Standard · CUI · US federal contractors
NIST 800-171 compliance means protecting Controlled Unclassified Information with the security requirements in NIST SP 800-171. US defense contractors must meet the 110 requirements of Revision 2 under DFARS 252.204-7012, even though Revision 3 (97 requirements) was published in May 2024, and post a self-assessment score in SPRS.
Non-federal organisations that process, store or transmit CUI for the US government.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
NIST 800-171 requires you to protect the confidentiality of CUI on your systems through 110 requirements in 14 families (Revision 2), document them in a System Security Plan, and track gaps in a plan of action.
22 requirements on who and what can reach CUI.
In QULDEX: Access reviews on scheduleMFA for privileged and network access.
In QULDEX: MFA coverage trackedTraceable, protected logs.
In QULDEX: Log reviews as evidenceSystem Security Plan and POA&M.
In QULDEX: SSP linked to live evidenceBoundary protection and FIPS-validated crypto.
In QULDEX: Network evidence110 minus weighted deductions, posted to SPRS.
In QULDEX: Score calculated from statusRevision 2 has 14 families and 110 requirements; Revision 3 adds three families. Select any family to see what it covers, typical evidence and the matching NIST 800-53 and ISO 27001 references.
Showing up to 6 per group. Search, filter, or open a group to see all 17.
3.1Access ControlLimit system access to authorised users, processes and devices, and to permitted transactions and functions. (22 requirements)
In QULDEXAccess reviews run as recurring tasks; MFA and session settings are evidence.
3.2Awareness and TrainingMake sure staff know security risks and are trained for their duties, including insider threat. (3 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.3Audit and AccountabilityCreate, protect and review logs so actions can be traced to individual users. (9 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.4Configuration ManagementSet and enforce baseline configurations and control changes, software and functions. (9 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.5Identification and AuthenticationIdentify and authenticate users and devices, with MFA for privileged and network access. (11 requirements)
In QULDEXMFA coverage is tracked per system.
3.6Incident ResponseEstablish incident handling, track and report incidents, and test the capability. (3 requirements)
In QULDEXIncidents run with DFARS 72-hour reporting timers.
3.7MaintenancePerform and control system maintenance, including remote and off-site maintenance. (6 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.8Media ProtectionProtect, mark, control and sanitise media containing CUI. (9 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.9Personnel SecurityScreen people before access to CUI and protect CUI during terminations and transfers. (2 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.10Physical ProtectionLimit physical access, escort visitors, keep access logs and protect alternate work sites. (6 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.11Risk AssessmentAssess risk periodically, scan for vulnerabilities and remediate them. (3 requirements)
In QULDEXScan results become CAPA items with due dates.
3.12Security AssessmentAssess controls periodically, run plans of action, monitor continuously and keep a System Security Plan. (4 requirements)
In QULDEXThe SSP is linked to live evidence, not a static document.
3.13System and Communications ProtectionMonitor and protect communications at boundaries, separate functions and use FIPS-validated cryptography for CUI. (16 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
3.14System and Information IntegrityFix flaws promptly, protect against malicious code and monitor systems and alerts. (7 requirements)
In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.
03.15PlanningRev 3 newRev 3 adds planning requirements such as policies and procedures and rules of behaviour. (Rev 3 family)
In QULDEXRev 3 families are mapped so you can move when DoD adopts Rev 3.
03.16System and Services AcquisitionRev 3 newRev 3 adds security engineering principles, unsupported components and external system services. (Rev 3 family)
In QULDEXRev 3 families are mapped so you can move when DoD adopts Rev 3.
03.17Supply Chain Risk ManagementRev 3 newRev 3 adds a supply chain risk management plan, acquisition strategies and supplier requirements. (Rev 3 family)
In QULDEXSupplier records in the vendor register support this family.
Nothing matches that search.
Family numbers follow NIST SP 800-171 Rev 2 (3.x) and Rev 3 (03.x). Requirement counts are for Rev 2. Summaries are QULDEX paraphrases.
Scope where CUI lives, implement the 110 requirements, write the SSP, then score yourself and post it to SPRS. Most organisations need 6 to 12 months; a CUI enclave can shorten that.
Map where CUI enters, is stored and leaves, and define the system boundary.
