Overview
SP 800-171 tells nonfederal organizations how to protect the confidentiality of CUI, which is sensitive but unclassified U.S. government information listed in the National Archives CUI Registry. They come from SP 800-53. They're written to go into contracts, so a company handling CUI agrees to meet them on the systems and components where that information lives.
NIST published Rev. 3 in May 2024 and marked Rev. 2 as withdrawn on May 14, 2024. Rev. 3 reorganized the requirements to line up with SP 800-53 Rev. 5, grew from 14 to 17 families by adding planning, system and services acquisition, and supply chain risk management, and introduced organization-defined parameters. These let the agency or organization set values such as how often to review logs. Some Rev. 2 requirements were merged or withdrawn, leaving 97 active requirements. SP 800-171A Rev. 3 provides the matching assessment procedures.
There's a split between versions in practice. The U.S. Department of Defense still requires Rev. 2 through DFARS 252.204-7012, and the CMMC program rule (32 CFR part 170) incorporates the 110 requirements of Rev. 2 by reference for Level 2. Defence contractors therefore assess against Rev. 2 today, even though Rev. 3 is NIST's current text. Canada took a different path. The Cyber Centre's ITSP.10.171, first released in April 2025 with a second release in October 2025, adapts Rev. 3 for Canadian use and replaces CUI with the term specified information. It is the control source for the CPCSC.
Who it applies to in Canada
Contractors, subcontractors, universities, and other nonfederal organizations that store, process, or transmit U.S. Controlled Unclassified Information (CUI) under a federal contract or agreement.
Canadian firms meet SP 800-171 when they handle CUI as suppliers or subcontractors to U.S. defence and federal programs, because the contract clauses flow down to them regardless of country. Canada has also adapted Rev. 3 as the Cyber Centre's ITSP.10.171, which underpins the Canadian Program for Cyber Security Certification (CPCSC) for defence suppliers.
Controls at a glance
Rev. 3 organizes 97 requirements into 17 families that mirror SP 800-53 family names.
Access control and identification (AC, IA)
- Limit system access to authorized users and devices
- Apply least privilege and separation of duties
- Control remote access and external connections
- Identify and authenticate users, devices, and services
- Use multi-factor authentication for system access
Awareness, personnel, and physical (AT, PS, PE)
- Train users on security risks and their roles
- Screen staff before granting CUI access
- Remove access promptly on termination or transfer
- Limit and log physical access to facilities
Audit and monitoring (AU, CA)
- Log events and protect audit records
- Review and analyze logs for unusual activity
- Assess requirements and track plans of action
- Maintain a system security plan and monitor controls
Configuration, maintenance, and media (CM, MA, MP)
- Set and enforce secure baseline configurations
- Control changes and restrict unneeded functions
- Control maintenance tools and remote maintenance
- Protect, mark, and sanitize media holding CUI
Incident response and risk (IR, RA)
- Plan, handle, and report security incidents
- Test incident response capability
- Assess risk and scan for vulnerabilities
- Remediate vulnerabilities based on risk
System and communications protection (SC, SI)
- Monitor and control traffic at system boundaries
- Encrypt CUI in transit and at rest
- Fix flaws and protect against malicious code
- Monitor systems for attacks and unauthorized use
Planning, acquisition, and supply chain (PL, SA, SR)
- Set rules of behaviour and security policies
- Apply security engineering principles to systems
- Manage unsupported system components
- Plan for supply chain risk and assess suppliers
These 3 families are new in Rev. 3.
Certification and assessment
Organizations document a system security plan, assess themselves using SP 800-171A, and record gaps in a plan of action. Defence contractors post a score in the Supplier Performance Risk System (SPRS) and, under CMMC, an annual affirmation. Third-party assessment comes through CMMC rather than SP 800-171 itself.
Dates to know
- 2021-01-28
- Last update to SP 800-171 Rev. 2, the version still used in DFARS and CMMC
- 2024-05-14
- SP 800-171 Rev. 3 published and NIST marks Rev. 2 as withdrawn
- 2024-12-16
- CMMC program rule takes effect, incorporating SP 800-171 Rev. 2 by reference
- 2025-10
- Second release of the Cyber Centre's ITSP.10.171, the Canadian adaptation of Rev. 3
Resources
Official texts and free tools for NIST 800-171. Links open the publisher’s site.
- SP 800-171 Rev. 3 publication page, NIST
- SP 800-171A Rev. 3, Assessing Security Requirements for CUI, NIST
- SP 800-171 Rev. 2 publication page, NIST
- Controlled Unclassified Information (CUI) program and registry, U.S. National Archivesguidance
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171), Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- NIST SP 800-171 Rev. 3 (PDF), NIST
- 32 CFR part 170, CMMC Program, Electronic Code of Federal Regulations
- ITSP.10.171, Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.