800-171 is a focused set of security requirements derived from the NIST SP 800-53 catalog, tailored for one job: protecting Controlled Unclassified Information where it sits outside federal systems - on your network, your endpoints, your Microsoft 365 tenant, your cloud services.
Revision 3 organizes the requirements into 17 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity, and - new in Revision 3 - planning, system and services acquisition, and supply chain risk management.
The requirements are outcomes, not products. "Employ multifactor authentication" does not name a vendor. That makes 800-171 achievable with ordinary, well-run IT - and it means the work is configuration, process, and evidence, not a shopping list.
800-171 applies to nonfederal organizations when an agreement makes it apply. The mechanism is contract language, not the data itself:
Size is not a factor. A five-person machine shop with CUI in email has the same obligations as a prime. If your contract cites 252.204-7012, or a prime flows it down to you, 800-171 is your working standard.
800-171 protects one thing: Controlled Unclassified Information on nonfederal systems. In a defense environment that typically means:
The scoping decision that matters most is where CUI is allowed to exist. Every system inside that boundary inherits the full requirement set - which is why experienced contractors isolate CUI into a defined enclave instead of letting it sprawl across the whole environment.
800-171 sits in the middle of the defense chain:
Read together: the CUI Program names the data, 800-171 names the controls, DFARS names the obligation, and CMMC names the proof.
Translated from requirement language into operations, 800-171 expects a contractor environment to have:
None of this is exotic. It is disciplined IT, documented well enough to survive an assessment.
For a defense contractor, 800-171 is not a best practice - it is a condition of doing business:
The practical risk is the gap between what you attested and what is actually running. Closing that gap is the entire job.
800-171 is a strong forcing function for general cyber hygiene. An organization that genuinely meets it has covered most of what cyber insurers ask, most of what enterprise security reviews probe, and the operational core of frameworks like SOC 2 and ISO 27001.
The reverse is also true: if you have already built disciplined identity, logging, and incident response for another framework, your 800-171 gap is usually scoping and evidence - deciding exactly where CUI lives and proving the controls around it.
Reality check: the organizations that struggle with 800-171 are rarely missing sophisticated security. They are missing scoping and proof.
CUI has spread across email, personal drives, and unmanaged devices; nobody can say precisely where it is; and the controls that exist are undocumented, so a self-assessment score is a guess. The fix is unglamorous: draw a boundary around CUI, run the environment inside it properly, and write down what you do.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment scopes where CUI actually lives in your environment, measures you against each 800-171 requirement, and produces the corrective plan - and evidence trail - that an assessment score can stand on.
Read your clauses. DFARS 252.204-7012, flow-down language from primes, and CMMC Level 2 requirements all point at 800-171, but the specifics - self-assessment versus third-party assessment, and which version - come from the contract, not the internet.
Work from the CUI Registry and your contract deliverables to decide what you actually hold, then define the boundary: which systems, accounts, and locations CUI is permitted to touch. A tight enclave shrinks everything that follows.
Score your current state against every 800-171 requirement using NIST SP 800-171A as the yardstick. Be honest - the score you post to SPRS is a representation you are accountable for.
Document your System Security Plan describing how each requirement is met, and a Plan of Action & Milestones for every gap, with owners and dates. These two documents are the artifacts every downstream review asks for.
Remediate the highest-exposure gaps first - identity, email, endpoints, logging - and collect evidence as you go. Evidence is what turns a claim into a score that survives verification.
800-53 is the full federal control catalog, binding on federal agencies and their systems under FISMA. 800-171 is the tailored subset written for one job: protecting CUI on nonfederal systems - your systems. If you are a contractor, 800-171 is your working document; 800-53 is the source it was derived from.
Revision 3 is the current publication (May 2024). But your contract rules: CMMC Level 2, as codified at 32 CFR Part 170, is built on Revision 2, and DFARS clause language references the version current when it was written. When the publication and the contract differ, the contract wins - confirm which revision your clauses and assessment type actually reference.
It depends on the solicitation and the CMMC level assigned to the work. DFARS 252.204-7019/-7020 already require a self-assessment score posted to SPRS before award, and CMMC Level 2 self-assessment is required in covered contracts - third-party certification for Level 2 is tied to CMMC Phase II, currently suspended. Either way, the underlying obligation is the same: implement 800-171 and be able to show it.
The System Security Plan (SSP) is the document that describes your system boundary and how each 800-171 requirement is implemented. Yes, you need one - 800-171 expects it, DoD assessments ask for it, and a score without an SSP behind it cannot be substantiated. The companion document is the Plan of Action & Milestones (POA&M), which tracks the gaps you have not closed yet.
If CUI or covered defense information reaches your systems, yes. The DFARS clause flows down to subcontractors and suppliers without regard to size, and primes increasingly verify their suppliers' posture. The good news for small shops: a tightly scoped environment - a defined enclave for CUI rather than the whole network - makes compliance proportionate to what you actually handle.
The assessment itself typically runs 2 to 4 weeks. Remediation depends on your starting posture and scope - a disciplined environment with a sprawl problem fixes scoping and documentation; an undisciplined one rebuilds identity, patching, and logging. The gap picture tells you which situation you are in.
Cost is driven by scope and gaps, not by the publication - the standard itself is free. A tight CUI enclave costs far less to secure and evidence than an entire network. We publish no pricing; you get a firm quote after the assessment establishes your actual gap, and the assessment conversation costs nothing.
Start with the boundary, not the controls: confirm what your contracts require, identify what CUI you actually hold, and decide where it is allowed to live. Then a gap assessment against the 800-171 requirements produces your SSP, your POA&M, and a prioritized remediation plan - in that order.
Official source: NIST Computer Security Resource Center
Secondary source: Acquisition.gov, DFARS 252.204-7012
Source verified 2026-09-18
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-09-18