority programs.