NIST 800-171 vs 800-53 is a comparison between a catalog and a derivative of it. SP 800-53 is the full control catalog for federal information systems — twenty families, more than a thousand controls and enhancements, with low, moderate and high baselines published separately in SP 800-53B. SP 800-171 is what you get when the moderate baseline is tailored for one purpose only: protecting the confidentiality of Controlled Unclassified Information on systems the federal government does not own.
Revision 3 of 800-171 makes the derivation explicit — its Appendix C walks every moderate-baseline control through five tailoring criteria and shows which of them became the 97 requirements. This guide sets out the difference on purpose, scope, size, structure and who must comply; shows the tailoring arithmetic from NIST’s own tables; explains what 800-53 covers that 800-171 does not; and answers the question most contractors are really asking, which is whether an 800-53 program satisfies 800-171 and vice versa.

NIST 800-171 vs 800-53 at a glance
| NIST SP 800-53 Rev 5 | NIST SP 800-171 (Rev 3 / Rev 2) | |
|---|---|---|
| Purpose | Security and privacy controls for federal information systems and organizations | Security requirements for protecting the confidentiality of CUI in nonfederal systems |
| Who must use it | Federal agencies under FISMA and OMB A-130; cloud providers under FedRAMP; anyone a contract binds to it | Nonfederal organizations that process, store or transmit CUI under a contract or agreement — DoD contractors under DFARS 252.204-7012 and CMMC |
| Security objectives | Confidentiality, integrity, availability — and privacy | Confidentiality only |
| Size | 20 families; more than 1,000 controls and enhancements in the catalog; the moderate baseline selects 287 | 17 families, 97 requirements (Rev 3); 14 families, 110 requirements (Rev 2) |
| Baselines | Low, moderate, high and privacy, in SP 800-53B; tailored per system | One set, applicable to every CUI system; tailoring is done by NIST, not the organization |
| Parameters | Organization-defined parameters throughout | 88 ODPs in 50 requirements (Rev 3); none in Rev 2 |
| Assessment companion | SP 800-53A | SP 800-171A |
| Certification or authorization | Authorization to operate (ATO) by the agency; FedRAMP authorization for cloud | Self-assessment and SPRS score; CMMC certification for DoD (Level 2 third-party path suspended since July 2026) |
NIST 800-171 vs 800-53: the tailoring arithmetic
SP 800-171 Rev 3, Appendix C, lists every control and enhancement in the SP 800-53B moderate baseline and assigns it one of five tailoring criteria. Counting NIST’s own tables gives the derivation in numbers.
| Tailoring criterion | Meaning | Controls and enhancements |
|---|---|---|
| CUI | Directly related to protecting the confidentiality of CUI — carried into 800-171 as, or within, a requirement | 156 |
| NCO | Not directly related to confidentiality of CUI (integrity- or availability-focused, for example) | 98 |
| FED | Primarily the responsibility of the federal government | 22 |
| ORC | Outcome adequately covered by another related control | 11 |
| N/A | Not applicable — the Program Management and PII Processing families, which sit in no baseline | 58 |
The 287 moderate-baseline items (the rows other than N/A) reduce to 156 that matter to CUI confidentiality, and those 156 are expressed as 97 requirements because a single requirement often carries a control and its enhancements together. Revision 2 did the same derivation from SP 800-53 Rev 4 with an extra criterion, NFO — controls “expected to be routinely satisfied by nonfederal organizations without specification” — which Revision 3 eliminated after NIST found that NFO controls such as the family policy controls were simply not being implemented. That is why Planning is now a family of its own. Our guide to NIST 800-171 Rev 3 vs Rev 2 covers the change in full.
What 800-53 has that 800-171 does not
- Integrity and availability. Contingency Planning (CP) is absent from 800-171 entirely: backups, alternate sites and recovery are NCO. So are most of the availability-oriented enhancements in System and Communications Protection.
- Privacy. The PT family and the privacy baseline have no counterpart; 800-171 is about confidentiality of government information, not about personal data rights.
- Program-level controls. Program Management (PM) is N/A; the enterprise-level governance an agency’s CISO runs is assumed, not required.
- Federal responsibilities. The 22 FED items — authorization, interconnection agreements, certain assessments — belong to the agency that owns the risk.
- Tailoring freedom. An agency tailors its own baseline per system under SP 800-53B; a contractor implementing 800-171 does not get to drop a requirement because its system is low-impact. The tailoring has been done once, for everyone.
