NIST SP 800-171 Compliance

Implementation, documentation, and remediation support for all 110 controls — the backbone of CMMC Level 2 and DFARS 252.204-7012.

Why NIST SP 800-171 Matters

NIST Special Publication 800-171 defines the 110 security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. If your contracts include DFARS clause 252.204-7012, you are already contractually obligated to implement it — independent of CMMC. That obligation survived the July 2026 suspension of CMMC Phase 2 untouched: while the program is under review, DoD is enforcing 800-171 through self-assessments and select government-led assessments.

That makes 800-171 the center of gravity for defense-contractor cybersecurity — now more than ever. Implement it well and any future CMMC verification becomes a validation exercise. Implement it on paper only, and you carry both assessment risk and False Claims Act exposure.

The 14 Control Families

The requirements span fourteen families: Access Control, Awareness & Training, Audit & Accountability, Configuration Management, Identification & Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System & Communications Protection, and System & Information Integrity. You can explore the controls — and track your own implementation status — with our NIST 800-171 self-assessment tracker; Level 1 is free in your browser, and the licensed desktop app covers all 110 Level 2 controls.

How GetCMMC Helps

Not sure which controls you're missing? Start with a gap analysis. Already remediated? Validate with a mock assessment.

Frequently Asked Questions

Is NIST 800-171 the same as CMMC Level 2?

CMMC Level 2 adopts the 110 NIST SP 800-171 requirements wholesale. The difference is verification: 800-171 compliance has historically been self-attested, and CMMC Level 2 was set to add third-party assessment for most CUI contracts. That Phase 2 requirement was suspended in July 2026 — in the interim, DoD verifies compliance through self-assessments and select government-led assessments.

Do we need NIST 800-171 if we only handle FCI, not CUI?

If you only handle Federal Contract Information, CMMC Level 1's 17 basic safeguarding practices apply instead. But many contractors underestimate where CUI actually exists in their environment — a scoping review settles the question definitively.

What is Revision 3, and which version applies to us?

NIST published SP 800-171 Revision 3, but DoD has specified Revision 2 as the basis for current CMMC assessments and DFARS compliance. We build programs against Rev 2 requirements while keeping an eye on the transition path so your investment carries forward.

CMMC Phase 2 Is Suspended.
Your Security Obligations Are Not.

Jul 13, 2026

DoD suspended the CMMC Phase 2 requirements — originally set to take effect November 10, 2026 — along with pending implementation milestones, while a task force reviews the program.

Still in force

Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 — now enforced through self-assessments and select government-led assessments. An inflated SPRS score still carries False Claims Act exposure.

60 days

The CMMC Reform Task Force reports on the program's future within 60 days. Requirements can return — reshaped — on short notice; contractors who keep implementing won't be starting over.

The certification pause is not a security pause: your contracts still require NIST 800-171, and the government is still checking. Read the plain-English breakdown of the suspension.

Start Closing Your 800-171 Gaps

Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant. Every inquiry starts with a free 30-minute consultation — no obligation.

Senior-led, capacity-limited. Every engagement is led personally by a Lead Certified CMMC Assessor (LCCA) — never handed off to junior staff. To protect that standard, I take on a limited number of clients at a time. Most inquiries get a reply within 1–2 business days.
Book Your Free 30-Minute Consultation

Pick a time that works for you — no back-and-forth email.

Your information is kept confidential and never shared. See our privacy policy.

Message sent!

Thanks for reaching out. Neal will be in touch within 1–2 business days.