NIST 800-171, Translated for Small Contractors

George
By George
27 September 2026
Defense contractor compliance standard and CUI

NIST 800-171 is the security standard behind almost every uncomfortable email a small defense supplier receives: the prime's questionnaire, the contracting officer's request for a score, the clause buried on page forty of a purchase order. It is also one of the most misunderstood documents in the whole compliance world, partly because it now exists in two versions, and partly because its scoring system produces numbers that look like typos. This guide explains what NIST 800-171 actually requires, which version governs your contracts in 2026, how the scoring math works against the unprepared, and a realistic ninety-day path from an honest negative score to a defensible one.

The short version for the impatient: Revision 2, with its 110 requirements, is still the contractual standard; your SPRS score is a condition of winning defense work today; and the distance between "we have good IT" and "we can evidence 110 requirements" is almost always wider than leadership expects.

What NIST 800-171 Is, and What CUI Actually Means

NIST Special Publication 800-171 is the federal government's standard for protecting Controlled Unclassified Information on systems the government does not own. CUI is information the government creates or that contractors create for it, which is sensitive enough to require protection but not classified: engineering drawings, technical specifications, export-controlled designs, certain program and pricing data. When that information leaves a government system and lands on a contractor's file server, laptop, or cloud tenant, 800-171 is the rulebook that follows it.

The standard was written for exactly this situation, which distinguishes it from its better-known sibling. The NIST Cybersecurity Framework is a voluntary structure any organization can adopt to organize its security program. NIST 800-171 is different in kind: for defense contractors it is a contractual obligation with a score attached, and treating it as optional best practice is how companies end up ineligible for the work they already do.

Rev 2 or Rev 3: The Version Question, Settled for Now

Two versions of the standard exist, and knowing which one you owe is worth stating plainly, because getting it wrong wastes months.

Revision 2 contains 110 security requirements organized into 14 families. It is the version written into defense contracts through DFARS clause 252.204-7012, the version behind the SPRS scoring methodology, and the version the CMMC program assesses at Level 2. Revision 3, published by NIST in May 2024, restructured the standard to 97 requirements in 17 families. It is the newer document, and it is not what your contracts require: the Department issued a class deviation directing contractors to continue with Revision 2 until contracting rules formally adopt the newer version, and as of September 2026 they have not.

The practical rule is simple. Build, score, and document against Revision 2 today, because that is what SPRS, assessors, and primes all reference. Keep Revision 3 on the radar as the eventual destination, and treat any gap analysis you commission that quietly used the wrong revision as a red flag about the vendor, not a bonus.

NIST 800-171 fourteen control families wheel

The 14 Families, in Plain Business Terms

The 110 requirements sound overwhelming until they are grouped by what they actually ask, which is a set of questions any well-run business should be able to answer.

  • Who gets in, and to what. Access Control and Identification and Authentication are the largest families: unique accounts, least privilege, multifactor authentication, and control over remote and privileged access. This is where granular access control stops being a slogan and becomes a scored requirement.
  • What people know and do. Awareness and Training and Personnel Security cover training the workforce that touches CUI and handling departures and role changes cleanly.
  • What you can prove afterward. Audit and Accountability requires logs that can reconstruct who did what, retained and reviewed, which is the family small environments most often fail silently.
  • How systems are built and kept. Configuration Management and Maintenance cover hardened baselines, change control, and controlled maintenance, including who plugs what into which machine.
  • Where the data lives and travels. Media Protection, Physical Protection, and System and Communications Protection govern encryption in transit and at rest, marked media, visitor control, and network boundaries.
  • What happens when it goes wrong. Incident Response requires a tested capability to detect, report, and recover, and defense contracts add a hard reporting clock measured in hours, not weeks. Recovery leans on the same tested backup and recovery discipline every business should already have.
  • Whether you keep checking. Risk Assessment, Security Assessment, and System and Information Integrity cover vulnerability scanning, periodic control review, and malicious code protection, the recurring work that keeps the other families true over time.
NIST 800-171 Rev 2 versus Rev 3

Nothing in that list is exotic. What makes 800-171 demanding is not any single requirement but the evidence discipline: every "yes" must be a yes an assessor could verify from documentation, settings, and logs.

