Guide

NIST SP 800-171 explained: who must follow it and what it requires

If a federal contract touches controlled unclassified information, SP 800-171 is almost certainly in your clauses. Here's what it actually demands.

Who must follow it

Any nonfederal organization that processes, stores, or transmits CUI — in practice, defense contractors and subcontractors via DFARS clauses. It's a contractual requirement, not a law you can ignore because you didn't know about it.

What it requires

800-171 sets requirements across 14 families (access control, incident response, audit, configuration management, and more). The prior revision had 110 requirements; Rev. 3 (published 2024) restructured and updated them. The families didn't go away — the organization and some specifics changed.

The documentation that matters

The path

Readiness assessment → remediation → CMMC Level 2 assessment by an authorized C3PAO. Firms in our directory tagged for the defense stage do this work daily — see our cost guide for planning ranges.

Independent directory. NISTFramework.com is an independent directory and quote-matching service.

Get quotes from verified firms

One brief, matched firms, competing quotes — free.

Get a free quote

← All guides