NIST SP 800-171
Information SecurityIssued by National Institute of Standards and Technology (NIST)
NIST Special Publication 800-171 specifies security requirements for protecting Controlled Unclassified Information (CUI) when it resides in nonfederal systems — that is, on the systems of contractors and other organisations doing business with the US government rather than in federal systems themselves. The current edition is Revision 3, published May 2024, which restructured the requirement families and realigned them with the controls in SP 800-53. It matters commercially because compliance is contractually mandated rather than voluntary: DFARS clause 252.204-7012 requires defence contractors handling CUI to implement it, and it forms the technical basis of the CMMC certification programme, so failing to meet it can disqualify an organisation from federal contracts.
Get notified the moment NIST SP 800-171 actually changes — reviewed by a human before it ever reaches you.
Get started freeMost recent update
No published updates yet
This framework hasn't had a confirmed update yet — check back after the next monitoring run.