GovCon Cybersecurity | | 23 min read
NIST SP 800-171 Explained: Requirements, Controls, and Compliance
Key Takeaways
NIST SP 800-171 is the 110 requirement standard that decides whether you can hold Controlled Unclassified Information.
110 Requirements, 14 Families
Revision 2 organizes the standard into 14 families, from Access Control with 22 requirements down to Personnel Security with 2. The distribution is uneven, and that matters for planning.
SPRS Is a Live Scoreboard
You start at 110 and lose 5, 3, or 1 point per open requirement with no partial credit. Contracting officers can see the number, so a few open controls carry real weight.
Sequence by Dependency, Not List Order
The GS Implementation Sequencing Index ranks families by control count, how much other work depends on them, and how much evidence they generate. Identity and access come first.
Rev 3 Is Coming
The draft moves to 97 requirements across 17 families and adds supply chain and planning. Build to the intent of the standard and the transition is an update, not a rebuild.
NIST SP 800-171 is not a certificate. It is not a product you buy.
It is the list of requirements that decides whether the government trusts you with its sensitive information.
If you have heard the number 800-171 in a contract, a flow down clause, or a prime's questionnaire, this is what sits behind it: a federal standard that spells out, in 110 specific requirements, how a company that is not part of the government must protect Controlled Unclassified Information on its own systems. Meet the standard and you can hold the data. Fall short and, sooner or later, you lose the work.
Most of the confusion around it comes from treating 800-171 as paperwork. It is not paperwork. It is an operating condition, and the paperwork only describes it.
This guide explains what NIST SP 800-171 is, who it applies to, how the 110 requirements break down across the 14 families, how the SPRS score is calculated, what the coming Revision 3 changes, and the order we recommend working the controls in. Along the way we share original GS Consulting research on which families to tackle first, so you can plan the work instead of guessing at it.
Turn 800-171 into a sequenced plan, not a scramble.
GS Consulting helps contractors scope CUI, assess against all 110 requirements, calculate an honest SPRS score, and build the evidence an assessor will accept.
Request an 800-171 Readiness ReviewWhat NIST SP 800-171 Actually Is
NIST SP 800-171, in full "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," is a publication from the National Institute of Standards and Technology. Its job is narrow and important. When sensitive but unclassified government information lands on a contractor's laptops, servers, or cloud tenant, the standard defines the safeguards that information is supposed to have around it.
The information it protects is Controlled Unclassified Information, or CUI. That is government created or government owned information that is not classified but still requires protection under law or policy: technical drawings, specifications, logistics data, and similar material the government has marked. CUI is the trigger. If your contract involves it, 800-171 is almost certainly in play.
Here is the part people miss. NIST SP 800-171 is a standard, not a program. It lists what good looks like. It does not, by itself, come to your office and check. The checking happens through other mechanisms that point back to it: the DFARS clause 252.204-7012, which requires contractors to implement 800-171 and report on it, and CMMC, which adds a verification step. So when a prime asks whether you are "800-171 compliant," they are asking whether you meet the 110 requirements in the standard, and whether you can prove it.
Who Has to Comply
The short answer: if you handle CUI on your own systems as part of a federal contract, you are in scope. The obligation reaches far beyond the largest primes.
The requirement most often arrives through DFARS 252.204-7012, the safeguarding clause that appears in Department of Defense contracts involving Covered Defense Information. When that clause is in your contract, you are required to implement the security requirements in NIST SP 800-171 and to report cyber incidents. Two companion clauses, 252.204-7019 and 252.204-7020, require you to post your assessment score and give the government access to verify it.
Three points decide whether the standard applies to you:
- The data, not the contract size. A two person shop that receives CUI carries the same 800-171 obligation as a large integrator. Sensitivity of the information sets the requirement, not headcount or revenue.
- Flow down is real. If a prime passes CUI to you as a subcontractor, the safeguarding requirement flows with it. You cannot assume the prime's compliance covers your systems.
- Your own systems are the boundary. The standard governs the nonfederal systems where CUI lives. Where that data actually flows, including cloud and managed service providers, defines the scope of the work.
If your work sits inside the defense industrial base and touches anything marked CUI or described as Covered Defense Information, treat 800-171 as a present obligation. For the wider federal contracting picture, our guide on NIST SP 800-171 compliance for government contractors walks through how the clauses connect.