How 800-171 Becomes a Contract Obligation

The standard reaches a contractor through a chain of clauses worth knowing by number, because they are what a prime's supply chain team will quote at you.

DFARS 252.204-7012 has required implementation of NIST 800-171 for systems handling covered defense information since the end of 2017, and it carries the incident-reporting obligation, seventy-two hours to report a cyber incident through the Department's portal. DFARS 252.204-7019 and 7020 added the requirement to complete the official self-assessment methodology and post a current score to SPRS, the Supplier Performance Risk System, where contracting officers can see it. And 252.204-7021 is the CMMC clause that layers formal verification on top. Since November 2025, new covered solicitations condition award on that SPRS entry and an annual affirmation, and the July 2026 pause of CMMC's third-party assessment phase changed none of it: the self-assessment, the score, and the affirmation remain the price of admission.

The affirmation deserves respect. It is a representation to the federal government signed by a senior official, and inflated scores have already produced False Claims Act settlements across the industry. An honest negative number with a dated remediation plan is a defensible position. A confident 110 with no evidence behind it is a liability with a signature on it.

The SPRS Score: Why Good Companies Score Negative

The scoring methodology starts every company at 110 and subtracts for each unimplemented requirement, with weights of one, three, or five points reflecting how much protection the requirement carries. Because the five-point penalties attach to the fundamentals, multifactor authentication, encryption of CUI, controlled connections, the floor of the scale is minus 203, and a company that has real security but incomplete coverage routinely scores below zero on its first honest pass.

That first number is diagnostic, not shameful. The score is designed to move fast when the heavy items close: implementing multifactor authentication alone can swing the total by five points per related requirement, and the first month of a serious effort usually moves the score more than the following six. What the methodology refuses to reward is paperwork without implementation, and what SPRS quietly records is the date of your assessment, so a stale entry tells its own story to anyone who looks.

SPRS score waterfall with POAM checklist

A Plan of Action and Milestones absorbs the remainder: each open requirement, its owner, and its closure date. Under current rules the highest-weight requirements cannot sit on a POA&M indefinitely, and CMMC assessment rules cap closure at 180 days, so the plan is a runway, not a parking lot.

Scoping: The Decision That Sets Your Cost

The single most expensive mistake in 800-171 work happens before any control is touched: letting the whole company network fall in scope. The requirements apply to systems that store, process, or transmit CUI, and to components that provide security for those systems. Everything else is out of scope, and out of scope means out of cost.

The winning pattern for a small contractor is an enclave: a defined set of systems, accounts, storage locations, and, where needed, a government-grade cloud tenant, inside which all CUI lives, with the boundary enforced technically rather than by memo. Cloud choice matters here, because when CUI sits in a cloud service the government expects that service to meet FedRAMP Moderate or equivalent, a bar ordinary commercial email and storage tiers do not clear. This is why defense suppliers end up on the government-cloud editions of the major productivity platforms, with cloud security controls configured to keep the covered data inside the boundary.

Scoping is also where the flow of information gets mapped: which contracts deliver CUI, which machines and people touch it, which vendors receive it. Companies are regularly surprised in both directions, discovering CUI in a shared drive nobody flagged, and discovering that half the network they feared certifying never touches covered data at all.

CUI scoping enclave versus out-of-scope systems

Where Small Contractors Actually Fail

Assessment findings cluster with remarkable consistency, and knowing the pattern lets a small company aim its first ninety days where they count.

The System Security Plan is missing or aspirational, describing intentions rather than the environment as configured. Multifactor authentication covers email but not VPN, servers, or administrative accounts. Encryption exists but not validated encryption where the standard requires it. Logging is on by default and reviewed by no one, so the audit trail exists until the day someone needs it and discovers retention was thirty days. CUI turns out to live in a personal sync folder, an unmarked subfolder, or a commercial cloud tenant that cannot satisfy the government's bar. And incident response is a paragraph, not a tested procedure with the seventy-two-hour defense reporting clock built in. None of these are failures of spending. They are failures of specificity, which is exactly what the standard is designed to force.

