Compliance Framework
NIST SP 800-171 Rev 2
Protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations. The foundation for CMMC certification.
Overview
NIST Special Publication 800-171 provides recommended security requirements for protecting the confidentiality of CUI when it resides in non-federal systems and organizations. Originally published to support DFARS clause 252.204-7012, it is now the cornerstone of the Cybersecurity Maturity Model Certification (CMMC) program. The 110 controls span 14 families and are derived from the moderate baseline of NIST SP 800-53, tailored for non-federal environments.
Who Needs This?
- Department of Defense (DoD) contractors and subcontractors
- Organizations handling Controlled Unclassified Information (CUI)
- Companies pursuing CMMC Level 2 certification
- Defense Industrial Base (DIB) suppliers at any tier
- Research institutions with federally funded CUI
Key Benefits
- Meet DFARS 252.204-7012 requirements for DoD contracts
- Build a direct path to CMMC Level 2 certification
- Establish a proven security baseline for sensitive data
- Demonstrate security maturity to government partners
- Reduce risk of data breaches involving controlled information
Control Families
Access Control
Limit system access to authorized users, processes, and devices.
Awareness & Training
Ensure personnel are aware of security risks and trained in policies.
Audit & Accountability
Create, protect, and retain system audit records.
Configuration Management
Establish and maintain baseline configurations and inventories.
Identification & Authentication
Identify and authenticate users, processes, and devices.
Incident Response
Establish operational incident handling capabilities.
Maintenance
Perform timely maintenance on organizational systems.
Media Protection
Protect and control system media containing CUI.
Personnel Security
Screen individuals prior to authorizing access to CUI.
Physical Protection
Limit physical access to systems, equipment, and environments.
Risk Assessment
Periodically assess risk to operations, assets, and individuals.
Security Assessment
Assess, monitor, and correct deficiencies in security controls.
System & Communications Protection
Monitor, control, and protect communications at boundaries.
System & Information Integrity
Identify, report, and correct information and system flaws.
Related Frameworks
Need Help With NIST SP 800-171?
Our team can assess your current posture, identify gaps, and build a roadmap to compliance. Get expert guidance tailored to your organization.
Request a Compliance Assessment