Also known as: NIST 800-171 · NIST Special Publication 800-171
The NIST standard that defines how to protect Controlled Unclassified Information on non-government systems — the control baseline behind DFARS 7012 and CMMC.
NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," is the U.S. National Institute of Standards and Technology's catalog of security requirements for safeguarding CUI when it lives on a contractor's systems rather than the government's. Revision 2 organizes 110 security requirements across 14 families (such as Access Control, Incident Response, and System and Communications Protection) and is the control set referenced by DFARS 252.204-7012 and required for CMMC Level 2. (NIST published Revision 3 in 2024, which restructures the families and controls; however, DoD contracts and the CMMC program continue to be anchored to Revision 2 during the transition, so confirm which revision a specific contract cites.)
Source: NIST SP 800-171 Rev. 2 (NIST CSRC)
Revision 2 contains 110 security requirements organized into 14 families. This is the baseline referenced by DFARS 252.204-7012 and CMMC Level 2.
NIST 800-171 is the underlying set of security requirements. CMMC is the DoD program that verifies a contractor has actually implemented them — Level 2 maps directly to the 110 requirements in NIST SP 800-171 Rev 2.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.