Fortinetics Book a call →
Menu
DEFENSE · CUI

NIST SP 800-171 — the 110 controls every CUI-handling contractor lives by.

NIST 800-171 is the security standard for protecting Controlled Unclassified Information on nonfederal systems. Its 110 controls (Revision 2) are the technical substance of CMMC Level 2 and the basis of every SPRS self-assessment score. We design, implement, and document 800-171 programs to assessor grade, the same work that carries straight into a C3PAO assessment.

110
Controls in Rev 2
14
Control families
Rev 3
Published, no DoD transition date

What is NIST 800-171?

NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," defines the security requirements that contractors must meet when they store, process, or transmit Controlled Unclassified Information (CUI) on their own systems.

Revision 2, the current assessable baseline, contains 110 controls across 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

800-171 was derived from the NIST 800-53 Moderate baseline, tailored down to the controls relevant to protecting CUI when it lives outside federal systems. It is the standard that DFARS 252.204-7012 requires defense contractors to implement, and the technical substance that CMMC Level 2 assesses.

Who needs to comply with 800-171?

Any organization that handles Controlled Unclassified Information under a federal contract. In the defense world, that means any contractor or subcontractor whose contract includes DFARS 252.204-7012, which is a large share of the Defense Industrial Base. For scale, DoD's own estimate in the CMMC final rule is that roughly 76,600 entities will require a CMMC Level 2 certification assessment, with a further 4,000 at Level 2 self-assessment and 1,487 at Level 3.

The reach extends through the supply chain. A prime contractor flows the requirement down to subcontractors at any tier that touches CUI. A small machine shop, a software vendor, a logistics provider — if CUI passes through their systems, 800-171 applies.

Beyond DoD, NIST 800-171 is becoming the default federal CUI baseline. GSA's 2026 civilian-contractor CUI rule draws on the same 800-171 foundation, meaning contractors serving civilian agencies are increasingly subject to equivalent requirements.

800-171 and SPRS scoring

DFARS requires contractors to submit a NIST 800-171 self-assessment score to the Supplier Performance Risk System (SPRS). The score starts at 110 and subtracts weighted points for each control not fully implemented: some controls are worth 1 point, others 3 or 5, reflecting their security impact. A perfect implementation scores 110; significant gaps can produce sharply negative scores.

The SPRS score is what contracting officers check before award, and it is the figure that False Claims Act enforcement now scrutinizes. A self-asserted score materially higher than what an honest assessment would produce is, in the Department of Justice's reading, a false claim, actionable even without a breach. Eight cyber-fraud settlements landed in 2025.

We treat the SPRS score as an output of a real assessment, not a number to optimize. A defensible score is one you could re-derive in front of an assessor.

The Rev 2 to Rev 3 transition

NIST published 800-171 Revision 3, but CMMC Level 2 is still assessed against Revision 2, and 32 CFR 170.2 incorporates Revision 2 by reference. DoD staged the transition by publishing Organization-Defined Parameters ahead of formal rulemaking, but it has published no date: the CMMC final rule says only that Rev 3 "is not currently applicable to this rule" and that DoD "will issue future amendments to this rule to incorporate the current version at that time." Treat any specific migration year you see quoted as trade-press expectation, not a DoD commitment.

Rev 3 restructures the catalog. It adds three control families: Planning (PL), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). That aligns it more closely with NIST 800-53 Rev 5, and it introduces Organization-Defined Parameters that let organizations specify implementation details.

The practical guidance for 2026: build to Rev 2, because it is what 32 CFR 170.2 incorporates and what any assessment — self or third-party — is scored against. That did not change when the Phase 2 transition was suspended on July 13, 2026; the CIO memo is explicit that the Department "will continue enforcing baseline compliance with NIST SP 800-171 Rev 2 through DIB self-assessments and select government-led assessments." Track the Rev 3 delta anyway. Tier-1 primes are starting to ask subs about Rev 3 readiness in pre-award evaluations even where Rev 2 remains the contractual baseline.

Why Fortinetics for NIST 800-171

The program that carries into CMMC. Implementing 800-171 well is implementing CMMC Level 2 well: the 110 controls are identical. We design the program once, to assessor grade, so the same evidence and documentation support both the SPRS score and a C3PAO assessment. No throwaway work.

Authorship-level CMMC knowledge. A member of our team contributed to the CMMC standard at the Department of Defense in 2019. The 800-171-to-CMMC relationship is not abstract to us; we helped shape how the controls are assessed.

Evidence-as-byproduct design. A defensible 800-171 posture produces audit-grade artifacts as a byproduct of operations, not a reconstruction exercise at assessment time. That discipline is the difference between a score you can defend and a score that invites scrutiny.

