NIST SP 800-171
NIST SP 800-171 is a U.S. government publication that lays out recommended security requirements for protecting sensitive but unclassified government information, known as Controlled Unclassified Information (CUI), when it lives on systems that are not run by the federal government. It generally applies to non-federal organizations, such as contractors and their partners, that store, process, or handle this kind of information. The publication has been revised over time, with Revision 2 and the later Revision 3 being the versions organizations most commonly reference.
NIST SP 800-171 is a NIST Special Publication that specifies recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations. It codifies requirements that non-Federal information systems must satisfy to store, process, or transmit CUI, organized into families of security requirements. Revision 2 (2021) and Revision 3 (2024) represent successive iterations, with Rev. 3 reflecting extended data collection, technical analysis, and redesign of the security requirements. A virtual CISO can support an organization's readiness and gap assessment against SP 800-171, but the publication itself defines requirements rather than conferring compliance or certification; organizational accountability for meeting and attesting to these requirements typically remains with the client organization and any contractual or regulatory obligations it holds.
Why it matters
For organizations that do business with the U.S. government, NIST SP 800-171 defines the baseline expectations for protecting Controlled Unclassified Information (CUI) when that information resides on systems the federal government does not operate. Because CUI often flows from federal agencies down through prime contractors to subcontractors and partners, the reach of the publication extends well beyond direct government suppliers. Meeting its requirements can become a condition of winning or retaining contracts, which makes it a business and risk-management concern, not merely a technical one.
The publication has evolved over time. Revision 2 (2021) and Revision 3 (2024) represent successive iterations, with Rev. 3 reflecting extended data collection, technical analysis, customer interaction, and a redesign of the security requirements. Organizations that aligned to an earlier revision may need to reassess as expectations shift, and the version an organization must satisfy is often driven by contractual or regulatory obligations rather than by choice.
A critical point that experienced leaders stress: SP 800-171 defines recommended security requirements; it does not by itself confer compliance or certification. Satisfying the requirements, attesting to that status, and carrying the associated legal and organizational accountability typically remain with the client organization and the contractual or regulatory obligations it holds. Treating the document as a checklist that guarantees a favorable outcome, or assuming an external advisor absorbs that accountability, is a common and consequential misunderstanding.
Who it's relevant to
Inside SP 800-171
Common questions
Answers to the questions practitioners most commonly ask about SP 800-171.