Framework · Last verified
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-171 is NIST's framework for protecting Controlled Unclassified Information in nonfederal systems; DoD contracts bind it through DFARS clauses. The current NIST revision is Rev 3 (May 2024), but CMMC Level 2 remains defined by regulation against the withdrawn Rev 2, so which revision applies depends on the contract.
- Class
- Framework
- Owner
- National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- Last verified
What it is
NIST SP 800-171 is a NIST publication, not a certification scheme — no certificate is issued against it, and what DoD contracts require is an assessment score, not a certificate. The current revision is Rev. 3 (May 2024); NIST's record for the previous revision states "Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3".
Which revision applies is set by the contract, not by NIST's catalogue. DFARS 252.204-7012 requires that "The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017" — the clause text names no revision number and ties the publication to the "version in effect at the time the solicitation is issued or as authorized by the Contracting Officer".
A regulation-level nuance follows: 32 CFR 170.14 states verbatim that "The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2." CMMC Level 2 is therefore defined against a revision NIST itself has withdrawn — a sentence like "the most recent revision applies" would be wrong for this record.
Who owns it
The publication is issued by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce. The demand mechanism is owned separately: the DFARS clauses that bind it sit in the Defense Federal Acquisition Regulation Supplement.
Who assesses it
The DFARS mechanism starts with the contractor's own assessment, whose score is posted to the Supplier Performance Risk System (SPRS). SPRS states: "The NIST SP 800-171 Basic Assessment cannot be performed in SPRS, SPRS only stores the results of NIST SP 800-171 Assessments", and "A 'SPRS Cyber Vendor User' role is required for companies to enter/edit basic self-assessment information." Under DFARS 252.204-7020(c), the contractor must also "provide access to its facilities, systems, and personnel necessary for the Government to conduct a Medium or High NIST SP 800–171 DoD Assessment". At the top of the neighbouring CMMC programme, 32 CFR 170.18 states that "DCMA DIBCAC will perform a Level 3 certification assessment in accordance with NIST SP 800-171A Jun2018".
Who asks for it
Public procurement. Contractual in one defined scope: DoD contracts and subcontracts carrying DFARS clauses 252.204-7012, 252.204-7019 and 252.204-7020. Outside DoD contracting this record documents no verified demand driver.
DoD contracting is the verified demand side. Under DFARS 252.204-7019(c)(1), an offeror must verify that "summary level scores of a current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) are posted in the Supplier Performance Risk System (SPRS)"; the clause's own example describes the score format as "95 out of 110, NOT the individual value for each requirement." DFARS 252.204-7020(g) flows the requirement down to subcontracts, requiring at least a Basic Assessment within the last three years. Outside contracts carrying these clauses, no obligation was identified in the sources reviewed as of 31 August 2026 — confirm against the specific solicitation.
Sources
- NIST CSRC — SP 800-171 Rev. 3 publication record ↗ — accessed
- NIST CSRC — SP 800-171 Rev. 2 publication record (withdrawal notice) ↗ — accessed
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting (MAY 2024) ↗ — accessed
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements (NOV 2023) ↗ — accessed
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements (NOV 2023) ↗ — accessed
- SPRS — NIST SP 800-171 assessment page (DISA) ↗ — accessed
- 32 CFR 170.14 — CMMC level and assessment requirements (govinfo) ↗ — accessed
- 32 CFR 170.18 — CMMC Level 3 certification assessment (govinfo) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.