NIST SP 800-171 has a problem that catches defense contractors every year: the current NIST revision is not the revision you are assessed against.
NIST published Revision 3 in May 2024 and records it as superseding Revision 2. CMMC still runs on Revision 2, because that is what the regulation incorporates by reference. Both statements are true at the same time, and acting on the first one alone is an expensive mistake.
What NIST SP 800-171 is for
SP 800-171 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations — sets recommended security requirements for protecting the confidentiality of CUI when it sits outside federal systems.
Three points in that framing do real work:
- It is about confidentiality. Not availability, not integrity in the general sense. The requirements are shaped by the question of who can read the information.
- It applies to components that process, store or transmit CUI, or that provide protection for such components. That second clause is the one that quietly expands scope — your identity provider and your logging platform are in even if no CUI passes through them.
- It becomes binding through contracts, not by itself. NIST writes it for federal agencies to use in contractual vehicles and agreements. On its own it is a recommendation.
Its companion, SP 800-171A, provides the assessment procedures — the document an assessor actually works from.
The NIST SP 800-171 revision trap

Here is the NIST SP 800-171 position as it actually stands.
At NIST: Revision 3 was published in May 2024 and supersedes Revision 2, which dated from 28 January 2021. An HTML version of Rev 3 has been available since June 2024.
In the regulation: 32 CFR 170.14, the section defining the CMMC Model, incorporates NIST SP 800-171 R2 by reference. It also incorporates NIST SP 800-171A Jun2018 — that specific June 2018 edition — and references NIST SP 800-172 Feb2021 for Level 3.
Incorporation by reference is the mechanism that matters. Once a regulation names a specific revision, that revision stays binding until the regulation itself is amended. NIST publishing something newer does not change the rule.
So if you are pursuing CMMC, build against Rev 2. A contractor who re-baselines a System Security Plan against Rev 3 will arrive at a C3PAO assessment describing the wrong control set, having done a great deal of unnecessary work.
This is not hypothetical timing. CMMC Phase 2 begins on 10 November 2026, at which point Level 2 third-party certification becomes a condition of contract award — under a rule that points at Rev 2.
What NIST SP 800-171 Revision 2 asks for
Rev 2 contains 110 security requirements across fourteen families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Around those sit the artefacts an assessor reads:
- A defined CUI boundary — which systems and components are in scope, decided and recorded rather than assumed.
- A System Security Plan describing how each requirement is met for that boundary.
- A Plan of Action and Milestones for anything not yet met.
- An SPRS score, submitted and current.
- Evidence that the controls operate — dated records, not policies asserting that they should.
The last item is where most first assessments fail. A policy saying access is reviewed quarterly proves nothing; four dated review records prove it.
Where Revision 3 still matters
NIST SP 800-171 Rev 3 is not irrelevant just because CMMC has not adopted it.
Non-DoD federal agencies write their own contract clauses, and some will reference the current revision directly. If your CUI obligations come from a civilian agency rather than through DFARS, check which revision the contract names — it may well be Rev 3.
And Rev 3 is the direction of travel. An organisation building its programme now can sensibly implement to Rev 2 for assessment while noting where Rev 3 diverges, so the eventual transition is a documentation exercise rather than a rebuild.
The rule to work by: implement what your contract names, and read the contract rather than the news.
How NIST SP 800-171 relates to other frameworks
| Framework | Relationship |
|---|---|
| CMMC | The verification regime built on top. CMMC does not invent requirements — Level 2 assesses this control set, at the revision the regulation names |
| FedRAMP | Built on SP 800-53 rather than 800-171, and aimed at cloud services. A FedRAMP-authorised cloud helps where your CUI sits in it, but does not cover your own boundary |
| ISO 27001 | Maps substantially onto the fourteen families and gives you the management system to keep them running. It is not a CMMC status and does not shorten an assessment |
| NIST CSF | Outcome-based where 800-171 is requirement-based. Useful for board reporting, not for an assessor |
Where to start with NIST SP 800-171
- Find out which revision your contract names. Everything else follows from that one answer.
- Define the CUI boundary and record the reasoning, including components that protect in-scope components.
- Gap-assess against all 110 requirements honestly, separating met-in-policy from met-in-practice.
- Use SP 800-171A — the edition the rule names — because it is what the assessor uses.
- Start the evidence trail now. Dated records cannot be produced retrospectively.
- Track Rev 3 without implementing it, unless a contract names it.
This guide reflects csrc.nist.gov and 32 CFR 170.14 as published at 15 August 2026. Incorporation by reference can change when a rule is amended — check the regulation before a contractual commitment.
The NIST SP 800-171 CUI Protection Toolkit provides editable templates covering the System Security Plan, the boundary definition, the control implementation records and the POA&M. If the assessment regime is also in scope, the CMMC Toolkit covers it.