Standard · CUI · US federal contractors

NIST 800-171 compliance: the 110 requirements, Rev 3 and SPRS scoring

NIST 800-171 compliance means protecting Controlled Unclassified Information with the security requirements in NIST SP 800-171. US defense contractors must meet the 110 requirements of Revision 2 under DFARS 252.204-7012, even though Revision 3 (97 requirements) was published in May 2024, and post a self-assessment score in SPRS.

Key takeaways

What you need to know about NIST 800-171

Rev 2 still appliesA DoD class deviation keeps DFARS 7012 tied to Revision 2.
Score in SPRSA current self-assessment score is a condition of award under DFARS 7019.
Basis of CMMCCMMC Level 2 assesses the same 110 requirements.
Cloud mattersCloud services holding CUI need FedRAMP Moderate or equivalent.
Plan for Rev 3Its new families (planning, acquisition, supply chain) are coming.

Who must comply with NIST 800-171?

Non-federal organisations that process, store or transmit CUI for the US government.

Defense contractorsThrough DFARS 252.204-7012 in Department of War contracts.
SubcontractorsThe clause flows down to every tier handling CUI.
Universities and labsResearch contracts involving CUI.
Other federal contractorsAgencies increasingly require it for CUI.
Cloud and IT providersWhen they handle a contractor's CUI.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the standard requires

What does NIST 800-171 require?

NIST 800-171 requires you to protect the confidentiality of CUI on your systems through 110 requirements in 14 families (Revision 2), document them in a System Security Plan, and track gaps in a plan of action.

3.1 Access

Access Control

22 requirements on who and what can reach CUI.

In QULDEX: Access reviews on schedule
3.5 Identity

Identification and Authentication

MFA for privileged and network access.

In QULDEX: MFA coverage tracked
3.3 Logs

Audit and Accountability

Traceable, protected logs.

In QULDEX: Log reviews as evidence
3.12 SSP

Security Assessment

System Security Plan and POA&M.

In QULDEX: SSP linked to live evidence
3.13 Network

System and Communications Protection

Boundary protection and FIPS-validated crypto.

In QULDEX: Network evidence
SPRS Score

Self-assessment score

110 minus weighted deductions, posted to SPRS.

In QULDEX: Score calculated from status
Family explorer

What are the NIST 800-171 control families?

Revision 2 has 14 families and 110 requirements; Revision 3 adds three families. Select any family to see what it covers, typical evidence and the matching NIST 800-53 and ISO 27001 references.

110Rev 2 requirements
14Rev 2 families
97Rev 3 requirements
17Rev 3 families

Showing up to 6 per group. Search, filter, or open a group to see all 17.

Revision 2 families 14

  1. 3.1Access Control

    Limit system access to authorised users, processes and devices, and to permitted transactions and functions. (22 requirements)

    In QULDEXAccess reviews run as recurring tasks; MFA and session settings are evidence.

    Typical evidence
    Access policy, access reviews
    Maps to
    NIST 800-53 ACISO 27001 A.5.15

  2. 3.2Awareness and Training

    Make sure staff know security risks and are trained for their duties, including insider threat. (3 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Training records
    Maps to
    NIST 800-53 ATISO 27001 A.6.3

  3. 3.3Audit and Accountability

    Create, protect and review logs so actions can be traced to individual users. (9 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Log configuration, review records
    Maps to
    NIST 800-53 AUISO 27001 A.8.15

  4. 3.4Configuration Management

    Set and enforce baseline configurations and control changes, software and functions. (9 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Baselines, change records
    Maps to
    NIST 800-53 CMISO 27001 A.8.9

  5. 3.5Identification and Authentication

    Identify and authenticate users and devices, with MFA for privileged and network access. (11 requirements)

    In QULDEXMFA coverage is tracked per system.

    Typical evidence
    MFA settings, password policy
    Maps to
    NIST 800-53 IAISO 27001 A.8.5

  6. 3.6Incident Response

    Establish incident handling, track and report incidents, and test the capability. (3 requirements)

    In QULDEXIncidents run with DFARS 72-hour reporting timers.

    Typical evidence
    IR plan, test records
    Maps to
    NIST 800-53 IRISO 27001 A.5.24

  7. 3.7Maintenance

    Perform and control system maintenance, including remote and off-site maintenance. (6 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Maintenance logs
    Maps to
    NIST 800-53 MA

  8. 3.8Media Protection

    Protect, mark, control and sanitise media containing CUI. (9 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Media policy, sanitisation records
    Maps to
    NIST 800-53 MPISO 27001 A.7.10

  9. 3.9Personnel Security

    Screen people before access to CUI and protect CUI during terminations and transfers. (2 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Screening and offboarding records
    Maps to
    NIST 800-53 PSISO 27001 A.6.1

  10. 3.10Physical Protection

    Limit physical access, escort visitors, keep access logs and protect alternate work sites. (6 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Visitor logs, badge records
    Maps to
    NIST 800-53 PEISO 27001 A.7.2

  11. 3.11Risk Assessment

    Assess risk periodically, scan for vulnerabilities and remediate them. (3 requirements)

    In QULDEXScan results become CAPA items with due dates.

