what-is-nist-sp-800-171

Key takeaways

  • NIST SP 800-171 is the federal publication setting out how contractors protect Controlled Unclassified Information on their own systems.
  • Defense work still runs on Revision 2 and its 110 requirements, which NIST withdrew in May 2024.
  • The transition to CMMC Phase 2 has been suspended since 13 July 2026, so new requirements can only specify Level 1 (Self) or Level 2 (Self). DFARS 252.204-7012 is untouched.
  • MORSECORP reported a score of 104, a consultant later put the real figure at -142, and the company paid $4.6 million. 
  • Draft evidence fails an assessment. Working papers and unapproved policies do not count, and a missing SSP stops it outright.

What is NIST SP 800-171?

NIST SP 800-171 is a federal publication titled Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. It sets the security requirements a private company must meet to protect Controlled Unclassified Information (CUI) on its own systems. The requirements address confidentiality.

The National Institute of Standards and Technology develops and publishes the requirements. Applying them, and resolving any compliance question they raise, falls to the federal agency holding your contract. A contract or agreement is what puts them in force.

The requirements reach only the system components that process, store, or transmit CUI, plus any component that provides protection for those. Systems that never touch CUI sit outside the assessment boundary.

Revision 2 was published in February 2020 and updated on January 28, 2021. NIST withdrew it on May 14, 2024, and replaced it with Revision 3. Defense contracts stayed on the older version.

What is CUI (controlled unclassified information)?

CUI is unclassified information that a law, regulation, or government-wide policy tells an agency to protect or restrict. Executive Order 13556 set up the program and put the National Archives and Records Administration in charge as Executive Agent, and the Archivist passed those responsibilities to the Information Security Oversight Office. 

The implementing rule, 32 CFR Part 2002, binds agencies and any outside organization that comes into contact with CUI.

  1. CUI vs. FCI

Federal contract information is the non-public material that changes hands because of a government contract, whether the agency gives it to you or you produce it while delivering the product or service. 

CUI turns on origin: the government made it or holds it, or a company made it or holds it on the government's behalf. NARA's summary is that every piece of CUI a contractor holds counts as FCI, though not all FCI is CUI. Material that never came from an agency, and that nobody created for one, falls outside CUI entirely.

  1. CUI Basic vs. CUI Specified

The dividing line is the authority itself. If it demands protection without naming the controls, you are dealing with CUI Basic, and NARA's standard control set governs. If it prescribes its own controls, the information is CUI Specified. If it prescribes only part, the label stays Specified and Basic fills whatever is left open.

Who has to comply with NIST SP 800-171?

NIST SP 800-171 reaches non-federal organizations that handle CUI under a federal contract. For defense work, the obligation arrives through DFARS 252.204-7012.

Costing a government-wide version of the same duty, the FAR Council put the annual population at 22,680 contractors and subcontractors, 15,809 of them small businesses.

  1. Flow-down to subcontractors

A prime that sends CUI to a subcontractor must pass along the compliance obligations with it, and under the proposed FAR rule that duty reaches every subcontract tier. 

  1. Civilian contractors and the proposed FAR CUI rule

Civilian agencies have never had a single clause matching DFARS 7012. FAR Case 2017-016 was written to create one. Its January 2025 version was named Revision 2 and deferred Revision 3 until the government settled on how to standardize the organization-defined parameters.

The June 2026 overhaul rule renumbers the clause to FAR 52.240-7 and updates its standard form to identify the applicable parameters for Revision 3. Comments closed July 23, 2026.

Rev 2 vs. Rev 3: Which one applies right now?

Revision 2 applies.

DFARS 252.204-7012 as codified ties you to whichever version of NIST SP 800-171 was in effect when the solicitation was issued. A class deviation replaces that text. Contracting officers shall use the deviation clause in place of the published one, and it requires Revision 2 instead of the version current at solicitation. DoD issued it on May 2, 2024, and revised it that same month. It remains in effect until rescinded.

NIST SP 800-171 Revision 2 governs DFARS 252.204-7012 and CMMC Level 2 despite being withdrawn, while Revision 3 applies to nothing yet

The clause is also being relocated. A separate deviation replaced DFARS Part 204 from February 17, 2026, reserving both the safeguarding subpart that prescribed 252.204-7012 and the CMMC subpart, with the revised text pointing to DFARS Part 240.

The 110 requirements and how they are organized

The CMMC program rule defines its security requirements as the 15 Level 1 requirements from FAR 52.204-21 plus the 110 Level 2 requirements from Revision 2.

Level 2's requirements are identical to Revision 2's, and CMMC's domains map to Revision 2's requirement families.

Each requirement breaks into assessment objectives, and the rule requires meeting all applicable objectives in NIST SP 800-171A June 2018.

CMMC defines periodic compliance as a regular interval the contractor sets, capped at one year.

Some systems cannot be brought into full compliance. The rule allows enduring exceptions for cases like medical devices and operational technology. No operational plan of action is needed, though the circumstance must be documented in the system security plan.

The DFARS deviation clause lets a contractor submit a written request to the contracting officer to vary from a requirement for the DoD CIO to consider. Where the CIO finds a requirement nonapplicable, or accepts an alternative as equally effective, the contractor need not implement it. Prior approvals do not carry across contracts, so a copy has to go to the contracting officer for recognition each time.

How NIST SP 800-171 fits with DFARS and CMMC

DFARS 252.204-7012 and CMMC both attach to the same 110 requirements, and each has its own additional obligations: 

  1. What DFARS 252.204-7012 adds

A cyber incident affecting covered defense information must be reported to DoD within 72 hours of discovery, through DIBNet. Images of affected systems and relevant monitoring data then have to be held for at least 90 days, giving DoD a window to ask for them. A cloud provider storing or transmitting covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline. 

