NIST SP 800-171
NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.
Rev. 3 · NIST Computer Security Resource Center · published 2024-05-14
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NIST SP 800-171 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; requirements not ingested as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- 97Security requirements in SP 800-171 Rev. 3 across 17 families, as published by NIST.
- Control families
- AC · AT · AU · CM · IA · IR · MA · MP · PE · PL · PS · RA · CA · SA · SC · SI · SR
- Applies to
- defense industrial base · federal contractors · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- Rev. 3 is the current NIST publication, but DoD contracts still enforce Rev. 2 through a DFARS class deviation, reinforced by the 2026-07-13 CMMC Phase II suspension, which pins interim enforcement to Rev. 2 self-assessment. Do not tell a defense contractor Rev. 3 is their contractual baseline without checking their clause.Expected: DFARS transition not expected before late 2026 to 2027 at the earliest
03Version ledger
| Rev. 2 | Superseded | date not published |
| Rev. 3 | Current edition · supersedes Rev. 2 | 2024-05-14 |
03aCoexisting versions
- Rev. 2
Applies to: DoD contracts under the current DFARS class deviation — the sole self-assessment baseline while CMMC Phase II remains suspended
No scheduled end date — DFARS rulemaking to require Rev. 3 is not expected before late 2026 to 2027 at the earliest; no date has been set.
Source (opens in a new tab)
05Change history
06Related frameworks
- CMMC32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025)
Also applies to defense industrial base · The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.
- NIST SP 800-172Rev. 3
Also applies to defense industrial base · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
- FISMAFederal Information Security Modernization Act of 2014
Also applies to federal contractors · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.
- NIST SSDFv1.1
Also applies to federal contractors · The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.