What 800-171 adds that a plain 800-53 baseline does not
Nothing new in substance — on the NIST 800-171 vs 800-53 ledger every 800-171 requirement traces to an 800-53 control, and Rev 3 cites the source in each requirement’s references section. What 800-171 adds is specificity and scope discipline: it applies to “components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components”, which makes system boundary and CUI flow the first task rather than an afterthought. It also adds an assessment regime with consequences: the DoD Assessment Methodology’s score in SPRS, and CMMC’s MET/NOT MET determinations at objective level. Our guide to NIST 800-171A covers the objectives.
NIST 800-171 vs 800-53 in practice: does one satisfy the other?
| Situation | Answer | Caveat |
|---|---|---|
| You run a moderate-baseline 800-53 program and a customer asks for 800-171 | Substantially yes | Map each 800-171 requirement to its 800-53 sources and produce the SSP in 800-171 terms; check the ODP values (Rev 3) and the CUI boundary. FedRAMP Moderate-authorized cloud services are commonly accepted as meeting the requirements for the CUI they host — the DFARS clause says ‘equivalent’ to FedRAMP Moderate |
| You have implemented 800-171 and an agency asks for 800-53 moderate | No | 800-171 omits contingency planning, integrity and availability controls, privacy, and the federal-responsibility controls; a 287-item baseline is roughly twice the 156 items 800-171 keeps |
| You are a DoD contractor deciding which to implement | 800-171 Rev 2 | It is what DFARS 252.204-7012 and CMMC assess; implementing 800-53 moderate instead is not wrong, but the SSP must still be written against the 110 requirements |
| You want one program that satisfies both | Build to 800-53 moderate, document to 800-171 | The 800-171 requirements are a subset; keep a crosswalk and state the CUI scope in the 800-171 SSP |
Our guides to NIST SP 800-53 and NIST 800-53 tailoring cover the catalog side; CMMC vs NIST 800-171 covers the assessment layer on the 800-171 side.
Frequently asked questions
What is the difference in NIST 800-171 vs 800-53?
800-53 is the full security and privacy control catalog for federal systems, with baselines tailored per system; 800-171 is a fixed set of confidentiality requirements for CUI on nonfederal systems, derived by NIST from the 800-53 moderate baseline — 97 requirements in Rev 3, 110 in Rev 2.
Is 800-171 a subset of 800-53?
In substance, yes: every 800-171 requirement traces to 800-53 controls, and Rev 3’s Appendix C shows 156 of the 287 moderate-baseline controls and enhancements carried through as CUI-relevant. The requirement language is more specific than the source controls.
Which one do government contractors need?
800-171 for CUI on their own systems — Rev 2 under DFARS 252.204-7012 and CMMC, the revision named in other agreements otherwise. 800-53 applies when the contractor operates a system on the agency’s behalf, or as a FedRAMP cloud provider.
Does FedRAMP Moderate satisfy 800-171?
For cloud services that store, process or transmit CUI, DFARS 252.204-7012 requires FedRAMP Moderate or equivalent, and the 800-171 requirements are drawn from the same moderate baseline. The contractor still owns the requirements for its own systems and the shared-responsibility split.
Why does 800-171 leave out backups and contingency planning?
Because it protects confidentiality only. Contingency Planning is tailored out as NCO — not directly related to confidentiality of CUI. An organization that wants resilience adds it from 800-53 or ISO 22301 on its own account.
Where this leaves you
Read NIST 800-171 vs 800-53 as tailoring, not competition: 800-53 is the catalog and the baselines, 800-171 is the moderate baseline cut to CUI confidentiality by NIST’s own criteria — 287 items to 156, expressed as 97 requirements. Implement 800-171 in the revision your contract names, document it in 800-171 terms, and reach for 800-53 when integrity, availability, privacy or a federal authorization is actually in scope.
References
- NIST SP 800-171 Rev. 3 — Appendix C, Tailoring Criteria — Tables 3–22: every moderate-baseline control and enhancement with its tailoring criterion and resulting requirement.
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations — The control catalog; SP 800-53B holds the baselines.
- NIST FAQ: SP 800-171r3 and SP 800-171Ar3 — Why the NFO criterion was eliminated and the ORC and N/A criteria added.
More on NIST SP 800-171
- NIST 800-171 vs 800-53 — you are here
- NIST SP 800-171: the complete guide
- NIST 800-171 Rev 3 vs Rev 2
- NIST 800-171A: the assessment objectives
- Controlled unclassified information explained
- NIST 800-171 compliance cost
The System Security Plan, the 800-171-to-800-53 cross-mapping matrix, the control-family policies and the CUI scoping workbook are in the NIST SP 800-171 CUI Protection Toolkit, or start with the free templates.