The 110 Requirements and the 14 Families
Revision 2 of the standard, the version written into most contracts today, contains 110 security requirements. They are grouped into 14 families, each covering one area of security. The families are not equal in size. Access Control alone accounts for 22 requirements, while Personnel Security has 2.
Understanding the shape of the standard is the first step to planning the work. The 14 families in Revision 2 are Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each family holds a set of requirements written as plain statements of what the organization must do.
The distribution tells you something useful before you have read a single requirement. Access Control, System and Communications Protection, and Identification and Authentication together hold nearly half the standard. These are the families that govern who gets in, how data moves across your boundary, and how identity is proven. They are also where scoping and evidence work gets hardest. Smaller families like Personnel Security, Awareness and Training, Incident Response, and Risk Assessment matter, but they involve fewer requirements and simpler proof.
Revision 2 Versus Revision 3
You will see two versions of 800-171 discussed, and it is worth being clear about which one governs you today. Revision 2, published in 2021, is the version referenced by the current DFARS clause and by CMMC Level 2. It has 110 requirements and 14 families. Unless your contract says otherwise, this is the standard you are being measured against right now.
Revision 3, published in 2024, restructures the standard. It reduces the count to 97 requirements but expands to 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management, and it folds some older requirements together while raising the bar on others. A lower number does not mean less work. Several Revision 3 requirements are broader and more prescriptive than their Revision 2 predecessors.
The transition from Rev 2 to Rev 3 in contracts happens through rulemaking and clause updates, not on the day NIST publishes. That gives contractors a window, and the smart move is to use it. If you build your program to the intent of the standard, protect the data, prove the control, keep the evidence current, rather than to a literal checklist of 110 items, the shift to Rev 3 is a mapping exercise and not a teardown. Our companion piece on NIST SP 800-171 controls for AI systems shows how the same principle applies when new technology enters your environment.
Original Research: Which Families to Tackle First
The most common planning mistake we see is working the 110 requirements in numerical order, starting at Access Control 3.1.1 and grinding to Personnel Security at the end. That order is an artifact of how the document is written. It is not the order that makes the work efficient.
To give contractors a better starting sequence, GS Consulting built the NIST 800-171 Implementation Sequencing Index. We took the requirement count for each of the 14 families as a factual anchor, then added two weighting factors drawn from our assessment practice: how much other control work depends on that family being in place first, and how much ongoing evidence the family generates. The index weights requirement count at 50 percent, foundational dependency at 25 percent, and evidence density at 25 percent, scaled from 0 to 100.
The ranking is decisive at the top. Access Control scores 100, System and Communications Protection 81, and Identification and Authentication 70. That is not a coincidence. Identity and access are foundational: you cannot meaningfully log activity, control configuration, or protect media until you know who your users are and what they can reach. These families also generate the evidence assessors ask for first. Audit and Accountability, Configuration Management, and Security Assessment sit in the middle, high on evidence but dependent on identity being solved. Awareness and Training and Personnel Security land at the bottom, not because they are optional, but because they are quick to stand up once the technical foundation exists.
The practical instruction is simple. Do not spread your early effort evenly across 14 families. Concentrate it on the top of the index. A team that gets access control, boundary protection, and identity right has done the structural work, and the lighter families fall into place with far less friction and far less rework.
How the SPRS Score Works
The Supplier Performance Risk System score is how the government sees your 800-171 posture at a glance, and it is where a lot of contractors quietly lose ground. The mechanic is unforgiving on purpose.
You begin at 110, one point for every requirement, and assume full implementation. Then, for each requirement you do not fully meet, you subtract a weighted value. Higher risk requirements cost 5 points, medium risk requirements cost 3, and lower risk requirements cost 1. There is no partial credit: a requirement is either fully implemented or it is not, and a control that is half built scores the same as one you have not started. Because some requirements carry multiple weighted subtractions, the lowest possible score is -203, well below zero.
Two consequences follow. First, the highest weighted requirements deserve your attention first, because closing one of them is worth five times closing a low weight item. Second, the score is visible. Under the reporting clauses, your posted SPRS score is available to contracting officers, so a low number can quietly cost you consideration before any conversation about an assessment happens. Treat the score as a live scoreboard you manage, not a form you fill in once. For the deeper mechanics and how the SPRS number connects to CMMC, our complete CMMC compliance guide covers the full picture.
The Implementation Path
When the sequence is clear, the path becomes a series of steps rather than a pile of tasks. The order matters as much as the content.
