NIST SP 800-171 Rev. 3 Pillar Guide · Published September 2026

NIST SP 800-171 Rev. 3
Implementation Guide

A practical walkthrough of CUI scope, the 17 security-requirement families, organization-defined parameters, tailoring, SSP and POA&M evidence, SP 800-171A Rev. 3 assessment methods, common readiness gaps, and a sequenced 90-day implementation plan.

Maintained by ComplianceStack · 2026-09-09 · Citation-ready (Dublin Core & citation metadata)

On this page

  1. §1 CUI scope and who Rev. 3 applies to
  2. §2 Rev. 3 structure, ODPs, tailoring, and all 17 families
  3. §3 Rev. 2 to Rev. 3 and the role of 800-171A Rev. 3
  4. §4 Sequenced implementation method
  5. §5 Evidence expectations: examine, interview, test
  6. §6 Common readiness gaps
  7. §7 Practical 90-day roadmap
  8. §8 NIST publication vs current contract and CMMC requirements
  9. §9 ComplianceStack tools
  10. §10 Primary sources and frequently asked questions

§1 CUI scope and who NIST SP 800-171 Rev. 3 applies to

NIST SP 800-171 Rev. 3 is for protecting Controlled Unclassified Information in nonfederal systems and organizations. Scope starts with the information and the authority that requires its protection, not with a vendor’s product list or a generic “government data” label.

Controlled Unclassified Information (CUI) is information the federal government creates or possesses, or that a non-executive-branch entity creates or possesses for or on behalf of an agency, where a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls. CUI is not classified information, and ordinary company confidential information is not automatically CUI. Confirm the category and authority in the NARA CUI Registry and the contract or other federal agreement.

Rev. 3 is relevant to a contractor, subcontractor, grantee, research institution, service provider, or other nonfederal organization that receives, creates, stores, processes, or transmits CUI. The organization may be a prime or a lower-tier supplier. The practical question is: which information is CUI, where does it go, which systems and people can touch it, and what clause or authority makes the protection requirement applicable?

Define a defensible boundary before scoring requirements. Include CUI repositories and processing systems, endpoints, identity systems, administrators, network paths, cloud services, managed service providers, facilities, removable media, backups, and interfaces. Record exclusions too: a system that never stores, processes, or transmits CUI may be out of scope, but a connection that can move CUI across the boundary still needs a documented treatment.

§2 Rev. 3 structure, ODPs, tailoring, and all 17 requirement families

Rev. 3 aligns its requirements more directly with NIST SP 800-53 Rev. 5 and introduces organization-defined parameters (ODPs). The 17 families are the organizing structure; each family contains requirements, and an ODP makes a locally approved value or decision explicit where the publication leaves it to the organization, customer, or authorizing authority.

ODPs are decisions, not blanks to ignore. For each ODP, document the selected value, decision owner, rationale, approval date, review trigger, and the procedure or technology that enforces it. Tailoring then removes or adjusts requirements only when the Rev. 3 tailoring criteria and the applicable authority support that decision. Record common controls and inherited services instead of counting them twice, and preserve the rationale in the SSP.

FamilyWhat it covers in an implementation programTypical evidence starting point
AC Access ControlLimit CUI access, enforce least privilege, control remote and wireless access, and separate privileged functions.Access policy, role matrix, account review, authorization logs.
AT Awareness and TrainingPrepare users and privileged roles to recognize, handle, report, and protect CUI.Training content, completion records, role-specific curriculum.
AU Audit and AccountabilityDefine auditable events, protect logs, review activity, and connect records to accountable identities.Logging standard, SIEM configuration, review tickets, retention settings.
CA Assessment, Authorization, and MonitoringAssess controls, authorize operation, track findings, and monitor changes to the security posture.Assessment plan/report, authorization decision, POA&M, monitoring reports.
CM Configuration ManagementEstablish secure baselines, control changes, inventory components, and prevent unauthorized configuration drift.Baseline, change records, asset inventory, compliance scans.
IA Identification and AuthenticationUniquely identify users and devices, manage authenticators, and protect privileged authentication.Identity policy, MFA configuration, joiner/mover/leaver records.
IR Incident ResponsePrepare for, detect, report, contain, eradicate, recover from, and learn from CUI-related incidents.IR plan, playbooks, exercises, incident tickets, lessons learned.
MA MaintenanceControl maintenance tools, personnel, remote maintenance, and equipment used on in-scope systems.Maintenance approvals, vendor access records, session logs.
MP Media ProtectionControl access to, transport, storage, sanitization, and disposal of digital and physical CUI media.Media register, encryption settings, sanitization certificates.
PE Physical and Environmental ProtectionProtect facilities, workstations, output, and supporting infrastructure from physical and environmental threats.Badge reports, visitor logs, facility procedures, environmental alerts.
PL PlanningTranslate mission, risk, system, and CUI assumptions into plans, rules of behavior, and security architecture.SSP, rules of behavior, security architecture, planning approvals.
PS Personnel SecurityScreen, authorize, transfer, and terminate personnel with access to CUI or security-relevant functions.Screening records, nondisclosure agreements, termination checklist.
RA Risk AssessmentIdentify threats and vulnerabilities, assess likelihood and impact, and keep risk information current.Risk assessment, risk register, vulnerability reports, treatment decisions.
SA System and Services AcquisitionBuild security requirements into acquisition, development, external services, and supply-chain decisions.Procurement requirements, vendor review, contract language, acceptance tests.
SC System and Communications ProtectionProtect boundaries, transmission paths, architecture, cryptography, and CUI flows between systems.Network diagram, boundary rules, encryption standard, firewall review.
SI System and Information IntegrityDetect and correct flaws, malicious code, unauthorized changes, and integrity failures affecting CUI.Vulnerability cadence, patch records, malware controls, integrity alerts.
SR Supply Chain Risk ManagementIdentify, assess, and manage cybersecurity risks introduced by suppliers, services, components, and sub-tier dependencies.Supplier inventory, risk assessments, flow-down terms, review records.