Assess each requirement against its assessment objectives.
Describe how each requirement is met and the system boundary.
Close gaps, starting with high-weight requirements such as MFA and encryption.
Calculate the score and post it with the SSP date.
Durations are QULDEX planning ranges.
The standard names two documents outright; assessors expect the rest.
| Document | Requirement | Where it lives in QULDEX |
|---|---|---|
| System Security Plan | 3.12.4 | Policy library |
| Plan of Action and Milestones | 3.12.2 | CAPA automation |
| CUI data-flow and network diagrams | 3.13.1 | Evidence vault |
| Access control policy and reviews | 3.1 | Policy library |
| Incident response plan and tests | 3.6.1, 3.6.3 | Evidence vault |
| Configuration baselines | 3.4.1 | Evidence vault |
| Risk assessment and scan reports | 3.11.1–3.11.2 | Risk register |
| SPRS score record | DFARS 252.204-7019 | Evidence vault |
Requirement numbers follow NIST SP 800-171 Rev 2.
Most organisations need 6 to 12 months. The size of the CUI environment and gaps in high-weight requirements such as MFA, encryption and logging drive most of the effort.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
NIST 800-171 is derived from NIST 800-53 Moderate, and CMMC Level 2 assesses it directly. ISO 27001 evidence covers part of it.
| NIST SP 800-171 Rev 2 | NIST SP 800-171 Rev 3 | |
|---|---|---|
| Published | 2020 (with updates) | May 2024 |
| Requirements | 110 | 97 |
| Families | 14 | 17 (adds PL, SA, SR) |
| Parameters | Fixed | Organisation-defined parameters |
| Required by DFARS 7012 | Yes, via class deviation | Not yet |
| In QULDEX | QULDEX maps both revisions, so moving to Rev 3 reuses Rev 2 evidence. | |
| NIST 800-171 Rev 2 | CMMC Level 2 | NIST 800-53 Rev 5 | ISO 27001:2022 | Shared evidence |
|---|---|---|---|---|
| 3.1 Access Control | AC | AC | A.5.15–A.5.18 | Access reviews |
| 3.3 Audit | AU | AU | A.8.15 | Log samples |
| 3.4 Configuration | CM | CM | A.8.9 | Baselines |
| 3.5 Identification | IA | IA | A.8.5 | MFA settings |
| 3.6 Incident Response | IR | IR | A.5.24–A.5.26 | IR plan |
| 3.11 Risk Assessment | RA | RA | 6.1.2, A.8.8 | Scan reports |
| 3.12 Security Assessment | CA | CA, PL | 9.2 | SSP, POA&M |
| 3.13 Communications | SC | SC | A.8.20–A.8.24 | Network diagrams |
Indicative mapping for planning. CMMC vs NIST 800-171 is compared in full on the blog.
QULDEX is NIST 800-171 compliance and audit management software built from EGV Group's audit delivery, used by contractors, their advisors and the assessors who check them. Pick your role to see who does what.
For organisations handling CUI.
For RPOs, consultants and internal audit.
For C3PAOs and DIBCAC-style reviews.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →For defense contracts, Revision 2. A DoD class deviation keeps DFARS 252.204-7012 tied to Rev 2 (110 requirements), although NIST published Rev 3 (97 requirements) in May 2024.
Revision 2 has 110 requirements in 14 families. Revision 3 has 97 requirements in 17 families, adding planning, system and services acquisition, and supply chain risk management.
You start at 110 and subtract 1, 3 or 5 points for each requirement not met, according to the DoD Assessment Methodology, so the lowest possible score is −203.
CMMC Level 2 assesses the same 110 NIST SP 800-171 Rev 2 requirements, either by self-assessment or by a C3PAO.
Non-federal organisations that process, store or transmit CUI under a contract requiring it, most often defense contractors and subcontractors through DFARS 252.204-7012.
NIST CSF, 800-53 and CIS Controls articles.
blog.quldex.comA file-naming scheme assessors can follow.
blog.quldex.comHow many samples assessors look at.
blog.quldex.comGovernance outcomes that support an 800-171 programme.
Reviewed by
Answer a short readiness check and get a gap summary by family. No sales call needed to see the result.