Honest SPRS scoring. We score against reality, not aspiration. A score we help you submit is one you could re-derive in front of a C3PAO or, if it comes to it, a DOJ inquiry.

Recent regulatory changes

What changed in NIST 800-171, recently.

  • May 2026
    Rev 3 expectations harden in trade press, but DoD still publishes no date

    Q2 2026 trade-press commentary converged on a near-term rulemaking window for the Rev 2 to Rev 3 transition. DoD has not published one: 32 CFR 170.2 still incorporates Rev 2, and the CMMC final rule states Rev 3 is not currently applicable. CMMC Level 2 remains Rev 2-assessed, but primes are asking subs about Rev 3 readiness.

    Read more →
  • March 2026
    GSA CUI rule extends the 800-171 baseline to civilian contractors

    GSA's January 2026 Controlled Unclassified Information rule (CIO-IT Security-21-112, Rev 1) draws on the same NIST 800-171 foundation, beginning to emerge a CMMC-like regime for federal civilian agency contracts. NIST 800-171 is becoming the default federal CUI baseline, not just a DoD obligation.

    Read more →
  • December 2025
    DOJ False Claims Act enforcement targets false SPRS scores

    A subcontractor-level FCA settlement landed in December 2025, reportedly the first to reach the subcontractor tier. FCA liability attaches to the SPRS self-attestation itself: a score materially higher than an honest assessment would produce is actionable even without a breach.

    Read more →
Frequently asked

Questions we get about NIST 800-171.

What is NIST 800-171 and who has to comply?
NIST SP 800-171 is the security standard for protecting Controlled Unclassified Information (CUI) on nonfederal systems: its 110 Rev 2 controls across 14 families. Any organization handling CUI under a federal contract must comply, which in defense means any contractor or subcontractor whose contract includes DFARS 252.204-7012. DoD estimates that roughly 76,600 entities will require a CMMC Level 2 certification assessment; that figure is the certification-assessment population, not a count of every CUI-handling organization.
How does NIST 800-171 relate to CMMC?
CMMC Level 2 is the 110 NIST 800-171 Rev 2 controls, with the assessment and certification machinery layered on top. Implementing 800-171 is implementing CMMC Level 2; the controls are identical. The difference is that CMMC adds third-party (C3PAO) assessment and a certificate, where 800-171 on its own has historically been self-assessed and reported as a SPRS score. That difference is currently dormant: the CMMC Phase 2 transition was suspended on July 13, 2026 and only Level 1 (Self) and Level 2 (Self) may be designated, which leaves the 800-171 work itself as the whole of the obligation.
What is a SPRS score and how is it calculated?
The Supplier Performance Risk System (SPRS) score is the NIST 800-171 self-assessment figure DFARS requires contractors to submit. It starts at 110 and subtracts weighted points for each control not fully implemented: controls are worth 1, 3, or 5 points based on security impact. A perfect implementation scores 110. Contracting officers check the score before award, and False Claims Act enforcement now scrutinizes scores that are materially higher than an honest assessment would produce.
Should we implement 800-171 Rev 2 or Rev 3?
Build to Rev 2. It is the current assessable baseline: 32 CFR 170.2 incorporates Rev 2 by reference, and the July 13, 2026 suspension of the CMMC Phase 2 transition explicitly kept Rev 2 compliance enforced through self-assessment. NIST has published Rev 3 and DoD staged the transition by releasing Organization-Defined Parameters, but DoD has published no migration date — the CMMC final rule says only that Rev 3 'is not currently applicable to this rule.' Treat any specific year you see quoted as trade-press expectation. Track the Rev 3 delta (it adds Planning, System and Services Acquisition, and Supply Chain Risk Management families), but don't redesign your environment for it yet.
How many controls are in NIST 800-171?
Revision 2, the current assessable baseline, has 110 controls across 14 families. Revision 3 restructures the catalog and adds three families (Planning, System and Services Acquisition, Supply Chain Risk Management) aligning more closely with NIST 800-53 Rev 5, but CMMC Level 2 is still assessed against the Rev 2 set of 110.
Is NIST 800-171 the same as NIST 800-53?
No, but they're related. NIST 800-171 (110 controls) is a tailored subset derived from the NIST 800-53 Moderate baseline (1,000+ controls), focused on protecting CUI on nonfederal systems. 800-171 underpins CMMC for defense contractors; 800-53 underpins FedRAMP and DoD authorizations for cloud services. See our NIST 800-171 vs 800-53 comparison for the full breakdown.
Tools & comparisons
Next step

Book a scoping call.

Thirty minutes. We'll walk through your specific NIST 800-171 target, current posture, and what a realistic engagement shape looks like. NDA-first when the scoping needs sensitive detail.

Book a scoping call →