800-171 Evidence

September 29, 2026

What Is NIST 800-171?

What is NIST 800-171?

NIST 800-171 is a federal publication that protects a specific type of data. NIST stands for the National Institute of Standards and Technology. The current revision, Rev 3, was finalized in May 2024 and holds 97 requirements across 17 families (CSRC).

Each requirement ties to a parent control in NIST SP 800-53 Revision 5 (CSRC). That link keeps the CUI rules aligned with the wider federal control catalog.

What is CUI?

CUI stands for Controlled Unclassified Information. It is government information that is not classified but still needs protection.

Think of technical drawings, export-controlled data, or contract details. The publication covers systems that store, process, or transmit this data in nonfederal organizations (CSRC).

CUI comes in many categories, from export-controlled technical data to legal and financial records. Your contract marks which information counts as CUI. When in doubt, ask your contracting officer before you share it.

What changed in Rev 3?

Rev 3 reorganized the rules into 17 families, up from 14 (CSRC). Three families are new: Planning, System and Services Acquisition, and Supply Chain Risk Management.

The count moved from 110 requirements in Rev 2 to 97 in Rev 3. Rev 3 supersedes Rev 2, which NIST published on January 28, 2021 (CSRC).

Which revision do DoD contractors follow today?

The answer is Rev 2. On May 2, 2024, DoD issued Class Deviation 2024-O0013. It pins DFARS 252.204-7012 to NIST SP 800-171 Revision 2 (DoD memo). The clause no longer floats to the newest revision.

CMMC Level 2 also runs on Rev 2. The CMMC rule assesses 110 practices drawn from Rev 2 (32 CFR Part 170). Moving CMMC to Rev 3 will take formal rulemaking (32 CFR Part 170).

So: track Rev 3 to see where the rules are heading, but build your program on Rev 2 today.

What should contractors do about Rev 3?

Keep your current program on Rev 2. That is the version your contracts and assessments use today.

Read Rev 3 on the side. Note the new families on planning, services acquisition, and supply chain risk. Ask whether your program already covers them in practice.

Do not rebuild your documentation around Rev 3 yet. Wait for DoD rulemaking to set the transition date. Rebuilding early means doing the work twice.

Who has to follow it?

Companies that handle CUI under federal contracts usually must follow it. The duty arrives through contract language, such as the DFARS safeguarding clause.

It applies to every system the CUI touches: servers, laptops, and cloud services. If CUI flows down to subcontractors, the requirements flow with it.

Small businesses are not exempt. The rules key off the data you handle, not your company size.

How does it connect to CMMC?

CMMC stands for Cybersecurity Maturity Model Certification. It is the DoD program that verifies contractor cybersecurity.

Level 2 is built directly on NIST 800-171 Rev 2. Meet the 110 requirements and you meet the heart of a Level 2 assessment (32 CFR Part 170). In short, NIST 800-171 is the rulebook and CMMC Level 2 is the exam.

Where should a beginner start?

Find every place your CUI lives. List the systems that store, process, or transmit it. You cannot protect data you have not mapped.

Compare each requirement against that map. Note what is in place and what is missing. The missing items become your plan of action and milestones.

Write down what you do as you go. Assessors ask for evidence, not promises. PolicyCortex gathers that evidence from live Azure settings and maps it to NIST 800-171.

Where can you read the actual publication?

NIST publishes SP 800-171 free on its Computer Security Resource Center. The Rev 3 page holds the final PDF and an HTML version (CSRC).

Read the requirements in the publication itself, not in a vendor summary. Vendor summaries help, but the publication is the source your assessor uses.

Sources

Next step

Start with a map of your CUI, then collect proof for each requirement. See how PolicyCortex pulls that proof from your Azure tenant.