NIST SP 800-171 (Protecting CUI in Nonfederal Systems)
NIST Special Publication 800-171 defines the security requirements that a nonfederal organization must implement when it processes, stores, or transmits Controlled Unclassified Information (CUI) on behalf of the federal government. Rev 2 has 110 requirements across 14 control families. Rev 3 (published May 14, 2024) restructures the document and expands the number of requirements. DFARS 252.204-7012 requires Rev 2. CMMC Level 2 uses Rev 2. Rev 3 will be adopted in future rulemaking.
- glossary
- The 14 Control Families (Rev 2)
The 14 Control Families (Rev 2)
- Access Control (AC): 22 requirements. Who can do what.
- Awareness and Training (AT): 3 requirements. Security awareness program.
- Audit and Accountability (AU): 9 requirements. Logs and accountability.
- Configuration Management (CM): 9 requirements. Baselines, change control, least functionality.
- Identification and Authentication (IA): 11 requirements. MFA, identifier management.
- Incident Response (IR): 3 requirements. Detection, reporting, recovery.
- Maintenance (MA): 6 requirements. How maintenance is performed.
- Media Protection (MP): 9 requirements. Protecting media that contains CUI.
- Personnel Security (PS): 2 requirements. Screening and access termination.
- Physical Protection (PE): 6 requirements. Facility access.
- Risk Assessment (RA): 3 requirements. Identify and prioritize risks.
- Security Assessment (CA): 4 requirements. Internal assessment and POA&M.
- System and Communications Protection (SC): 16 requirements. Boundary protection, cryptography.
- System and Information Integrity (SI): 7 requirements. Flaw remediation, malicious code protection.
Rev 2 vs Rev 3
Rev 3 (May 14, 2024) reorganizes requirements to match NIST SP 800-53 Rev 5 more closely. The 14 families become 17. Some requirements merge, split, or get new language. Rev 3 introduces organization-defined parameters (ODPs) that let the federal agency specify values like password complexity. Assessments continue to reference Rev 2 until DoD rulemaking formally adopts Rev 3.
Implementation Pattern
- Scope: Identify systems, networks, and facilities where CUI lives.
- Gap assess: Score yourself against each of the 110 requirements.
- SSP: Write the System Security Plan describing how each requirement is met.
- POA&M: List requirements not yet fully implemented with realistic target dates.
- Remediate: Close the gaps.
- Score and submit: Run the DoD Assessment Methodology, submit to SPRS.
Highest-Value Controls to Close First
Under the DoD Assessment Methodology, some missing controls cost more points than others. If your score is low and you want quick wins: 3.5.3 (MFA for privileged accounts and network access, -5), 3.1.13 (cryptographic protection for remote access, -5), 3.13.11 (FIPS-validated cryptography, -5), 3.14.1 (flaw remediation, -5), and 3.14.2 (malicious code protection, -5). Closing these five moves your score by up to 25 points.