NIST SP 800-171 is the main security standard federal agencies use to require contractors to protect Controlled Unclassified Information in nonfederal systems.
In plain terms. NIST SP 800-171 is a security standard for protecting Controlled Unclassified Information (CUI) when CUI is stored, processed, or transmitted in nonfederal systems. It is not a statute by itself, but contracts and regulations often make it mandatory.
Who it applies to. Contractors usually need NIST SP 800-171 when a contract, clause, agency instruction, or CUI requirement says that CUI must be protected in contractor systems. DoD contractors most often encounter it through DFARS 252.204-7012, DFARS 252.204-7019/7020, and CMMC.
What it requires. NIST SP 800-171 defines security requirements for protecting CUI. Contractors typically use it to build or update a System Security Plan (SSP), assess implementation, document gaps, manage plans of action and milestones (POA&Ms), and support DoD assessment or CMMC evidence.
Why it matters. NIST published SP 800-171 Rev. 3 as the current final NIST version in May 2024. But contract applicability depends on what the contract, clause, rule, or agency instruction incorporates. DoD's current CMMC Program rule incorporates NIST SP 800-171 Rev. 2, so GovConCyber pages should clearly distinguish current NIST publication status from current contract-enforcement status.
Citation. NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (May 2024); NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (Feb. 2020, updated Jan. 28, 2021); 32 C.F.R. Part 170.