The family table is a planning aid, not a substitute for the requirement text. Use the NIST Cybersecurity and Privacy Reference Tool (CPRT) to work from the final Rev. 3 dataset and retain the exact requirement, ODP, tailoring, evidence, status, and owner in your control register.

§3 What changed from Rev. 2, and how 800-171A Rev. 3 fits

Rev. 3 is a substantive NIST publication update, while SP 800-171A Rev. 3 is the companion assessment publication. Neither silently changes a contract that still names Rev. 2.

Important Rev. 2-to-Rev. 3 changes include direct alignment to the SP 800-53 Rev. 5 control catalog, new organization-defined parameters, revised tailoring criteria, clearer control and requirement structure, and a 17-family model that includes Assessment, Authorization, and Monitoring (CA), System and Services Acquisition (SA), and Supply Chain Risk Management (SR). The result is more explicit governance around assessment, inherited controls, acquisition, and supply-chain risk; it also creates more decisions that must be approved and maintained rather than assumed.

NIST SP 800-171A Rev. 3 supplies assessment objectives and procedures for determining whether Rev. 3 requirements are implemented. Its methods are examine (review documentation, specifications, mechanisms, and records), interview (obtain information from people with relevant knowledge), and test (operate or exercise mechanisms and processes). The assessor may tailor depth and coverage to the purpose of the assessment; the procedure is not a claim that every organization needs one identical evidence binder.

Publication
800-171 Rev. 3
Requirements
Assessment
800-171A Rev. 3
Procedures
Program
CPRT dataset
Mappings
Contract
Clause + scope
Obligation

§4 A sequenced NIST SP 800-171 Rev. 3 implementation method

The order matters. A control checklist without a CUI boundary, approved ODPs, and a current SSP will produce a score that is difficult to defend.

1. Discover CUI and establish the boundary

Inventory CUI types, designating agency, category, authority, markings, contract source, and data lifecycle. Trace repositories, applications, endpoints, identities, facilities, service providers, backups, printed output, and transfer paths. Draw the boundary and document connections to systems that are not themselves CUI systems.

For a focused walkthrough of turning CUI discovery and boundary decisions into a defensible readiness register, read the NIST 800-171 CUI boundary readiness article.

2. Map obligations to the boundary

Read the solicitation and contract clauses with procurement and legal stakeholders. Separate NIST’s implementation guidance from obligations created by DFARS, 32 CFR Part 170, agency policy, customer flow-down, or a specific program. Record the required baseline, assessment type, scoring or submission process, and timing as contract facts.

3. Tailor the 17 families and decide ODPs

Start with every applicable Rev. 3 family. For each requirement, mark implemented, partially implemented, planned, inherited, not applicable with rationale, or not implemented. Complete ODPs with accountable owners and approvals. Capture common controls, external services, assumptions, exceptions, and risk acceptances.

4. Build the SSP and POA&M together

The SSP explains how the system and requirements are implemented, including architecture, boundaries, roles, technologies, procedures, ODP values, and inherited controls. The POA&M tracks unfinished work with a specific weakness, owner, milestone, dependency, risk treatment, and validation method. A POA&M is a management instrument; it is not proof that an incomplete requirement is already implemented.

5. Implement high-leverage protections

Prioritize identity and privileged access, CUI flow and boundary controls, logging and monitoring, secure configuration, vulnerability remediation, incident response, media handling, supplier risk, and personnel lifecycle. Link each technical change to a policy, an owner, and a repeatable evidence source.

6. Assess, remediate, and monitor continuously

Run an internal assessment against 800-171A procedures, close or accept gaps through the authorized governance process, retest changes, and update the SSP whenever the boundary, service, architecture, CUI flow, or requirement decision changes. Keep evidence current enough to show operation, not merely intent.

§5 Evidence expectations: examine, interview, and test

Evidence should let an assessor reproduce the claim: what requirement is addressed, where the control operates, who owns it, when it was effective, what population it covers, and what happened when the control found an exception.

