home / frameworks / nist-800-171

// U.S. frameworks that reach Canada

NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

NIST SP 800-171 sets security requirements for protecting U.S. Controlled Unclassified Information held by contractors and other nonfederal organizations. Rev. 3 has 97 requirements in 17 families, while U.S. defence contracts and CMMC still use the 110 requirements of Rev. 2.

United States

Overview

SP 800-171 tells nonfederal organizations how to protect the confidentiality of CUI, which is sensitive but unclassified U.S. government information listed in the National Archives CUI Registry. They come from SP 800-53. They're written to go into contracts, so a company handling CUI agrees to meet them on the systems and components where that information lives.

NIST published Rev. 3 in May 2024 and marked Rev. 2 as withdrawn on May 14, 2024. Rev. 3 reorganized the requirements to line up with SP 800-53 Rev. 5, grew from 14 to 17 families by adding planning, system and services acquisition, and supply chain risk management, and introduced organization-defined parameters. These let the agency or organization set values such as how often to review logs. Some Rev. 2 requirements were merged or withdrawn, leaving 97 active requirements. SP 800-171A Rev. 3 provides the matching assessment procedures.

There's a split between versions in practice. The U.S. Department of Defense still requires Rev. 2 through DFARS 252.204-7012, and the CMMC program rule (32 CFR part 170) incorporates the 110 requirements of Rev. 2 by reference for Level 2. Defence contractors therefore assess against Rev. 2 today, even though Rev. 3 is NIST's current text. Canada took a different path. The Cyber Centre's ITSP.10.171, first released in April 2025 with a second release in October 2025, adapts Rev. 3 for Canadian use and replaces CUI with the term specified information. It is the control source for the CPCSC.

Who it applies to in Canada

Contractors, subcontractors, universities, and other nonfederal organizations that store, process, or transmit U.S. Controlled Unclassified Information (CUI) under a federal contract or agreement.

Canadian firms meet SP 800-171 when they handle CUI as suppliers or subcontractors to U.S. defence and federal programs, because the contract clauses flow down to them regardless of country. Canada has also adapted Rev. 3 as the Cyber Centre's ITSP.10.171, which underpins the Canadian Program for Cyber Security Certification (CPCSC) for defence suppliers.

Controls at a glance

Rev. 3 organizes 97 requirements into 17 families that mirror SP 800-53 family names.

Access control and identification (AC, IA)

  • Limit system access to authorized users and devices
  • Apply least privilege and separation of duties
  • Control remote access and external connections
  • Identify and authenticate users, devices, and services
  • Use multi-factor authentication for system access

Awareness, personnel, and physical (AT, PS, PE)

  • Train users on security risks and their roles
  • Screen staff before granting CUI access
  • Remove access promptly on termination or transfer
  • Limit and log physical access to facilities

Audit and monitoring (AU, CA)

  • Log events and protect audit records
  • Review and analyze logs for unusual activity
  • Assess requirements and track plans of action
  • Maintain a system security plan and monitor controls

Configuration, maintenance, and media (CM, MA, MP)

  • Set and enforce secure baseline configurations
  • Control changes and restrict unneeded functions
  • Control maintenance tools and remote maintenance
  • Protect, mark, and sanitize media holding CUI

Incident response and risk (IR, RA)

  • Plan, handle, and report security incidents
  • Test incident response capability
  • Assess risk and scan for vulnerabilities
  • Remediate vulnerabilities based on risk

System and communications protection (SC, SI)

  • Monitor and control traffic at system boundaries
  • Encrypt CUI in transit and at rest
  • Fix flaws and protect against malicious code
  • Monitor systems for attacks and unauthorized use

Planning, acquisition, and supply chain (PL, SA, SR)

  • Set rules of behaviour and security policies
  • Apply security engineering principles to systems
  • Manage unsupported system components
  • Plan for supply chain risk and assess suppliers

These 3 families are new in Rev. 3.

Certification and assessment

Organizations document a system security plan, assess themselves using SP 800-171A, and record gaps in a plan of action. Defence contractors post a score in the Supplier Performance Risk System (SPRS) and, under CMMC, an annual affirmation. Third-party assessment comes through CMMC rather than SP 800-171 itself.

Dates to know

2021-01-28
Last update to SP 800-171 Rev. 2, the version still used in DFARS and CMMC
2024-05-14
SP 800-171 Rev. 3 published and NIST marks Rev. 2 as withdrawn
2024-12-16
CMMC program rule takes effect, incorporating SP 800-171 Rev. 2 by reference
2025-10
Second release of the Cyber Centre's ITSP.10.171, the Canadian adaptation of Rev. 3

Resources

Official texts and free tools for NIST 800-171. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. NIST SP 800-171 Rev. 3 (PDF), NIST
  2. 32 CFR part 170, CMMC Program, Electronic Code of Federal Regulations
  3. ITSP.10.171, Canadian Centre for Cyber Security