The clause flows down to subcontracts without alteration, and the prime decides whether the information keeps its identity as covered defense information.

  1. What CMMC adds

A contracting officer checks SPRS and cannot award to an offeror lacking a current status at the required level. A Final Level 2 assessment stays current for three years, while the affirmation of continuous compliance must be no older than one year. A conditional status permits award at Level 2 for up to 180 days. Level 1 requires a final status before award.

How your compliance gets scored

A Level 2 score starts at the total number of requirements and falls. Each requirement assessed as NOT MET subtracts its own value, which can push the total below zero.

Requirements are worth 1, 3, or 5 points. The five-point ones are those whose absence could lead to significant exploitation of the network or exfiltration of CUI.

Two requirements carry partial credit. Multi-factor authentication costs three points where it covers only remote and privileged users, and five where it covers nobody. Encryption that is employed but not FIPS-validated costs three.

CMMC Level 2 scoring starts at 110 and subtracts 5, 3 or 1 point per unmet requirement, with partial credit only for MFA and FIPS-validated encryption.

At Level 1, every requirement must be fully implemented, no plan of action is permitted, and the result is scored MET or NOT MET in its entirety.

SPRS stores the result and states the assessment cannot be performed there. Entering one requires a Cyber Vendor User role in PIEE.

The SSP, POA&M, and your body of evidence

An SSP has to be current at the time of assessment and has to describe each information system within the assessment scope. Without one, the finding is that an assessment could not be completed due to incomplete information and noncompliance with DFARS 252.204-7012.

A plan of action is not a substitute for a completed requirement. Anything unimplemented is assessed NOT MET either way.

A requirement is MET only where all applicable objectives are satisfied on evidence in final form. Working papers, drafts, and unapproved policies do not count.

Where the DoD CIO has found a requirement nonapplicable or an alternative equally effective, that adjudication must be in the system security plan to count, and only where the environment has not changed.

How NIST SP 800-171 is enforced 

Enforcement runs on two tracks. One decides whether you win work. The other decides what happens after you have told the government you were compliant.

  1. What the July 2026 Phase 2 suspension did and didn't change

On 13 July 2026, the Department of War suspended the November 2026 transition to Phase 2. During the suspension, program managers may only require Level 1 (Self) or Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).

Requiring activities holding those requirements in an active solicitation must produce an amended requirements document, and the contracting officer must issue the amendment as soon as practicable. Existing contracts get modified before the next option is exercised or at the next administrative modification. No waivers are granted during the review.

The Department says it will enforce NIST SP 800-171 Rev 2 through Level 1 and Level 2 self-assessment and select Government-led assessments, and DFARS 252.204-7012 remains in effect.

  1. False Claims Act exposure

Your own compliance report is a claim the government can sue on.

MORSECORP paid $4.6 million in March 2025 and admitted the facts. It reported a score of 104 in January 2021. A consultant told it the real figure was −142 in July 2022, and the score was not corrected until June 2023, three months after a subpoena arrived. LOGZONE paid $507,144 in June 2026 after DCMA assessed its implementation at −170, at the low end of a range running from −203 to 110.

Honeywell Aerospace paid $2,042,518 on 1 September 2026 over one network between April 2020 and December 2023.

The MORSECORP and Honeywell cases both started as whistleblower suits. The LOGZONE and Honeywell settlements resolve allegations without a determination of liability.

How to get compliant with NIST SP 800-171

The boundary you draw determines how many requirements you have to implement and evidence.

For a Level 2 assessment, every asset falls into one of five categories. Four sit inside the scope, covering assets that handle CUI, assets that provide security functions, assets that could handle CUI but are not meant to, and specialized assets such as operational technology. Out-of-scope assets sit outside it.

DoD's guide states that separation is required only for out-of-scope assets, and that separating assets limits the assessment scope. Logical separation blocks data transfer between connected assets through software or network controls. Physical separation means no connection, leaving manual transfer as the only route.

An enterprise-wide tool does not put the whole enterprise in scope. Where a central IT group deploys one anti-malware product, that tool and the people running it can sit in scope while other enterprise functions do not.

For an external provider, the test is whether CUI or security protection data resides on their systems. Staff augmentation, where you supply the processes and technology, needs no assessment of its own.

Operational changes inside your existing boundary can ride on the annual affirmation. 

How Koop helps with NIST SP 800-171 compliance

Koop's NIST SP 800-171 offering starts with scoping and a gap assessment, so the control set is narrowed to your environment. The SSP, the POA&M, GovCloud integrations, and the SPRS score are managed together. Pre-built templates and integrations pull evidence in order for audit, and Koop offers access to a network of C3PAO auditors alongside its own experts.

Requirements management covers the contract side, extracting obligations from agreements and cross-mapping them, which matters when a prime flows a clause down to you, and you flow it down again.

Koop reports that its Housekeeper AI agent automates up to 95% of compliance tasks.

See your scope and evidence in one place.

Book a demo

Frequently asked questions

  1. Is there a NIST SP 800-171 certification?

No. NIST develops and publishes the requirements, and applying them falls to the agency holding your contract. Certification exists under CMMC, where an assessment by a third-party organization produces a CMMC status. Since July 2026, the Department of War has suspended designating that third-party level in new requirements.

  1. Does NIST SP 800-171 apply to subcontractors?

Yes. The DFARS clause passes down to subcontracts without alteration wherever performance involves covered defense information. Whether the information keeps that identity as it moves down the chain is the prime's call.

  1. What is the difference between NIST SP 800-171 and CMMC?

NIST SP 800-171 is the control set. CMMC is the program that verifies it and ties the result to award eligibility.

‍

‍

article highlights: