Skip to content
Capability/Compliance Frameworks

NIST 800-171

Controlled Unclassified Information protection

01 / Overview

NIST Special Publication 800-171 establishes security requirements for protecting Controlled Unclassified Information in nonfederal systems. Thalorin automates 800-171 compliance with control implementation tracking, evidence collection, and self-assessment documentation that supports DFARS compliance.

NIST SP 800-171 is the control set behind most CUI obligations in federal contracting, and in 2026 it is in an awkward position: the current published revision is not the revision you are assessed against. NIST finalised Revision 3 in May 2024, reorganising the requirements from 110 into 97 and introducing organisation-defined parameters. The Department of Defense has not completed the rulemaking to adopt it, so assessment, SPRS scoring, and DFARS 252.204-7012 compliance still run on Revision 2.

The clause architecture around it is four interlocking provisions, and they are routinely conflated. DFARS 252.204-7012 imposes the safeguarding requirement and the 72-hour cyber incident report to the Department. DFARS 252.204-7019 makes a current summary level score in SPRS a condition of being considered for award. DFARS 252.204-7020 defines the assessment methodology behind that score — Basic self-assessment, Medium and High government-led — and carries the flow-down. DFARS 252.204-7021 adds CMMC on top. Each binds at a different moment.

What has not changed is that a score still has to reach SPRS, and it still has to be defensible. The scoring methodology is tied to the control structure of the applicable revision, which is precisely why a Rev 2 score cannot be mechanically translated into a Rev 3 score when adoption eventually lands.

Thalorin holds the control state once and projects it into whichever revision a given obligation requires, so a contractor can prepare for Rev 3 without abandoning the Rev 2 posture currently being scored.

02 / Challenges

Framework compliance requires sustained effort

Two live revisions, one score

Rev 3 is published and final; Rev 2 is what gets assessed. Teams that migrated early to Rev 3 documentation now maintain a translation layer back to the structure SPRS actually scores.

Four clauses, four different triggers

7012 binds during performance, 7019 at proposal, 7020 at assessment and at flow-down, 7021 at solicitation. Reading them as one CUI requirement is how a bid team discovers at proposal that its SPRS score has aged past three years.

Score defensibility

A SPRS figure is an assertion. When a Medium or High government assessment tests it, the gap between the claimed score and the evidence behind it becomes the finding.

Rev 3 will not be a mapping exercise

Reorganising 110 requirements into 97 with organisation-defined parameters changes what must be decided, not just where it is written. Adoption will require a new assessment and a new score.

03 / Capabilities

How Thalorin helps

Control family implementation

Hold one control state and project it into Rev 2 for scoring and Rev 3 for readiness, including the organisation-defined parameters Rev 3 introduces, rather than maintaining two divergent sets of documentation.

SSP generation for CUI

Maintain the System Security Plan as a generated artifact of the same control state, not as a document edited separately from the environment it describes.

POA&M management

Carry each unimplemented requirement as a POA&M item with its own owner, target date and evidence of progress, so the plan is a live record rather than a document rewritten before an assessment.

Self-assessment documentation

Compute the SPRS score from evidence rather than from a spreadsheet assertion, so the figure can be reconstructed on demand.

CUI boundary definition

Bind each requirement to the systems and assets in the CUI boundary that satisfy it, making scope changes visible as control impact.

Inheritance documentation

Record which requirements are satisfied by an external provider or a shared enclave, and which half of each shared control you still own, so inheritance is a documented split rather than an assumption.

Questions

NIST 800-171: common questions

Should I implement NIST 800-171 Rev 2 or Rev 3?

Assess and score against Rev 2 — that is what the Department uses for CMMC, SPRS, and DFARS 7012 as of August 2026. Prepare for Rev 3, which NIST finalised in May 2024, but do not migrate your assessed posture to it until rulemaking completes. Industry expectation has adoption somewhere in the late 2026 to mid 2027 range, and that has already slipped more than once.

What is the difference between DFARS 7012, 7019, 7020 and 7021?

They stack rather than substitute. 252.204-7012 requires you to safeguard covered defense information and to report a cyber incident to the Department within 72 hours of discovery. 252.204-7019 conditions award consideration on a current summary level score — not more than three years old — posted in SPRS. 252.204-7020 defines the assessment methodology behind that score and requires the clause to flow down to subcontractors handling covered information. 252.204-7021 layers CMMC certification on top where the contract carries it.

Why does Rev 3 have 97 requirements instead of 110?

Rev 3 consolidated and restructured the control families rather than removing obligations. The lower count does not mean less work — assessment complexity increased, and the introduction of organisation-defined parameters means some decisions previously fixed by the standard now have to be made, justified, and documented by the organisation.

Do I need a new SPRS score when Rev 3 is adopted?

Almost certainly. The scoring methodology is bound to the control structure of the applicable revision, and a shift from 110 requirements to 97 reorganised ones is a structural change rather than a renaming. Expect a fresh self-assessment and a new score submission rather than an arithmetic conversion.

How is 800-171 different from 800-53?

800-53 is the full federal control catalogue, used for federal information systems under FISMA and FedRAMP. 800-171 is a tailored subset addressing Controlled Unclassified Information in non-federal systems — contractor environments. Many 800-171 requirements derive from 800-53 controls, which is why an organisation carrying both can satisfy overlapping obligations from shared evidence.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about NIST 800-171.

See how one evidence artifact satisfies NIST 800-171 requirements alongside every other framework you carry.