NIST Special Publication 800-171, frequently abbreviated NIST 800-171, is the security standard developed by the National Institute of Standards and Technology to specify the requirements for protecting Controlled Unclassified Information in nonfederal information systems and organizations. The standard is the substantive foundation of the Cybersecurity Maturity Model Certification framework, and Defense Industrial Base contractors approaching CMMC compliance are approaching NIST 800-171 compliance through the verification structure CMMC establishes.
The relationship between the two frameworks is straightforward in principle and frequently misunderstood in practice. NIST 800-171 specifies what compliance requires. CMMC specifies how compliance is verified. A contractor cannot satisfy CMMC without implementing the controls NIST 800-171 specifies, and a contractor who has implemented those controls without preparing for the verification methodology CMMC applies will encounter findings during the assessment that the underlying implementation alone would not have produced. Understanding the standard and the verification framework as a connected pair is the prerequisite to substantive compliance work.
The Structure of NIST SP 800-171
The current version applicable to CMMC compliance is NIST SP 800-171 Revision 2, published in February 2020 with subsequent updates through January 2021. Revision 2 specifies 110 security requirements organized into 14 control families. Each requirement addresses a specific aspect of information system security, and the requirements collectively define the baseline of protection the standard establishes for Controlled Unclassified Information.
The 110 requirements are categorized as either basic security requirements or derived security requirements. Basic requirements describe the high-level security objectives the standard establishes. Derived requirements specify the more detailed implementation expectations that satisfy the basic requirements in operational practice. The categorization is structurally informative but does not change the substantive obligation. All 110 requirements apply to systems within the assessment scope, and the assessment evaluates each requirement against the implementation guidance in the companion publication NIST SP 800-171A.
The full list of the 110 controls, with the language assessors apply to each, is available in the firm's reference at CMMC Controls Library. The reference provides individual cards for each control with the assessor language and the practitioner notes that bear on implementation in operational environments.
The 14 Control Families
The 110 requirements are organized into 14 control families that group requirements by subject matter. The family structure is consistent across NIST SP 800-171 and the parent NIST SP 800-53, which gives practitioners with experience in either framework a familiar organizational structure when working with the other.
| Family | Subject | Controls |
|---|---|---|
| 3.1 Access Control | Restricting system access to authorized users and processes | 22 |
| 3.2 Awareness and Training | User and administrator security awareness and training | 3 |
| 3.3 Audit and Accountability | Creating, protecting, and reviewing audit logs | 9 |
| 3.4 Configuration Management | Establishing and maintaining baseline configurations | 9 |
| 3.5 Identification and Authentication | Identifying users and authenticating their identities | 11 |
| 3.6 Incident Response | Establishing operational incident response capability | 3 |
| 3.7 Maintenance | Performing system maintenance and controlling personnel | 6 |
| 3.8 Media Protection | Protecting system media containing CUI | 9 |
| 3.9 Personnel Security | Screening individuals before authorizing access to CUI | 2 |
| 3.10 Physical Protection | Limiting physical access to systems and facilities | 6 |
| 3.11 Risk Assessment | Assessing risks to organizational operations and assets | 3 |
| 3.12 Security Assessment | Periodically assessing security controls and addressing deficiencies | 4 |
| 3.13 System and Communications Protection | Monitoring, controlling, and protecting communications | 16 |
| 3.14 System and Information Integrity | Identifying and correcting system flaws and detecting malicious activity | 7 |
The control count distribution across families reflects the relative depth of the security objectives each family addresses. Access Control is the largest family at 22 requirements because access management is the foundational layer of system security and supports nearly every other family's objectives. System and Communications Protection is the second largest at 16 requirements because it covers network segmentation, encryption, and the technical controls that prevent unauthorized data exfiltration. The smaller families like Personnel Security and Awareness and Training carry fewer requirements but no less weight in the assessment, because their substantive implementation is highly visible during the on-site portion of an assessment.
The Relationship Between NIST SP 800-171 and CMMC
NIST SP 800-171 establishes the substantive security standard. CMMC establishes the framework for verifying that contractors have implemented the standard. The two frameworks address different questions and operate at different layers of the compliance architecture.
The contractor's substantive obligation under DFARS 252.204-7012 is to implement NIST 800-171 controls in any system that processes, stores, or transmits Controlled Unclassified Information. This obligation has been in effect since 2017 and existed before CMMC was developed. CMMC was added to the regulatory architecture to address the verification gap that emerged from the original DFARS clause's reliance on contractor self-certification. Without independent verification, contractors could and did report compliance status that did not match operational reality, and the verification gap became the substantive case for the CMMC program.