The path starts with the data and works outward. Confirm what you hold: if no CUI touches your systems, 800-171 may not apply, and that determination is worth making carefully rather than assuming. Then scope the environment by mapping every system, cloud service, and provider that stores, processes, or transmits CUI. Scope is the single largest lever on cost, because a tight, defensible boundary keeps systems out of assessment that would otherwise drag the whole environment in. Our walkthrough on building a CUI data flow map is the right companion for this step.
From there, assess against all 110 requirements and calculate an honest SPRS score, so you know exactly where you stand. Remediate in weight order, closing the 5 point gaps before the 1 point ones and following the sequencing index within that. Finally, sustain: stand up the evidence and the routines that keep each control operating and provable over time. That last step is the one contractors underinvest in, and it is the one that decides whether you are ready on the day someone asks. Automating it early pays for itself, which is why we wrote a full guide on automating NIST 800-171 compliance evidence.
The Evidence Set That Proves Compliance
Compliance comes down to one question. On the day a customer, a prime, or an assessor asks how you protect their information, what can you show? A confident answer is a small, well maintained set of artifacts, not a scramble through email and screenshots.
The system security plan, or SSP, is the spine. It describes how each of the 110 requirements is met across your scoped environment, and every other artifact hangs off it. The CUI inventory and data flow map define what you are protecting and where it lives. The SPRS score worksheet shows your current standing and how you calculated it. The plan of action and milestones tracks open gaps, their owners, and their closure dates, within the limits of what the rules allow to remain open. And the control evidence library, the configurations, logs, and records that prove each control actually operates, is the part teams most often neglect and assessors most want to see.
Build these five and keep them current, and you have an 800-171 program rather than an 800-171 document. The difference shows the moment someone asks you to prove it.
Research Sources and Caveats
The GS NIST 800-171 Implementation Sequencing Index is a GS Consulting derived planning tool based on cited public sources and documented assumptions. It is not an official NIST, DoD, CMMC, legal, audit, or assessment determination. The requirement counts, family names, revision structure, and the SPRS scoring mechanic are drawn from the standards and regulations below. The foundational dependency and evidence density weights, and the resulting family rankings, are GS planning assumptions and will vary with your environment.
Your actual 800-171 obligations depend on your contracts, the data you handle, your scope decisions, and the direction of your contracting officer and prime. Use the index to structure the work, not to replace legal, security, or assessment judgment.
- NIST SP 800-171 Rev 2
- NIST SP 800-171 Rev 3
- DFARS 252.204-7012: Safeguarding Covered Defense Information
- DFARS 252.204-7019 and 7020: Assessment Requirements
- 32 CFR Part 170: CMMC Program (eCFR)
- FAR 52.204-21: Basic Safeguarding
Frequently Asked Questions About NIST SP 800-171
What is NIST SP 800-171?
NIST SP 800-171 is a federal standard that defines how a nonfederal organization must protect Controlled Unclassified Information stored, processed, or transmitted on its own systems. Revision 2 sets 110 security requirements organized into 14 families. It is the technical backbone of DFARS clause 252.204-7012 and of CMMC Level 2, so meeting 800-171 is what most defense contractors actually mean when they say they need to be compliant.
How many controls are in NIST 800-171?
Revision 2, the version currently written into most contracts, has 110 security requirements across 14 families, from Access Control to Personnel Security. The draft Revision 3 restructures the standard to 97 requirements across 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management. The number changes, but the intent, protecting CUI, does not.
Is NIST 800-171 the same as CMMC?
No, but they are tightly linked. NIST SP 800-171 is the standard that lists the requirements. CMMC is the Department of Defense program that verifies you actually meet them. CMMC Level 2 is built directly on the 110 requirements in 800-171 Rev 2, so the work you do for 800-171 is the same work that gets you through a Level 2 assessment.
What is an SPRS score in NIST 800-171?
The Supplier Performance Risk System score is a self assessment of how completely you meet the 110 requirements. You start at 110 and subtract 5, 3, or 1 point for each requirement that is not fully implemented, weighted by risk, with no partial credit. The lowest possible score is -203. Contracting officers can see your posted score, so open high value requirements cost you before an assessment even begins.
How long does NIST 800-171 compliance take?
It depends on how far your current environment sits from the standard. A firm already running managed identity, logging, and a tight boundary may close its gaps in a few months. A firm starting from a commercial baseline should plan for a year or more, because the slow part is not writing the plan, it is implementing controls and building evidence that each one operates over time.