NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, sets the security requirements a contractor must meet when government information that is sensitive but not classified lives on the contractor's own systems. For defense contractors it is not optional guidance: DFARS clauses make it a contractual obligation, and it is the requirement set that CMMC Level 2 assesses.
Start with CUI, not with controls
Controlled Unclassified Information is information the government creates or possesses, or that a contractor creates for the government, that law, regulation, or government-wide policy requires to be safeguarded. The CUI program is governed by 32 CFR Part 2002, and the National Archives maintains the CUI Registry of categories. Typical examples for defense suppliers include controlled technical information, export-controlled data, and certain contract and logistics information.
Every 800-171 effort should begin by finding where CUI enters, is stored, is processed, and leaves your environment. The answer determines your assessment scope. Organizations that skip this step usually end up applying all 110 requirements to the whole company, when an enclave or a tightly scoped set of systems would have been cheaper and easier to defend.
Rev 2 and Rev 3: which one applies
NIST published Revision 3 in May 2024. It restructures the requirements to align more closely with SP 800-53 Rev 5, reorganizes them into 17 families, and introduces organization-defined parameters. However, the Department of Defense has continued to hold contractors to Revision 2 for DFARS 252.204-7012 purposes, and the CMMC program rule in 32 CFR part 170 references Rev 2 for Level 2. That is why this page, and most DoD-facing programs today, work from the Rev 2 structure of 110 requirements in 14 families.
The 14 families in NIST SP 800-171 Rev 2
DFARS 7012 and your SPRS score
DFARS 252.204-7012 requires contractors to provide adequate security for covered defense information by implementing 800-171, report cyber incidents to DoD within 72 hours of discovery, and ensure any cloud provider storing covered defense information meets security requirements equivalent to the FedRAMP Moderate baseline. The clause also flows down to subcontractors who handle that information.
DFARS 252.204-7019 and 252.204-7020 add the DoD Assessment Methodology. Contractors post a Basic Assessment score to the Supplier Performance Risk System (SPRS). Scoring starts at 110, and each requirement not implemented subtracts a weighted value of 1, 3, or 5 points, so a score can be negative. Contracting officers can see that score, which makes an honest self-assessment a business matter, not just a compliance one.
- Score only what is actually implemented today. Planned work belongs in the POA&M, not in the score.
- Keep the worksheet behind the number. If DoD performs a Medium or High assessment, you will need to show how you reached it.
- Record the SSP version and date the score is based on, and rescore when the SSP changes materially.
The SSP and POA&M are requirements themselves
Two documents sit at the center of every 800-171 program, and both are required by the standard itself. Requirement 3.12.4 calls for a System Security Plan describing the system boundary, environment, how each requirement is implemented, and connections to other systems. Requirement 3.12.2 calls for plans of action to correct deficiencies and reduce or eliminate vulnerabilities. DoD's assessment methodology states that an assessment cannot be completed without an SSP, so it is the first artefact to produce.
What a defensible SSP contains
- A system description and diagram showing where CUI flows and the boundary around it
- An inventory of in-scope assets, including security protection assets and external service providers
- For every requirement, an implementation statement naming the responsible role, the mechanism, and the frequency
- Clear identification of requirements met by an inherited or shared service, with the provider's responsibility documented
- Cross-references to the policies, procedures, and records that prove each statement
- A version history and approval by an accountable executive
A roadmap for contractors
- Identify CUI and contracts. Confirm which contracts include DFARS 252.204-7012 and what CUI you actually receive or generate.
- Decide scope. Choose between protecting the whole environment and building an enclave. Include people, facilities, and cloud services, not only servers.
- Run a gap assessment. Use the SP 800-171A assessment objectives; many requirements have several objectives, and all must be met.
- Write the SSP and score yourself. Post a Basic Assessment score to SPRS and open POA&M items for gaps.
- Remediate high-weight gaps first. Multifactor authentication, encryption of CUI, and audit logging carry heavier weights and are also what assessors probe hardest.
- Operate and evidence. Run access reviews, log review, vulnerability scanning, and training on a set cadence and keep the records.
- Prepare for CMMC. If your contracts will require a Level 2 certification assessment, treat your internal assessment as a dress rehearsal.
Common mistakes
- Mixing scope and inventory. Assets that store or process CUI, assets that protect them, and assets that merely connect are treated differently. An unclear inventory makes every other answer disputable.
- Using a commercial cloud tier for CUI. Check whether the service meets the FedRAMP Moderate equivalency expectation before you move CUI into it.
- Encryption that is not FIPS-validated. Requirement 3.13.11 calls for FIPS-validated cryptography when used to protect CUI confidentiality.
- Policies without records. A policy says what should happen; assessors ask for evidence it did.
- Inflated SPRS scores. A generous self-score can create contractual exposure if it is not supported.
Overlap with other frameworks and how Asurvo helps
800-171 was derived from the moderate baseline of NIST SP 800-53, so each requirement traces back to one or more 800-53 controls. It also overlaps heavily with ISO 27001 in areas such as access control, incident response, and configuration management, and CMMC Level 2 uses the same 110 requirements. Asurvo's AI cross-mapping links these frameworks so a single control and its evidence satisfy each of them. The platform supports SSP and POA&M work, and the risk register tracks treatment of gaps with owners and deadlines. Teams working through their first gap assessment can also use the free audit evidence tracker.