Whether you own or work for a company that stores unclassified or sensitive data, you are required by the US Government to comply with cybersecurity standards. These comprise the National Institute of Standards and Technology Special Publication 800-171.
Many industries need to meet these standards, from research institutions to contractors for the Department of Defense, universities that receive federal grants, and organizations offering services to government agencies. They ensure sensitive information held on federal contractors’ IT systems and networks is always safeguarded.
In this guide, we learn more about these standards and the requirements that ensue. Read on to learn more.
How to stay compliant
NIST 800-171 surrounds best-practice cybersecurity standards from government contractors. Having these in place ensures the federal supply chain is resilient and protected. This standard keeps Controlled Unclassified Information (CUI) hidden from unwanted eyes and secures sensitive government information stored on contractors’ networks.
If you’re a contractor who handles CUI on your network, by law, you must comply with NIST SP 800-171. In addition, you must conduct self-assessments. Why? To pinpoint and maintain compliance.
What is NIST SP 800-171
In a nutshell, NIST SP 800-171 is a publication surrounding the necessary security practices and standards for non-federal businesses processing CUI on their networks. It was introduced by NIST in June 2015. Who is NIST? They’re a US government agency behind various standards and publications.
They boost cybersecurity resilience in both private and public sectors. These standards are constantly updated, protecting highly sensitive data against ever-changing technologies and emerging cyber threats.
What is the Purpose of These Standards?

These standards ensure CUI is protected in the IT networks of government subcontractors and contractors. NIST highlights the procedures and practices government contractors must meet, whether their networks store or process CUI.
Pinpointing cybersecurity rules for contractors who deal with sensitive government data, NIST SP 800-171 has heightened security as a whole. The result? The federal supply chain is as strong as it can be. This ensures a cybersecurity baseline standard for contractors and subcontractors who handle CUI.
Top Tip for NIST SP 800-171 Compliance
Evidence-based assessments are crucial when determining an organization’s compliance with NIST SP 800-171. As a company, putting an up-to-date System Security Plan (SSP) in place is crucial. In addition, you need to initiate practices and policies that demonstrate compliance and provide evidence of it.
Controlled Unclassified Information (CUI) Explained

CUI or Controlled Unclassified Information is data that belongs to government bodies. Despite not being classified, it’s still sensitive. This information can include anything from technical data to patents to information relating to the acquisition or manufacture of services and goods. You can find more information on the definition of CUI via lists published by government agencies, which illustrate all relevant categories.
Despite not being classified, data breaches of sensitive data can be detrimental. When this data is in the wrong hands, it can lead to adverse economic and national security consequences. A lack of compliance can cause lawsuits, a loss of contracts, fines, and damage to reputations.
The NIST SP 800-171 Requirements Protecting CUI?
NIST SP 800-171 covers 110 requirements. Each requirement covers a different area of a company’s IT policy, technology, and practices. Factors include systems configuration, access control, and authentication procedures. In addition, they set cybersecurity procedures and incident response plan requirements.
What’s the reason for these requirements? They prevent cybersecurity risk, making your company less susceptible to risk. Each area deemed vulnerable features a ‘discussion’ text. This allows your organization to comprehend the requirements in detail. The result? Your employees can handle your organization’s network and systems efficiently. It ensures they are prepped to safely handle CUI. This comprises:
-
Access Control
-
Awareness and Training
-
Audit and Accountability
-
Configuration Management
-
Identification and Authentication
-
Incident Response
-
Maintenance
-
Media Protection
-
Personnel Security
-
Physical Protection
-
Risk Assessment
-
Security Assessment
-
System and Communications Protection and;
-
System and Information Integrity.
Who needs to comply with NIST SP 800-171?
US government departments employ various external companies and service providers. Those responsible for sensitive data include:
-
Defense contractors
-
Web and Communication Service Providers
-
Financial Services Organizations
-
Healthcare Data Processors
-
Educational Institutions
-
Systems Integrators
-
Research Institutes Or Labs
NIST SP 800-171 Best Practice
To achieve your compliance status, you must meet 110 requirements. This involves adhering to the below steps:
-
Senior information security heads must form an assessment team
-
This team must create an assessment plan, listing the timeframe and goals
-
Awareness shared via an internal marketing campaign
-
A list of personnel showcasing details and relevant responsibilities
-
Relevant documents must be collated, such as existing system records, security policies, and manuals, as well as past admin guidance documents, audit results, logs, and system architecture documents.
-
Recorded statements
-
A plan of action to address unmet requirements;
-
All evidence for compliance is logged into a System Security Plan (SSP) document.
The Bottom Line
If you’re an organization handling or storing sensitive data on your network, you must comply with NIST SP 800-171. This is a necessity of contracts between the US government and you (the contractor).
Although 110 requirements exist, all of which you must meet to achieve compliance, executing a NIST SP 800-171 assessment shouldn’t be something to be feared. When you follow the above tips, securing this involves a clear and precise method.
You must be logged in to post a comment.