A Ninety-Day Path to a Defensible Score

  1. Weeks 1 and 2: map and scope. Inventory contracts for the DFARS clauses, locate every place CUI actually lives, and draw the smallest honest boundary around it.
  2. Weeks 3 and 4: score truthfully. Assess all 110 requirements with the official methodology, record the real number, and let it be negative if it is negative.
  3. Weeks 5 through 8: close the five-point items. Multifactor authentication everywhere in scope, validated encryption for CUI at rest and in transit, administrative account separation, and boundary control. This block moves the score most.
  4. Weeks 9 and 10: write it down. Produce the System Security Plan that matches the environment as built, and the POA&M with owners and dates inside the 180-day discipline.
  5. Weeks 11 and 12: submit, affirm, and rehearse. Post the score to SPRS, complete the affirmation, run one incident-response tabletop against the seventy-two-hour clock, and calendar the quarterly re-check.

A company that completes this arc is eligible to compete, positioned for whatever verification model emerges from the current CMMC review, and materially harder to compromise, which for suppliers across Ventura County and the wider Los Angeles defense corridor is increasingly what primes are selecting for.

800-171 and CMMC: Same Requirements, Different Verification

The relationship between the two confuses buyers constantly, and it reduces to one sentence: NIST 800-171 is the standard, and CMMC is the program that verifies it. CMMC Level 2 assesses the same 110 Revision 2 requirements; what CMMC adds is the verification machinery of self-assessments, third-party C3PAO certifications, and affirmations. In July 2026 the Department suspended the phase that would have made third-party certification a condition of most CUI contract awards while a reform task force reviews the program, but the standard underneath, the DFARS clauses, and the SPRS scoring were untouched. Work done against the 110 requirements is never wasted by whatever the review decides, because every plausible outcome still verifies the same list.

Frequently Asked Questions

For companies whose contracts carry the DFARS cybersecurity clauses, yes. Implementation has been a contractual requirement since the end of 2017, a current self-assessment score in SPRS has been required since 2020, and since November 2025 new covered defense solicitations condition award on that score plus an annual affirmation. The 2026 pause of CMMC's third-party assessment phase did not suspend any of these obligations.
Not yet. Defense contracts continue to require Revision 2, with its 110 requirements in 14 families, under a Department class deviation issued when Revision 3 was published in 2024. Revision 3 reorganized the standard to 97 requirements in 17 families and will matter when acquisition rules formally adopt it, but building against it today would leave you misaligned with SPRS scoring, assessors, and your primes.
A perfect implementation scores 110, and there is no published passing threshold for eligibility; what contracts require is a current, truthful score with an affirmation. Companies routinely start negative because unmet requirements subtract weighted penalties down to a floor of minus 203. What matters is that the number is honest, that a dated POA&M covers the gaps, and that the highest-weight requirements are actually implemented rather than planned.
No. The plan of action is a scheduling tool with owners and closure dates, not a waiver. Under the assessment rules layered on by CMMC, POA&Ms are limited to certain lower-weight requirements and must close within 180 days, and the five-point fundamentals such as multifactor authentication and CUI encryption are expected to be implemented, not deferred.
Usually not. When CUI is stored or processed in a cloud service, the government expects that service to meet FedRAMP Moderate or an equivalent bar, which standard commercial email and file-sharing tiers generally do not. This is why defense suppliers operate on the government-cloud editions of the major platforms, with sharing and boundary controls configured to keep covered data inside the defined scope.

If a prime is asking for your score, or your SPRS entry is a guess rather than a measurement, a scoped NIST 800-171 gap assessment will give you the real number, the shortest path to raise it, and the documentation that makes the affirmation safe to sign.

Comments

0 Comments