What Is NIST SP 800-171?
NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," is the security standard published by the National Institute of Standards and Technology that defines how non-government organizations must protect CUI when it's stored, processed, or transmitted in their systems.
Revision 2 is the current operative version for CMMC Level 2. It contains 110 security requirements organized into 14 security domains (called "families" in NIST terminology). Every single one of these requirements must be addressed for a complete CMMC Level 2 assessment.
The 14 Security Domains
Each domain covers a distinct area of security practice. The requirement counts vary significantly — Access Control has 22 requirements while Personnel Security has only 2. SPRS point weights also vary by requirement criticality within each domain.
| Code | Domain | Requirements | Notes |
|---|---|---|---|
| AC | Access Control | 22 | Largest domain. Covers user access, least privilege, remote access, and CUI flow control. |
| AT | Awareness & Training | 3 | Security awareness training for all personnel handling CUI. |
| AU | Audit & Accountability | 9 | Audit logging, log protection, review, and reporting. |
| CM | Configuration Management | 9 | Baseline configs, change control, least functionality, software whitelisting. |
| IA | Identification & Authentication | 11 | User ID management, MFA, password policies, authenticator management. |
| IR | Incident Response | 3 | Incident capability, reporting to DoD, incident testing. |
| MA | Maintenance | 6 | Controlled maintenance, sanitization, removal of equipment. |
| MP | Media Protection | 9 | CUI media access, transport, sanitization, and disposal. |
| PS | Personnel Security | 2 | Screening and termination/transfer procedures. |
| PE | Physical Protection | 6 | Physical access to CUI systems and locations. |
| RA | Risk Assessment | 5 | Risk assessments, vulnerability scanning, risk remediation. |
| CA | Security Assessment | 4 | System assessments, POA&M, monitoring, and system connections. |
| SC | System & Comms Protection | 16 | Network segmentation, CUI in transit, boundary protection, remote sessions. |
| SI | System & Info Integrity | 7 | Malware protection, security alerts, patching, network monitoring. |
The Requirement Numbering System
Each requirement is identified by a three-part number. Understanding the structure helps you navigate requirements quickly:
Within the NIST numbering, the first digit (3) indicates it's from NIST 800-171 Section 3 (the requirements section). The second digit identifies the family/domain. The third digit is the sequential requirement within that family.
800-171 vs. 800-53 — What's the Relationship?
NIST SP 800-53 is the full federal security controls catalog — it contains hundreds of controls across dozens of families, designed for federal information systems. NIST SP 800-171 is a derived subset of 800-53, tailored specifically for non-federal organizations handling CUI.
If you're familiar with 800-53, you'll recognize the structure and many of the control families in 800-171. The key difference is scope: 800-171 is a much more manageable set of 110 requirements designed for organizations that aren't federal agencies but need to protect federal data.