NIST SP 800-171
What is NIST SP 800-171?
A NIST publication that provides recommended security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organisations. Compliance with 800-171 is required for US defence contractors.
Terms that appear alongside nist sp 800-171
Each of these is named in at least one of the same controls as nist sp 800-171. The number is how many controls name both.
- nist 8 shared controls
- fedramp 4 shared controls
- cmmc 4 shared controls
- encryption 3 shared controls
- baseline 3 shared controls
- authorization 3 shared controls
- audit 3 shared controls
- cybersecurity 3 shared controls
Frameworks that govern nist sp 800-171
What the standards actually require on nist sp 800-171
Requirements naming nist sp 800-171 across 4 standards, quoted from the control text.
The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in...
DFARS-7012-b · Adequate security - implement NIST SP 800-171 →FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).
FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration →Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...
IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral →ITAR technical data + defense services + Deemed Export Rule require careful management of foreign person access to controlled information regardless of physical location.
ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions · ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL →Questions people ask about nist sp 800-171
What is NIST SP 800-171?
Why is NIST SP 800-171 important for compliance?
Which compliance frameworks address NIST SP 800-171?
Where can I learn more about NIST SP 800-171?
See how NIST SP 800-171 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.