NIST Special Publication 800-171 sets security requirements for protecting controlled unclassified information in nonfederal systems and organizations when an applicable agreement requires those safeguards. Revision 2 contains 110 requirements in 14 families, covering access, people, technology, physical protection, and the assessment of security controls. As of September 30, 2026, the Department of War CIO identifies Revision 2 as the baseline for CMMC Level 2, even though NIST has published Revision 3. For defense contractors, the contract, the information involved, and the system boundary determine applicability, while CMMC specifies how implementation is assessed.
A revision number answers only one part of the problem. Before buying a tool or building a control checklist, identify the obligation, the information, and the system that handles it. That gives the checklist a boundary.
Who must implement NIST SP 800-171?
NIST SP 800-171 addresses CUI in nonfederal systems. Publication of a NIST standard doesn’t, by itself, make every federal supplier subject to every requirement.
For defense work, read DFARS 252.204-7012 in the contract. Its covered-defense-information definition and safeguarding provisions connect the information to the contractor’s systems. Paragraph (m) addresses applicable subcontract flowdown.
Use this reading order:
- Identify the clause and edition incorporated into the contract, including applicable deviations and amendments.
- Identify covered defense information supplied or developed for performance.
- Map the systems that process, store, or transmit it, and the components providing their protection.
- Record the applicable standard and assessment obligation separately.
A civilian agency contract needs its own clause review. Federal contract information and CUI also aren’t interchangeable labels. Start with the DFARS 7012 guide for the contract mechanics, then document the CUI boundary.
The 14 Revision 2 families
Revision 2 groups its 110 requirements into 14 families. The counts below come from Chapter 3’s numbered requirements. They count requirements, rather than tools, policies, or assessment objectives.
| Family | Requirements | A practical question for the owner |
|---|---|---|
| Access Control | 22 | Who can use the system, and what can each account do? |
| Awareness and Training | 3 | Do people understand their security responsibilities? |
| Audit and Accountability | 9 | Can activity be recorded, reviewed, and attributed? |
| Configuration Management | 9 | Is the approved configuration known and controlled? |
| Identification and Authentication | 11 | How does the system establish an identity? |
| Incident Response | 3 | Can the team prepare for and handle incidents? |
| Maintenance | 6 | Who performs maintenance, with which tools and access? |
| Media Protection | 9 | How is information protected on removable or other media? |
| Personnel Security | 2 | Are screening and personnel changes handled? |
| Physical Protection | 6 | Who can physically reach the systems? |
| Risk Assessment | 3 | Are vulnerabilities and risks identified and addressed? |
| Security Assessment | 4 | Are controls assessed and improvement actions tracked? |
| System and Communications Protection | 16 | How are communications and system boundaries protected? |
| System and Information Integrity | 7 | How are flaws and malicious activity detected and addressed? |
Treat the questions as an orientation aid. They don’t replace the requirement text. A family with fewer entries is not necessarily easier or less important to the system.
Basic and derived requirements
Revision 2 distinguishes basic requirements, drawn from FIPS 200’s high-level requirements, from derived requirements that supplement them using NIST SP 800-53. The labels explain their origin. Both sets belong in the implementation review.
Read both. A checklist that stops at basic requirements leaves part of Revision 2 unexamined.
Which revision applies to CMMC Level 2?
As of September 30, 2026, the DoW CIO program page identifies 110 NIST SP 800-171 Revision 2 requirements for CMMC Level 2. Publication of the newer revision does not automatically change a contract’s baseline. NIST marks Revision 2 as withdrawn and superseded by Revision 3 on May 14, 2024. The NIST publication record describes the standard’s publication status, while the contract and CMMC rule determine the applicable obligation.
That distinction matters when a consultant’s spreadsheet, a software library, and a contract use different revisions. Label each mapping with its revision before comparing the results. Otherwise, apparently missing requirements may reflect different numbering or structure.
The Revision 2 versus Revision 3 comparison covers the transition question. Keep this page as the definition and family map.
NIST requirements and CMMC assessments do different jobs
NIST SP 800-171 supplies security requirements. CMMC adds program rules for assessing their implementation and affirming status. There are CMMC levels, but no “NIST 800-171 Level 1” control set in Revision 2.
As of September 30, 2026, the DoW CIO says CMMC remains in Phase I and Phase II is suspended. The current program page describes self-assessment requirements. Avoid turning the shorthand “CMMC Level 2 equals NIST 800-171” into a claim that every Level 2 contract currently requires a third-party assessment.
For the broader distinction, see CMMC versus NIST SP 800-171. The assessment method and the underlying safeguarding obligation belong in separate fields of a readiness plan.
NIST SP 800-171 Revision 2, requirement 3.13.11, uses a precise condition:
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
Worked example: test the access path
Consider a hypothetical engineering team that accesses contract drawings through a remote workspace. The example is a way to organize a review, not evidence that a particular architecture passes.
For Revision 2 requirement 3.5.3, start by identifying privileged and non-privileged accounts and their access paths. Then examine where multifactor authentication is enforced. A screenshot of one successful login leaves other paths unanswered.
A useful working record would contain the requirement number, relevant systems, account types, configuration evidence, test results, owner, and unresolved exceptions. Add a date so a reviewer can distinguish current evidence from a historical setup record.
Now suppose the reviewer finds that the remote workspace uses MFA, but an administrative support path has not been examined. The useful next action is a test of that path, assigned to its owner. Recalculating a dashboard percentage does not resolve the missing evidence.
In Deep Fathom’s view, the record earns its place by exposing that specific uncertainty. Retain the tested paths and the unanswered one together. Certification requires its own assessment process.
Does NIST SP 800-171 require FIPS-validated cryptography?
Revision 2 requirement 3.13.11 requires FIPS-validated cryptography when cryptography protects the confidentiality of CUI. The qualifying phrase matters. A vendor’s statement that its product “uses encryption” does not establish that the relevant cryptographic module, version, and configuration meet the requirement.
Ask for those particulars when reviewing the implementation. Keep the answer tied to the CUI protection being claimed.
A useful first deliverable
Build a short obligation-to-system record before expanding the evidence library. Name the contract clause, revision, information category, system boundary, accountable owner, and assessment method. List unresolved questions alongside the person who can answer them.
Our editorial recommendation is to resolve ambiguity in that record early. Adding evidence to an undefined boundary makes the later review harder.
For a discussion with Deep Fathom, use the contact form to describe the scope question and the outcome you need. Keep CUI and sensitive contract attachments out of the initial message.
Sources and what they support
| Source | Use on this page |
|---|---|
| NIST Revision 2 publication record | Withdrawal and superseding publication date. |
| NIST SP 800-171 Revision 2 | Revision 2 requirements and family structure. |
| DFARS 252.204-7012 | Contract definitions, safeguarding, reporting, cloud and flowdown. |
| DoW CIO CMMC program status | Dated program status and assessment baseline. |