If your organization handles CUI under a DoD contract, you're required to protect it using a specific cybersecurity framework: NIST Special Publication 800-171. It's not a suggestion or a best practice guide — it's a contractual requirement tied to a DFARS clause in your contract, and your required CMMC certification level is built directly on top of it.
Understanding what NIST SP 800-171 requires, and why, is the foundation of your entire CUI security and compliance program.
Where CUI safeguarding requirements come from
DFARS clause 252.204-7012 requires contractors to implement NIST SP 800-171 security requirements on any system that processes, stores, or transmits Covered Defense Information. If you handle CUI under a DoD contract, that clause is in it, and the requirement applies to you.
Two enforcement layers sit on top of the clause. The first is self-reporting: DFARS 252.204-7019 and 7020 require contractors handling CUI to self-assess against NIST SP 800-171 and submit the resulting score to the Supplier Performance Risk System (SPRS), the DoD database contracting officers check before making awards.
The second is the Cybersecurity Maturity Model Certification (CMMC) program, which verifies that contractors have the cybersecurity controls in place appropriate to the sensitivity of the information they handle.
CMMC Level 1 applies to contractors handling only Federal Contract Information and involves 15 basic safeguarding practices.
CMMC Level 2 applies to contractors handling CUI and requires full implementation of 110 NIST 800-171 controls and 320 assessment objectives.
CMMC Level 3 is for contractors supporting the DoD's most sensitive programs and adds 24 requirements from NIST SP 800-172.

Recommended reading
DFARS 7012 vs CMMC: Key Differences & Overlaps Explained
Read MoreWhat is NIST 800-171?
NIST Special Publication 800-171 is a cybersecurity framework developed by the National Institute of Standards and Technology specifically to protect CUI in non-federal systems and organizations.
Federal agencies use NIST SP 800-53, which governs federal information systems directly. NIST SP 800-171 translates those federal requirements into a framework designed for the contractors and organizations outside government who handle CUI as part of their work.

The framework's current version for CMMC compliance is Revision 2, which defines 110 security requirements organized into 14 control families. NIST released Revision 3 in May 2024, restructuring the requirements into 97 controls across 17 families, but a DoD class deviation keeps Rev 2 as the standard for CMMC assessments until further notice.
That transition is now actively in motion: the DoD has defined values for all 88 of Rev 3's organization-defined parameters as policy, and its regulatory agenda includes an interim final rule establishing the deadline for shifting CMMC to Rev 3. No formal transition date has been announced yet, so if you're preparing for a CMMC assessment today, Rev 2 is what you're being assessed against. But building your program with Rev 3 in view is no longer optional planning.
Recommended reading
NIST 800-171 Rev 2 vs Rev 3: What Changed and What It Means for CMMC
Read MoreThe 14 control families
NIST SP 800-171 Rev 2 organizes its 110 requirements into 14 control families, each addressing a distinct domain of cybersecurity practice:
- Access Control (22 requirements): The largest family. Covers who can access your CUI systems, under what conditions, and through what mechanisms, including least privilege enforcement, remote access controls, and session management.
- Awareness and Training (3 requirements): Ensures that personnel who handle CUI understand their security responsibilities and receive role-based training. Small family, but routinely underimplemented.
- Audit and Accountability (9 requirements): Covers the creation, protection, retention, and review of audit logs. You need to be able to answer: what happened on your CUI systems, when, and by whom?
- Configuration Management (9 requirements): Governs how systems are configured, changed, and tracked. Includes baseline configurations, software inventory, and change control processes.
- Identification and Authentication (11 requirements): Verifies the identity of users and devices before granting access, including multi-factor authentication requirements for privileged and remote access.
- Incident Response (3 requirements): Requires a documented incident response process and the capability to detect, report, and respond to CUI security incidents. Small family, frequently underresourced.
- Maintenance (6 requirements): Controls how maintenance is performed on CUI systems, including restrictions on remote maintenance and requirements for sanitizing equipment before off-site servicing.
- Media Protection (9 requirements): Governs how physical and digital media containing CUI is labeled, stored, transported, and destroyed.
- Personnel Security (2 requirements): The smallest family. Covers screening individuals before granting CUI access and ensuring that CUI access is revoked promptly when someone leaves or changes roles.
- Physical Protection (6 requirements): Limits physical access to systems, equipment, and facilities where CUI is processed or stored.
- Risk Assessment (3 requirements): Requires periodic risk assessments, vulnerability scans, and remediation of identified vulnerabilities.
- Security Assessment (4 requirements): Covers how you assess your own controls, manage your System Security Plan, and monitor your environment for security deficiencies.
- System and Communications Protection (16 requirements): The second largest family. Covers encryption, network segmentation, boundary protection, and communications monitoring.
- System and Information Integrity (7 requirements): Addresses malware protection, system monitoring, security alerts, and flaw remediation.
What NIST SP 800-171 compliance requires
Meeting NIST SP 800-171 requirements isn't a project you complete once. It requires continuously meeting all 14 families across your CUI environment over time, even as your systems grow and change.
At a minimum, you’ll need to:
Define the scope of your CUI environment, including which systems, networks, personnel, and locations handle CUI, so you know what's subject to the requirements. This is perhaps the most important step in the process: scoping too broadly wastes resources on safeguards for information that doesn’t need to be protected, and scoping too narrowly creates compliance gaps.
Build a System Security Plan (SSP) that describes how your organization satisfies each of the 110 requirements. An SSP for a mid-sized contractor can run hundreds of pages, and your SSP must be kept up to date over time.
Track any gaps in a Plan of Action and Milestones (POA&M) with specific remediation actions, responsible owners, and target completion dates. Having open POA&M items doesn't automatically disqualify you from a CMMC assessment, but assessors evaluate whether your gaps are credible, documented, and actively being addressed.
Submit a Supplier Performance Risk System (SPRS) score reflecting your current implementation status. Submitting an inflated score while knowingly failing to implement the controls creates False Claims Act exposure, as several contractors have already discovered.
Recommended reading
NIST 800-171 Compliance: How to Comply with the Latest Revision [+ Checklist]
Read MoreSafeguarding CUI beyond your systems
NIST SP 800-171 governs your information systems, but the safeguarding requirements for CUI don't stop at your laptop. Under 32 CFR 2002.14, authorized holders must protect CUI in physical form and in conversation too.
The core obligations:
- Establish controlled environments where unauthorized individuals can't access CUI, observe it, or overhear conversations discussing it.
- When CUI leaves a controlled environment, it must stay under your direct control or behind at least one physical barrier, such as a sealed envelope, a locked drawer, or a locked file cabinet. That's what makes printed CUI on a home office desk or a discussion of contract details in a coffee shop a compliance problem, not just bad practice.
- Mailing CUI is permitted through USPS or commercial carriers, with tracking recommended.
- When CUI is destroyed, it must be made unreadable, indecipherable, and irrecoverable, following standards like NIST SP 800-88 for media sanitization.
For DoD contractors, DoDI 5200.48 layers its own handling procedures on top of these baseline rules. Two tools that make day-to-day physical protection easier, cover sheets and proper markings, are covered in the next article in this series: CUI Marking Requirements: Banner Markings, Designation Indicators, and DoD Rules