Skip to content

NIST SP 800-171

What is NIST SP 800-171?

A NIST publication that provides recommended security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organisations. Compliance with 800-171 is required for US defence contractors.

Compliance

Each of these is named in at least one of the same controls as nist sp 800-171. The number is how many controls name both.

What the standards actually require on nist sp 800-171

Requirements naming nist sp 800-171 across 4 standards, quoted from the control text.

The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in...

DFARS-7012-b · Adequate security - implement NIST SP 800-171
FISMA3 controls

FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).

FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration

Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...

IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral

Questions people ask about nist sp 800-171

What is NIST SP 800-171?
A NIST publication that provides recommended security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organisations. Compliance with 800-171 is required for US defence contractors.
Why is NIST SP 800-171 important for compliance?
NIST SP 800-171 is a key concept in Compliance. Understanding nist sp 800-171 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address NIST SP 800-171?
NIST SP 800-171 appears in the requirement text of DFARS 252.204-7012 - Safeguarding Covered Defense Information, FISMA, IRS Publication 1075, ITAR - International Traffic in Arms Regulations. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about NIST SP 800-171?
Explore our compliance framework pages to see how nist sp 800-171 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how NIST SP 800-171 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.