    Typical evidence
    Risk assessment, scan reports
    Maps to
    NIST 800-53 RAISO 27001 A.8.8

  12. 3.12Security Assessment

    Assess controls periodically, run plans of action, monitor continuously and keep a System Security Plan. (4 requirements)

    In QULDEXThe SSP is linked to live evidence, not a static document.

    Typical evidence
    SSP, POA&M
    Maps to
    NIST 800-53 CAISO 27001 9.2

  13. 3.13System and Communications Protection

    Monitor and protect communications at boundaries, separate functions and use FIPS-validated cryptography for CUI. (16 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Network diagrams, crypto evidence
    Maps to
    NIST 800-53 SCISO 27001 A.8.20

  14. 3.14System and Information Integrity

    Fix flaws promptly, protect against malicious code and monitor systems and alerts. (7 requirements)

    In QULDEXEach requirement in this family is pre-mapped with its NIST SP 800-171A objectives and an evidence request.

    Typical evidence
    Patch records, EDR evidence
    Maps to
    NIST 800-53 SIISO 27001 A.8.7

New in Revision 3 3

  1. 03.15PlanningRev 3 new

    Rev 3 adds planning requirements such as policies and procedures and rules of behaviour. (Rev 3 family)

    In QULDEXRev 3 families are mapped so you can move when DoD adopts Rev 3.

    Maps to
    NIST 800-53 PL

  2. 03.16System and Services AcquisitionRev 3 new

    Rev 3 adds security engineering principles, unsupported components and external system services. (Rev 3 family)

    In QULDEXRev 3 families are mapped so you can move when DoD adopts Rev 3.

    Maps to
    NIST 800-53 SA

  3. 03.17Supply Chain Risk ManagementRev 3 new

    Rev 3 adds a supply chain risk management plan, acquisition strategies and supplier requirements. (Rev 3 family)

    In QULDEXSupplier records in the vendor register support this family.

    Maps to
    NIST 800-53 SR

Family numbers follow NIST SP 800-171 Rev 2 (3.x) and Rev 3 (03.x). Requirement counts are for Rev 2. Summaries are QULDEX paraphrases.

Compliance path

How do you comply with NIST 800-171?

Scope where CUI lives, implement the 110 requirements, write the SSP, then score yourself and post it to SPRS. Most organisations need 6 to 12 months; a CUI enclave can shorten that.

  1. Find and scope CUI

    Map where CUI enters, is stored and leaves, and define the system boundary.

  2. Gap assessment against 800-171A

    Assess each requirement against its assessment objectives.

  3. Write the System Security Plan

    Describe how each requirement is met and the system boundary.

  4. Remediate and track a POA&M

    Close gaps, starting with high-weight requirements such as MFA and encryption.

  5. Score and post to SPRS

    Calculate the score and post it with the SSP date.

  6. Keep it current

    ContinuouslyMonitor and update the SSP
    Every 3 yearsRefresh the SPRS assessment at least
    On changeRe-score after major changes

Durations are QULDEX planning ranges.

Records to keep

Which documents does NIST 800-171 need?

The standard names two documents outright; assessors expect the rest.

DocumentRequirementWhere it lives in QULDEX
System Security Plan3.12.4Policy library
Plan of Action and Milestones3.12.2CAPA automation
CUI data-flow and network diagrams3.13.1Evidence vault
Access control policy and reviews3.1Policy library
Incident response plan and tests3.6.1, 3.6.3Evidence vault
Configuration baselines3.4.1Evidence vault
Risk assessment and scan reports3.11.1–3.11.2Risk register
SPRS score recordDFARS 252.204-7019Evidence vault

Requirement numbers follow NIST SP 800-171 Rev 2.

Time and cost

How long does NIST 800-171 take and what drives the effort?

Most organisations need 6 to 12 months. The size of the CUI environment and gaps in high-weight requirements such as MFA, encryption and logging drive most of the effort.

Where the time goes

Scoping2–6 wk
Gap assessment3–6 wk
SSP3–6 wk
Remediation3–9 mo
Scoring1–2 wk

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • CUI footprint: an enclave keeps the boundary small
  • High-weight gaps: 5-point requirements cost the most score
  • Cloud services: need FedRAMP Moderate or equivalent
  • Legacy systems: may need compensating measures
  • Existing ISO 27001: covers part of the requirements
Readiness check · 2 minutes

How ready are you for NIST 800-171?

