All Frameworks

Compliance Framework

NIST SP 800-171 Rev 2

Protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations. The foundation for CMMC certification.

110 Controls · 14 Families
NIST / DoD

Overview

NIST Special Publication 800-171 provides recommended security requirements for protecting the confidentiality of CUI when it resides in non-federal systems and organizations. Originally published to support DFARS clause 252.204-7012, it is now the cornerstone of the Cybersecurity Maturity Model Certification (CMMC) program. The 110 controls span 14 families and are derived from the moderate baseline of NIST SP 800-53, tailored for non-federal environments.

Who Needs This?

  • Department of Defense (DoD) contractors and subcontractors
  • Organizations handling Controlled Unclassified Information (CUI)
  • Companies pursuing CMMC Level 2 certification
  • Defense Industrial Base (DIB) suppliers at any tier
  • Research institutions with federally funded CUI

Key Benefits

  • Meet DFARS 252.204-7012 requirements for DoD contracts
  • Build a direct path to CMMC Level 2 certification
  • Establish a proven security baseline for sensitive data
  • Demonstrate security maturity to government partners
  • Reduce risk of data breaches involving controlled information

Control Families

Access Control

22

Limit system access to authorized users, processes, and devices.

Awareness & Training

3

Ensure personnel are aware of security risks and trained in policies.

Audit & Accountability

9

Create, protect, and retain system audit records.

Configuration Management

9

Establish and maintain baseline configurations and inventories.

Identification & Authentication

11

Identify and authenticate users, processes, and devices.

Incident Response

3

Establish operational incident handling capabilities.

Maintenance

6

Perform timely maintenance on organizational systems.

Media Protection

9

Protect and control system media containing CUI.

Personnel Security

2

Screen individuals prior to authorizing access to CUI.

Physical Protection

6

Limit physical access to systems, equipment, and environments.

Risk Assessment

3

Periodically assess risk to operations, assets, and individuals.

Security Assessment

4

Assess, monitor, and correct deficiencies in security controls.

System & Communications Protection

16

Monitor, control, and protect communications at boundaries.

System & Information Integrity

7

Identify, report, and correct information and system flaws.

Related Frameworks

Need Help With NIST SP 800-171?

Our team can assess your current posture, identify gaps, and build a roadmap to compliance. Get expert guidance tailored to your organization.

Request a Compliance Assessment