Compliance

NIST SP 800-171

The NIST standard for protecting CUI in non-federal systems. Revision 2 — the revision DoD assesses — specifies 110 security requirements and forms the basis of CMMC Level 2 and DFARS 252.204-7012 compliance.

In-Depth

NIST Special Publication 800-171 "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" organizes Revision 2's 110 security requirements across 14 families: Access Control, Awareness & Training, Audit & Accountability, Configuration Management, Identification & Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System & Communications Protection, and System & Information Integrity. Revision 3 (published May 2024) restructured the requirements, but it is not what DoD assesses: 32 CFR 170.14(c)(3) states that "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2", and DFARS 252.204-7012(b)(2)(i) applies the revision in effect when the solicitation was issued. Scoring, requirement numbering and the 110 count all refer to Revision 2.

Check Your CMMC Readiness

Run our free compliance tools to see where your organization stands.

Audit Your Tech Stack Free

Turn this gap analysis into a remediation plan

This NIST SP 800-171 explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.

Apply for an evaluation

Related: how much CMMC certification costs — DoD’s own priced figures