Check these eight things first. Nothing you enter leaves this page.

ScopeDo you know where CUI lives and the system boundary?
3.12.4Do you have a current System Security Plan?
3.5.3Is MFA in place for privileged and network access?
3.13.11Is CUI protected with FIPS-validated cryptography?
3.3.1Are logs kept and reviewed to trace user actions?
3.11.2Do you scan for vulnerabilities and fix findings?
3.6.1Do you have a tested incident response capability?
SPRSIs a current score posted in SPRS?
Crosswalk

How NIST 800-171 maps to CMMC, NIST 800-53 and ISO 27001

NIST 800-171 is derived from NIST 800-53 Moderate, and CMMC Level 2 assesses it directly. ISO 27001 evidence covers part of it.

Revision 2 vs Revision 3 at a glance

NIST SP 800-171 Rev 2NIST SP 800-171 Rev 3
Published2020 (with updates)May 2024
Requirements11097
Families1417 (adds PL, SA, SR)
ParametersFixedOrganisation-defined parameters
Required by DFARS 7012Yes, via class deviationNot yet
In QULDEXQULDEX maps both revisions, so moving to Rev 3 reuses Rev 2 evidence.

NIST 800-171 crosswalk

NIST 800-171 Rev 2CMMC Level 2NIST 800-53 Rev 5ISO 27001:2022Shared evidence
3.1 Access ControlACACA.5.15–A.5.18Access reviews
3.3 AuditAUAUA.8.15Log samples
3.4 ConfigurationCMCMA.8.9Baselines
3.5 IdentificationIAIAA.8.5MFA settings
3.6 Incident ResponseIRIRA.5.24–A.5.26IR plan
3.11 Risk AssessmentRARA6.1.2, A.8.8Scan reports
3.12 Security AssessmentCACA, PL9.2SSP, POA&M
3.13 CommunicationsSCSCA.8.20–A.8.24Network diagrams

Indicative mapping for planning. CMMC vs NIST 800-171 is compared in full on the blog.

Where QULDEX fits

How QULDEX runs NIST 800-171 from SSP to SPRS score

QULDEX is NIST 800-171 compliance and audit management software built from EGV Group's audit delivery, used by contractors, their advisors and the assessors who check them. Pick your role to see who does what.

For organisations handling CUI.

  1. ScopeScope CUIBoundary and asset categories
  2. SSPWrite the SSPSSP linked to live evidence
  3. FixRemediate gapsPOA&M with owners and dates
  4. ScorePost to SPRSScore calculated from status
  5. MonitorKeep evidence currentRecurring evidence requests
  6. Rev 3Plan the moveRev 2 to Rev 3 mapping
Without one systemWith QULDEX
SPRS score calculated in a spreadsheetScore calculated from status
SSP out of dateSSP linked to live evidence
Rev 3 unplannedBoth revisions mapped
Evidence scattered across teamsOne vault per requirement
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

NIST 800-171 questions people ask

Which revision of NIST 800-171 applies?

For defense contracts, Revision 2. A DoD class deviation keeps DFARS 252.204-7012 tied to Rev 2 (110 requirements), although NIST published Rev 3 (97 requirements) in May 2024.

How many requirements are in NIST 800-171?

Revision 2 has 110 requirements in 14 families. Revision 3 has 97 requirements in 17 families, adding planning, system and services acquisition, and supply chain risk management.

How is the SPRS score calculated?

You start at 110 and subtract 1, 3 or 5 points for each requirement not met, according to the DoD Assessment Methodology, so the lowest possible score is −203.

How does NIST 800-171 relate to CMMC?

CMMC Level 2 assesses the same 110 NIST SP 800-171 Rev 2 requirements, either by self-assessment or by a C3PAO.

Who must comply with NIST 800-171?

Non-federal organisations that process, store or transmit CUI under a contract requiring it, most often defense contractors and subcontractors through DFARS 252.204-7012.

Sources

References

  1. NIST SP 800-171 Rev 2 and Rev 3 (May 2024). csrc.nist.gov
  2. NIST SP 800-171A, assessment procedures. csrc.nist.gov
  3. DFARS 252.204-7012, 7019 and 7020. acquisition.gov
  4. DFARS class deviation 2026-O0025 (Rev 3). acq.osd.mil
  5. DoD Assessment Methodology for NIST SP 800-171. acq.osd.mil

Reviewed by

Abhishek Yadav

Lead Auditor · QULDEX

Reviewed this page against NIST SP 800-171 Rev 2 and Rev 3 and the DFARS clauses: families, counts and SPRS scoring.

Page history
  • : Page first built: family explorer for Rev 2 and Rev 3, SPRS scoring and readiness check

Know your SPRS score before your next bid

Answer a short readiness check and get a gap summary by family. No sales call needed to see the result.

Schedule
Book a Demo