Skip to main content
Promotional banner for the pentest readiness checklist
Category: Security Frameworks

NIST SP 800-171

Also known as: SP 800-171, NIST Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
Simply put

NIST SP 800-171 is a publication from the U.S. National Institute of Standards and Technology that sets out recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI). It applies chiefly to non-federal organizations, such as contractors and suppliers, that hold or process CUI on their own systems. It is guidance developed by NIST rather than a law in itself, though its requirements may become binding when incorporated into federal contracts or other agreements.

Formal definition

NIST SP 800-171 is a NIST Special Publication providing recommended security requirements aimed at protecting the confidentiality of Controlled Unclassified Information (CUI) when that information resides in nonfederal systems and organizations. It was developed by NIST in connection with its statutory responsibilities under the Federal Information Security Modernization Act, and it focuses specifically on confidentiality protections for CUI in non-federal environments (for example, contractors and other entities handling CUI on their own networks). As a NIST publication it is guidance rather than regulation; its requirements carry legal or contractual force only where incorporated by reference into a federal contract, agreement, or an implementing rule, and application depends on the specific contractual and CUI-handling context. The publication has been issued in multiple revisions (Revision 2 and the later Revision 3), and the specific control requirements differ between versions, so readers should confirm which revision applies to their situation and verify against the current official NIST text.

Why it matters

NIST SP 800-171 addresses a persistent gap in federal information protection: sensitive but unclassified government information routinely leaves federal systems and lands on the networks of contractors, subcontractors, universities, and other non-federal entities. Once Controlled Unclassified Information (CUI) resides outside government-controlled environments, the confidentiality protections that apply on federal systems no longer automatically follow it. The publication provides a common set of recommended security requirements so that organizations handling CUI on their own systems apply consistent safeguards to that information.

The practical significance of SP 800-171 comes less from the document itself than from how it is used. As a NIST publication, it is guidance rather than law; its requirements acquire legal or contractual force only when incorporated by reference into a federal contract, agreement, or an implementing rule. Where such incorporation occurs, an organization's ability to win or retain federal business may depend on demonstrating conformance with the applicable requirements. This makes SP 800-171 a frequent touchstone for contractors and suppliers in the federal supply chain, even though the underlying document does not itself impose obligations.

Because the publication has been issued in multiple revisions, with control requirements differing between versions, the specific expectations placed on an organization depend on which revision a given contract or rule references. Organizations should not assume that meeting one revision satisfies a requirement pinned to another, and they should confirm the operative version rather than treat the standard as a single fixed target.

Who it's relevant to

Federal contractors and suppliers handling CUI
Non-federal organizations that hold or process Controlled Unclassified Information on their own systems are the primary audience for SP 800-171. Where a contract or implementing rule incorporates the publication by reference, conformance with the applicable requirements may become a condition of the contractual relationship. These organizations should determine whether their agreements reference the standard and, if so, which revision applies.
Compliance and information security professionals
Personnel responsible for implementing confidentiality safeguards for CUI use SP 800-171 as the reference set of recommended security requirements. Because the control requirements differ between Revision 2 and Revision 3, these professionals need to confirm the operative version for each relevant contract rather than assuming a uniform requirement, and should verify their reading against the current official NIST text.
Contracting and procurement teams
Those drafting, negotiating, or administering federal contracts and supplier agreements should understand that SP 800-171 is guidance that carries force only where incorporated by reference. How the publication is cited, and which revision is specified, shapes the obligations placed on suppliers and the basis on which conformance is expected.
Subcontractors and supply-chain participants
Requirements tied to CUI protection can flow down through the supply chain to entities that process or store such information on behalf of a prime contractor. Organizations further down the chain should assess whether CUI reaches their systems and whether SP 800-171 requirements apply to them through their contractual arrangements.

Inside SP 800-171

Purpose and Scope
NIST SP 800-171 is a publication of the U.S. National Institute of Standards and Technology that provides recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when it resides in nonfederal systems and organizations. It is guidance in origin, though it becomes contractually binding when incorporated into federal contracts or acquisition regulations.
Controlled Unclassified Information (CUI)
The category of information the publication is designed to protect. CUI is information that is not classified but that federal law, regulation, or government-wide policy requires to be safeguarded. The requirements focus specifically on the confidentiality of this information rather than all security objectives equally.
Security Requirement Families
The requirements are organized into families addressing areas such as access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, and other control domains. Practitioners should verify the exact families and requirement text against the current revision, as content is periodically updated.
Basic and Derived Requirements
Within families, requirements have historically been expressed in a structure distinguishing higher-level obligations from more specific supporting ones. The precise structure and numbering can change between revisions, so the authoritative published version should be consulted.
Relationship to Federal Contracts
Compliance with SP 800-171 is generally mandated for certain nonfederal organizations through contractual flow-down clauses rather than by the publication itself. Its legal force in a given case depends on the specific contract, acquisition regulation, or agency requirement that references it.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-171.

