NIST SP 800-171 explained: who must follow it and what it requires
If a federal contract touches controlled unclassified information, SP 800-171 is almost certainly in your clauses. Here's what it actually demands.
Who must follow it
Any nonfederal organization that processes, stores, or transmits CUI — in practice, defense contractors and subcontractors via DFARS clauses. It's a contractual requirement, not a law you can ignore because you didn't know about it.
What it requires
800-171 sets requirements across 14 families (access control, incident response, audit, configuration management, and more). The prior revision had 110 requirements; Rev. 3 (published 2024) restructured and updated them. The families didn't go away — the organization and some specifics changed.
The documentation that matters
- System Security Plan (SSP): describes how each requirement is met. No SSP, no credible program.
- Plan of Action & Milestones (POA&M): tracks every unmet requirement with owners and dates.
- Evidence: assessors test controls — screenshots and policies aren't enough without operational proof.
The path
Readiness assessment → remediation → CMMC Level 2 assessment by an authorized C3PAO. Firms in our directory tagged for the defense stage do this work daily — see our cost guide for planning ranges.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.