Quick answer
NIST SP 800-171 is the federal cybersecurity standard defining 110 security controls that contractors must implement to protect Controlled Unclassified Information in non-federal systems.
NIST Special Publication 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) is the cybersecurity standard published by the National Institute of Standards and Technology that defines 110 security requirements defense contractors must implement to protect Controlled Unclassified Information (CUI).
What is NIST SP 800-171?
NIST SP 800-171 was first published in 2015 and is enforced through DFARS clause 252.204-7012, which applies to all DoD contracts that involve Controlled Unclassified Information. The standard organizes 110 security requirements into 14 control families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
The controls range from foundational practices (requiring multi-factor authentication for privileged accounts, maintaining audit logs, encrypting CUI at rest and in transit) to more sophisticated capabilities (real-time log monitoring with automated alerting, software supply chain risk management, and penetration testing). Contractors document their implementation through a System Security Plan (SSP) and track any deficiencies through a Plan of Action and Milestones (POA&M).
Prior to CMMC, contractors self-assessed against NIST SP 800-171 and submitted a self-assessment score to the Supplier Performance Risk System (SPRS) on a scale of -203 to +110. CMMC 2.0 Level 2 is built directly on NIST SP 800-171, adding third-party verification for prioritized programs. NIST SP 800-172 - referenced by CMMC Level 3 - adds advanced requirements beyond the 110 controls for the most sensitive defense programs.
Why NIST SP 800-171 matters for government contractors
NIST SP 800-171 compliance is legally required for any contractor whose systems process, store, or transmit CUI under a DoD contract. Failure to implement the required controls, or misrepresenting implementation status in a self-assessment score, can constitute a False Claims Act violation - a risk that has resulted in significant enforcement actions and settlements. Beyond legal compliance, the controls represent sound cybersecurity practice that reduces the contractor's risk of data breach, ransomware, and the associated operational and reputational damage that follows.
Example
A mid-size engineering firm wins a DoD contract to provide technical analysis support involving export-controlled technical data classified as CUI. The firm's IT security team conducts a gap assessment against the 110 NIST SP 800-171 controls and identifies a score of 87 out of 110. The 23 deficiencies are documented in a POA&M with remediation timelines. The firm uploads the assessment score to SPRS and begins implementing the deficient controls, prioritizing high-impact gaps in multi-factor authentication, log management, and incident response. Over nine months, the firm remediates all deficiencies and achieves a score of 110, submitted to SPRS. The firm's documentation package is later reviewed without findings during a DCAA audit.
Frequently Asked Questions
What is the difference between NIST SP 800-171 and NIST SP 800-53?
NIST SP 800-53 is the comprehensive security control catalog for federal information systems - it is the standard that federal agencies themselves must comply with. NIST SP 800-171 is a tailored subset of 800-53 adapted for nonfederal systems (contractor systems) that handle CUI. It is less comprehensive than 800-53 but still substantive, with 110 requirements across 14 families. Think of 800-53 as the full federal standard and 800-171 as the contractor-facing companion.
Do I need to comply with NIST SP 800-171 if I only have civilian agency contracts?
NIST SP 800-171 is specifically required by DFARS 252.204-7012 for DoD contracts. Civilian agency contracts may reference it in solicitations or contract clauses, but the mandatory requirement flows from DoD contracts. Civilian agencies have their own CUI protection requirements that may align with NIST SP 800-171 or may reference other standards. Check the specific contract clauses in each civilian agency award.
What is an SPRS score and how is it calculated?
SPRS (Supplier Performance Risk System) is a DoD database where contractors submit their NIST SP 800-171 self-assessment scores. The scoring scale runs from -203 to +110. The maximum score of +110 represents full implementation of all 110 controls, with each control assigned a point value based on its importance. Each unimplemented control results in a deduction from 110 according to DoD's scoring methodology. Contracting officers can view SPRS scores for contractors when evaluating proposals.
Is a System Security Plan required for NIST SP 800-171?
Yes. DFARS 252.204-7012 requires contractors to develop, document, and implement a System Security Plan that describes the system boundary, operating environment, how the security requirements are implemented, and the relationships with other systems. The SSP is a required document that defines the scope of your NIST SP 800-171 implementation and is reviewed during CMMC assessments and DCAA audits.
How Bidovate helps
Bidovate puts NIST SP 800-171 to work inside your capture and proposal workflow.
Federal contractingSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
Cybersecurity Maturity Model Certification (CMMC)
CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.
ViewControlled Unclassified Information (CUI)
Controlled Unclassified Information is government-designated sensitive information that is not classified but requires safeguarding controls and access restrictions by contractors.
ViewFedRAMP (Federal Risk and Authorization Management Program)
FedRAMP is the federal government's standardized security authorization program for cloud services, enabling agencies to use cloud products that have been pre-approved for federal use.
ViewSecurity Clearance in Government Contracting
A security clearance is a government-granted authorization allowing individuals or organizations to access classified national security information at specified sensitivity levels.
View