Is NIST SP 800-171 a law that organizations are legally required to follow?
NIST SP 800-171 is a publication issued by the National Institute of Standards and Technology, not a statute or regulation in itself. On its own it is guidance describing security requirements for protecting Controlled Unclassified Information (CUI). It generally acquires binding force only when it is incorporated by reference into a contract, regulation, or agency requirement. In the U.S. federal contracting context, for example, contractual clauses may obligate certain contractors and subcontractors to implement its requirements. Absent such incorporation, it functions as a voluntary reference framework. Because the mechanisms that make it enforceable are contractual or regulatory rather than inherent to the document, readers should verify the specific obligation that applies to their situation against the governing contract or authoritative source.
Does implementing NIST SP 800-171 mean an organization is 'certified' as compliant?
Not necessarily. Implementing the requirements in NIST SP 800-171 is a matter of compliance with a set of security requirements, which is distinct from formal certification by an external body. The publication itself does not establish a certification scheme; historically, demonstrating conformity has often relied on self-assessment against the requirements. Separate certification or assessment programs may exist that reference these requirements, but those are distinct mechanisms with their own scope, versions, and assessing parties. Because assessment and certification arrangements change over time, readers should confirm what form of demonstration—self-attestation, third-party assessment, or otherwise—applies to their circumstances against the current authoritative source.
Who typically needs to implement NIST SP 800-171?
The requirements are generally aimed at nonfederal organizations that store, process, or transmit Controlled Unclassified Information, such as contractors and subcontractors handling CUI on behalf of U.S. federal agencies. Whether a particular organization is in scope depends on the specific contractual clauses, flow-down requirements, and agency rules that apply to it, and on whether it actually handles CUI. Applicability is fact-specific, so an organization should determine its obligations by reviewing its contracts and consulting the relevant agency requirements rather than assuming coverage or exemption.
How does an organization identify what falls within the scope of these requirements?
Scoping generally begins with identifying where Controlled Unclassified Information resides and flows within the organization's systems, and then determining which components store, process, or transmit that information. Systems and personnel that handle CUI, and those that can affect the security of such systems, are typically considered in scope. Because scope determinations depend on the organization's specific data flows and system architecture, and because interpretations of boundaries can vary, organizations should document their scoping decisions and verify their approach against the current authoritative guidance and any applicable contractual direction.
How is conformity with NIST SP 800-171 typically demonstrated?
Demonstration of conformity has commonly involved a self-assessment against the requirements, often supported by documentation such as a system security plan and a record of any deficiencies together with plans to remediate them. Depending on the applicable contractual or regulatory requirements, some form of external assessment may also be required. The specific expectations—including what documentation must be maintained and whether a third party must be involved—can vary by contract and can change over time, so organizations should confirm the applicable expectations against the governing requirements and the current published version.
What should an organization do about requirements it cannot immediately meet?
Where certain requirements are not yet fully implemented, organizations have generally documented such gaps and the associated remediation actions, for example through a plan tracking outstanding items and timelines, alongside a description of the implemented security controls. Whether unmet requirements are contractually permissible, and under what conditions, depends on the specific obligations that apply; some arrangements may allow documented remediation plans while others may not. Because these expectations are fact-specific and subject to change, organizations should confirm the acceptable treatment of open items against the governing contract and the current authoritative source, and apply professional judgment to their particular circumstances.

Common misconceptions

NIST SP 800-171 is a law that applies to all organizations handling sensitive data.
It is a NIST guidance publication, not a statute or regulation in itself. It carries obligation primarily where it is incorporated into a federal contract or referenced by an acquisition regulation. Organizations outside that scope are not bound by it merely because they handle sensitive information.
SP 800-171 is a certification you can pass or achieve.
The publication sets out security requirements; it is not itself a certification scheme. Demonstrating compliance is typically a matter of assessment against the requirements, which is distinct from formal certification. Readers should verify what form of assessment or attestation a specific contract requires.
SP 800-171 covers all aspects of security and privacy for CUI.
Its focus is specifically on protecting the confidentiality of CUI in nonfederal systems. It is not a comprehensive framework addressing every security objective or privacy obligation, and other requirements may apply depending on the data, sector, and jurisdiction.

Best practices

Confirm whether SP 800-171 applies to your organization by reviewing the specific contract clauses, acquisition regulations, or agency requirements that reference it, rather than assuming universal applicability.
Identify and inventory where CUI is created, stored, processed, and transmitted within your nonfederal systems, since the requirements attach to that information.
Always work from the current published revision of the document, as the requirement families, structure, and numbering are periodically updated by NIST.
Distinguish an assessment against the requirements from any formal certification a contract may separately mandate, and verify which form of demonstration is expected.
Treat SP 800-171 as one component of a broader security posture, and check for additional security or privacy obligations arising from other applicable regulations or sector requirements.
Engage qualified professionals to apply the requirements to your specific circumstances, as compliance is fact-specific and this material is informational rather than legal advice.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."