NIST SP 800-172 adds enhanced security requirements for higher-risk CUI environments, especially critical programs and high-value assets facing advanced threats.
In plain terms. NIST SP 800-172 is the enhanced-security companion to NIST SP 800-171. It is designed for situations where ordinary CUI protections are not enough because the program, technology, or information faces higher risk.
Who it applies to. Contractors usually encounter NIST SP 800-172 only when a contract, agency, program, or CMMC Level 3 requirement specifically calls for enhanced protection. It is not the default baseline for every contractor handling CUI.
What it requires. NIST SP 800-172 provides enhanced security requirements that agencies may use to protect CUI associated with critical programs, high-value assets, or advanced threats. Under the current CMMC Program rule, CMMC Level 3 uses selected NIST SP 800-172 February 2021 requirements with DoD-specified parameters.
Why it matters. NIST has published NIST SP 800-172 Rev. 3 and withdrawn the February 2021 publication as a NIST publication matter. Contract implementation may lag the publication update. GovConCyber should therefore separate “current NIST publication” from “currently incorporated contract requirement” so contractors do not assume a Rev. 3 migration is required unless their contract or agency says so.
Citation. NIST SP 800-172 Rev. 3, Enhanced Security Requirements for Protecting Controlled Unclassified Information (May 2026); NIST SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 (Feb. 2021), withdrawn May 13, 2026; 32 C.F.R. Part 170.