Under CMMC, the verification methodology depends on the certification level. Level 1 applies to contractors handling only Federal Contract Information and requires implementation of a 17-control subset of NIST 800-171, verified through annual self-assessment. Level 2 applies to contractors handling Controlled Unclassified Information and requires implementation of all 110 NIST 800-171 Revision 2 controls, verified through either self-assessment or third-party assessment depending on the contract. Level 3 applies to contractors handling the most sensitive CUI categories and requires implementation of NIST 800-171 plus selected requirements from NIST SP 800-172, verified through Defense Industrial Base Cybersecurity Assessment Center assessment.
The practical implication for contractors is that NIST 800-171 compliance and CMMC compliance are not separate work streams. The implementation of NIST 800-171 controls is the substantive work that prepares the contractor for CMMC verification. A contractor who treats NIST 800-171 compliance as a prior phase to be completed before CMMC preparation begins frequently produces an implementation that satisfies the standard on paper but does not survive the assessment. Treating the two frameworks as a single integrated program from the beginning produces both the substantive compliance and the assessment readiness as connected outputs of the same work.
NIST published Revision 3 of SP 800-171 in May 2024. The CMMC framework, however, references Revision 2 as the operative standard, and contractors preparing for CMMC certification implement against Revision 2 rather than Revision 3. This decoupling between the latest NIST publication and the CMMC operative standard is intentional. The CMMC rule established Revision 2 as the standard, and changing the operative standard would require a regulatory amendment that has not yet been initiated. Contractors should plan their compliance work against Revision 2 and treat Revision 3 as relevant context rather than as an immediate obligation.
What Contractors Should Understand About the Standard
Several characteristics of NIST SP 800-171 are worth understanding directly because they affect how the standard operates in practice and how the assessment evaluates compliance.
The first characteristic is that the standard is operationally specific without being prescriptive about implementation technology. Each requirement specifies what the system must do without specifying how the system must do it. The flexibility allows contractors to satisfy the requirements using infrastructure that fits their environment, but the flexibility also requires the contractor to demonstrate that the chosen implementation actually satisfies the requirement. A requirement that the system "limit information system access to authorized users" can be satisfied through many different access control technologies, but the chosen technology must produce demonstrable evidence that access is in fact limited to authorized users.
The second characteristic is that the standard treats documentation as substantive rather than supplemental. The System Security Plan that documents the contractor's environment and the implementation of each requirement is itself one of the controls the standard requires (3.12.4). Documentation that does not describe the operational reality is therefore both a documentation finding and a control finding, and the relationship between the SSP and the implementation is structural rather than incidental. The substantive treatment of what an SSP should contain is at CMMC SSP Template.
The third characteristic is that the standard contemplates ongoing operation rather than point-in-time achievement. Many requirements specify that controls operate continuously, that records be retained over defined periods, and that periodic reviews occur on specified schedules. A contractor whose implementation reflects only a snapshot of the environment at a particular date will produce findings on the operational continuity requirements even if the snapshot itself satisfies the substantive control. Building the implementation as ongoing operations from the beginning produces the operational evidence the assessment examines.
The fourth characteristic is that the standard interacts with other regulatory provisions in ways that affect the contractor's overall compliance posture. DFARS 252.204-7012 establishes the substantive obligation, DFARS 252.204-7019 requires the SPRS score reporting, DFARS 252.204-7020 establishes the government access provision, and DFARS 252.204-7021 implements the CMMC certification requirement. The standard sits within this regulatory framework and the contractor's compliance work must address the interaction among the provisions. The regulatory framework around CMMC compliance is examined in detail at CMMC Compliance Consulting.
Where to Find the Standard and the Assessment Guidance
NIST SP 800-171 Revision 2 is available without charge from the National Institute of Standards and Technology. The standard itself, the companion assessment guide NIST SP 800-171A, and related publications are published on the NIST website and can be downloaded directly. For contractors approaching the standard for the first time, both publications are worth obtaining because the assessment guide provides the operational depth that the standard alone does not contain.
For contractors developing the implementation work, the firm's CMMC Controls Library provides individual reference cards for all 110 Level 2 controls organized by family. Each card contains the assessor language and the practitioner notes that bear on the operational implementation. The library is intended as a working reference that supplements the NIST publications with the specific assessment perspective that CMMC adds.
For contractors developing the documentation work, the firm's reference at CMMC SSP Template covers what a System Security Plan should contain, how the SSP and POA&M relate, and the common failure patterns practitioners encounter when developing or evaluating an SSP. The reference is framed around the assessment perspective rather than around generic documentation templates.