# NIST SP 800-171 (Protecting CUI in Nonfederal Systems) | Secureframe

> NIST 800-171 Rev 2 has 14 families and 110 requirements. Rev 3 (May 2024) restructures the document. Highest-impact controls for SPRS scoring and CMMC Level 2.

canonical: https://secureframe.com/glossary/nist-800-171

NIST Special Publication 800-171 defines the security requirements that a nonfederal organization must implement when it processes, stores, or transmits Controlled Unclassified Information (CUI) on behalf of the federal government. Rev 2 has 110 requirements across 14 control families. Rev 3 (published May 14, 2024) restructures the document and expands the number of requirements. DFARS 252.204-7012 requires Rev 2. CMMC Level 2 uses Rev 2. Rev 3 will be adopted in future rulemaking.

### The 14 Control Families (Rev 2)

- **Access Control (AC): 2**2 requirements. Who can do what.
- **Awareness and Training (AT):** 3 requirements. Security awareness program.
- **Audit and Accountability (AU)**: 9 requirements. Logs and accountability.
- **Configuration Management (CM**): 9 requirements. Baselines, change control, least functionality.
- **Identification and Authentication (I**A): 11 requirements. MFA, identifier management.
- **Incident Response (IR**): 3 requirements. Detection, reporting, recovery.
- **Maintenance (MA)**: 6 requirements. How maintenance is performed.
- **Media Protection (MP**): 9 requirements. Protecting media that contains CUI.
- **Personnel Security (P**S): 2 requirements. Screening and access termination.
- **Physical Protection (PE**): 6 requirements. Facility access.
- **Risk Assessment (**RA): 3 requirements. Identify and prioritize risks.
- **Security Assessment (C**A): 4 requirements. Internal assessment and POA&M.
- **System and Communications Protection (**SC): 16 requirements. Boundary protection, cryptography.
- **System and Information Integrity **(SI): 7 requirements. Flaw remediation, malicious code protection.

### Rev 2 vs Rev 3

Rev 3 (May 14, 2024) reorganizes requirements to match NIST SP 800-53 Rev 5 more closely. The 14 families become 17. Some requirements merge, split, or get new language. Rev 3 introduces organization-defined parameters (ODPs) that let the federal agency specify values like password complexity. Assessments continue to reference Rev 2 until DoD rulemaking formally adopts Rev 3.

### Implementation Pattern

- **Scope: **Identify systems, networks, and facilities where CUI lives.
- **Gap assess: **Score yourself against each of the 110 requirements.
- **SSP:** Write the System Security Plan describing how each requirement is met.
- **POA&M: **List requirements not yet fully implemented with realistic target dates.
- **Remediate: **Close the gaps.
- **Score and submit:** Run the DoD Assessment Methodology, submit to SPRS.

### Highest-Value Controls to Close First

Under the DoD Assessment Methodology, some missing controls cost more points than others. If your score is low and you want quick wins: 3.5.3 (MFA for privileged accounts and network access, -5), 3.1.13 (cryptographic protection for remote access, -5), 3.13.11 (FIPS-validated cryptography, -5), 3.14.1 (flaw remediation, -5), and 3.14.2 (malicious code protection, -5). Closing these five moves your score by up to 25 points.
