Skip to main content
—
Framework library
Framework module · nist-800-171-rev3

NIST SP 800-171

NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.

Rev. 3 · NIST Computer Security Resource Center · published 2024-05-14

Standing today
Directory entry

00Answer

from the registry record
What is NIST SP 800-171?
NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.
Who does NIST SP 800-171 apply to?
NIST SP 800-171 applies to defense industrial base, federal contractors, US, per NIST Computer Security Resource Center.
What is the current version of NIST SP 800-171?
The current edition is Rev. 3, issued by NIST Computer Security Resource Center and published 2024-05-14. Source: https://csrc.nist.gov/pubs/sp/800/171/r3/final.
What does an assessment under NIST SP 800-171 require?
97 control units are on record (Security requirements in SP 800-171 Rev. 3 across 17 families, as published by NIST.), organized into 17 control families: AC, AT, AU, CM, IA, IR, MA, MP, PE, PL, PS, RA, CA, SA, SC, SI, SR.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST SP 800-171 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; requirements not ingested as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
97Security requirements in SP 800-171 Rev. 3 across 17 families, as published by NIST.
Control families
AC · AT · AU · CM · IA · IR · MA · MP · PE · PL · PS · RA · CA · SA · SC · SI · SR
Applies to
defense industrial base · federal contractors · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
Rev. 3 is the current NIST publication, but DoD contracts still enforce Rev. 2 through a DFARS class deviation, reinforced by the 2026-07-13 CMMC Phase II suspension, which pins interim enforcement to Rev. 2 self-assessment. Do not tell a defense contractor Rev. 3 is their contractual baseline without checking their clause.Expected: DFARS transition not expected before late 2026 to 2027 at the earliest

03Version ledger

2 editions
Rev. 2Supersededdate not published
Rev. 3Current edition · supersedes Rev. 22024-05-14

03aCoexisting versions

1 other version in force
  1. Rev. 2

    Applies to: DoD contracts under the current DFARS class deviation — the sole self-assessment baseline while CMMC Phase II remains suspended

    No scheduled end date — DFARS rulemaking to require Rev. 3 is not expected before late 2026 to 2027 at the earliest; no date has been set.

    Source (opens in a new tab)

05Change history

06Related frameworks

scored from registry facts
  1. CMMC32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025)

    Also applies to defense industrial base · The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.

  2. Also applies to defense industrial base · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

  3. FISMAFederal Information Security Modernization Act of 2014

    Also applies to federal contractors · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.

  4. Also applies to federal contractors · The secure software development practices federal software attestations are written against — the reference behind most supply-chain questionnaires.

NIST SP 800-171 | ControlFrame