NIST SP 800-171 COMPLIANCE GUIDE

NIST SP 800-171 Compliance Guide

NIST SP 800-171 is the federal standard for protecting Controlled Unclassified Information (CUI) on nonfederal systems — the security baseline nearly every defense contractor handling CUI has to meet. If your company holds a DoD contract, or works as a subcontractor on one, these requirements are very likely already written into your agreement through DFARS 252.204-7012. This guide covers what the standard protects, who has to comply, how the 14 requirement families break down, how self-assessment scoring works in SPRS, how NIST SP 800-171 relates to CMMC certification, and where Essendis can help close the gaps.

Talk to a Compliance Expert

What NIST SP 800-171 Protects

NIST SP 800-171, published by the National Institute of Standards and Technology, defines the security requirements for protecting Controlled Unclassified Information when it lives on or moves through systems outside the federal government — in other words, your network, not a government-owned one. CUI covers a broad range of sensitive-but-unclassified defense data, including technical drawings, unclassified controlled technical information, and export-controlled specifications. If your business creates, receives, transmits, or stores CUI as part of DoD work, NIST SP 800-171 is the control set you're expected to have in place, whether or not a contracting officer has ever explicitly walked you through it.

Who Has to Comply

Compliance isn't something you opt into — it's a contractual obligation. DFARS 252.204-7012 flows the NIST SP 800-171 requirement down from prime contractors to every subcontractor that touches CUI, at every tier of the supply chain. A five-person machine shop building a component to a controlled drawing carries the same underlying obligation as a large prime. Contracting officers increasingly expect a current self-assessment score on file in SPRS before award, and where CMMC Level 2 certification applies to a contract, it's assessed directly against these same 110 requirements.

The 14 Requirement Families

NIST SP 800-171 Revision 2 — the version CMMC Level 2 currently assesses against — organizes 110 individual security requirements into 14 families. Each family groups related controls, from who can log into your systems to how you respond when something goes wrong. At a glance:

NIST released Revision 3 in 2024, reorganizing the same underlying control philosophy into 97 requirements across 17 families. As of this writing, CMMC Level 2 assessments are still conducted against Revision 2's 110 requirements — always confirm the current baseline that applies to your specific contract against official DoD and NIST guidance rather than assuming.

Scoring & SPRS

Self-assessment against NIST SP 800-171 uses a documented scoring methodology: you start at a maximum of 110 points and subtract 1, 3, or 5 points for each requirement that isn't fully implemented, depending on how significant that control is to overall security. The resulting score, along with the date you expect to reach full implementation, is reported into the Supplier Performance Risk System (SPRS), as required under DFARS 252.204-7019 and 252.204-7020. For requirements that aren't fully implemented yet, a Plan of Action and Milestones (POA&M) is allowed for some items — giving you a documented path to closure instead of requiring everything finished before you can report a score at all.

Not Sure Where Your Score Stands?

Request a Readiness Assessment

NIST SP 800-171 vs. CMMC

It helps to think of NIST SP 800-171 as the control set and CMMC as the verification model built on top of it. CMMC Level 1 covers a lighter set of practices for Federal Contract Information. CMMC Level 2 maps directly onto the 110 requirements in NIST SP 800-171 Revision 2, verified through self-assessment for some contracts and third-party assessment for most contracts handling CUI. CMMC Level 3 builds further on Level 2 using additional controls from NIST SP 800-172. In short: implementing NIST SP 800-171 well is the work; CMMC is how the DoD confirms you actually did it.

How Essendis Helps

Getting from a spreadsheet of 110 requirements to a defensible SPRS score and a durable security program is where most contractors get stuck. Essendis runs readiness assessments that map your current environment against every requirement, identify real gaps instead of paperwork gaps, and build a POA&M you can actually execute — the same process that helped one Essendis client reach a perfect 110/110 score on their CMMC Level 2 assessment. For contractors who'd rather shrink the assessment boundary than uplift an entire network, a secure enclave isolates CUI into a purpose-built, compliant environment. And once controls are in place, ongoing vCISO support keeps them maintained, monitored, and audit-ready.

Related Resources

NIST SP 800-171 doesn't stand alone. It connects directly to DFARS flow-down obligations, funding options for smaller contractors, and the third-party assessment process itself. Explore the related guides below.

DFARS 252.204-7012 Compliance

The clause that makes NIST SP 800-171 mandatory — and what it adds on top.

Read the DFARS Guide

CMMC Small-Business Grants

Where funding help exists for DIB contractors facing compliance costs.

Explore Funding Options

C3PAO & CMMC Assessment Explained

What actually happens during a CMMC Level 2 third-party assessment.

Understand the Assessment

Ready to Close Your NIST SP 800-171 Gaps?

Contact Essendis