MethodWhat the assessor doesEvidence examples
ExamineReviews documentation, policies, plans, specifications, configurations, records, and reports.SSP and diagrams; ODP approvals; policies; asset and supplier registers; tickets; logs; training records; incident and maintenance records.
InterviewTalks with system owners, administrators, users, managers, responders, and service providers who can explain the control.Named owner list; interview prompts; role-specific answers; escalation paths; evidence of awareness and operational knowledge.
TestOperates, observes, or exercises mechanisms and processes to verify they function as described.Access review sample; MFA or configuration demonstration; log query; restore test; incident exercise; vulnerability scan; boundary rule validation.

Build an evidence index with requirement ID, artifact name, system or population, period covered, owner, location, sensitivity, and review status. Avoid collecting screenshots with no date, scope, or context. A single point-in-time configuration screenshot is weaker than a controlled configuration export plus change history and a tested exception workflow.

§6 Common readiness gaps

Turn NIST 800-171 readiness gaps into next actions

If your CUI boundary, ODP decisions, SSP, evidence, supplier controls, or a POA&M still have open questions, use the free NIST 800-171 readiness analyzer to organize a directional starting point and prioritize the next diagnostic steps.

The result is directional guidance only; it does not replace a government assessment, C3PAO assessment, or contract-defined assessment.

Use the Free Readiness Analyzer →

§7 A practical 90-day implementation roadmap

Use the roadmap as a sequencing device. Contract dates and assessment requirements still control the actual schedule.

DaysFocusExit evidence
0–15Confirm CUI authority and categories; interview contract owners; inventory data flows, repositories, identities, endpoints, facilities, providers, and connections; draft the boundary.Approved scope statement, CUI/data-flow map, asset and supplier inventory, contract-obligation register.
16–30Map Rev. 3 requirements to the boundary; identify common and inherited controls; assign owners; decide ODPs and tailoring; baseline access, MFA, logging, encryption, and configuration.Requirement register, ODP decision log, tailoring rationale, control-owner matrix, initial risk register.
31–45Write the SSP; formalize policies and rules of behavior; implement prioritized AC, IA, SC, CM, AU, SI, and MP changes; establish evidence collection.Versioned SSP and diagrams, approved policies, baseline exports, access and logging evidence.
46–60Address IR, RA, CA, AT, PS, PE, MA, SA, and SR; validate supplier flow-down; run incident, recovery, access-review, and vulnerability-management exercises.Exercise records, training and personnel evidence, supplier reviews, test results, findings log.
61–75Run an 800-171A-style internal assessment using examine, interview, and test; prioritize findings; build a measurable POA&M; get management decisions on residual risk.Assessment plan and report, interview/test notes, POA&M, approved risk decisions.
76–90Retest remediations, close evidence gaps, update SSP and ODP approvals, verify monitoring cadence, and prepare the contract-specific assessment or customer review package.Retest results, current SSP, evidence index, monitoring calendar, readiness decision with scope and limitations.

§8 NIST’s Rev. 3 publication is not the same as today’s contract or CMMC baseline

This distinction prevents a common and costly mistake: treating a new NIST publication as an automatic amendment to every contract, solicitation, or CMMC assessment.

NIST published the final Rev. 3 and Rev. 3A publications on May 14, 2024. That establishes current NIST guidance and an assessment companion. It does not, by itself, rewrite a contract. The applicable solicitation, contract clauses, agency direction, customer flow-down, and program rules determine what a contractor must implement and how it must be assessed.

As of this guide’s publication, the current DFARS 252.204-7012, 252.204-7019, and 252.204-7020 text may still point to NIST SP 800-171 and the DoD assessment methodology in a contract-specific way. Read the clause version and solicitation rather than assuming Rev. 3 is the scoring baseline.

Likewise, the CMMC rule and program documents can preserve a Rev. 2 control baseline for the CMMC Level 2 requirements currently described by 32 CFR Part 170. See the ComplianceStack CMMC 2.0 guide for that Rev. 2 distinction. Rev. 3 implementation can be a sensible forward-looking security program, but it should not be presented as proof of CMMC compliance or as a replacement for a required government, C3PAO, or other contract-defined assessment.

§9 Pair this guide with ComplianceStack readiness tools

The primary tool is directional readiness guidance for scope, gaps, and next actions. It does not issue a government or C3PAO result.

Free CMMC Readiness Analyzer

Use the free CMMC readiness analyzer to organize CUI scope, contract context, assessment-path questions, and readiness gaps. It is a directional starting point and preserves the distinction between current CMMC Rev. 2 requirements and NIST Rev. 3 guidance.

Run the Free Readiness Analyzer →

Free Multi-Framework Assessment

The free compliance assessment helps prioritize security and compliance gaps across frameworks. Use it for directional triage, then validate the NIST boundary, contract baseline, ODPs, and evidence with the accountable program team.

Start the Free Assessment →

Evidence and Compliance Pulse

Pair the CMMC evidence pack with the CMMC Compliance Pulse when you need an evidence-oriented checklist and a quick readiness signal. They support preparation; they are not an assessment.

Review the Evidence Pack →

Build a 90-Day Plan

Use the 90-day roadmap for owner assignment, sequencing, and milestones. For framework context, compare the NIST CSF 2.0 guide with this requirement-level CUI guide.

Build the Roadmap →

§10 Primary sources and frequently asked questions

What is NIST SP 800-171 Rev. 3?
NIST SP 800-171 Rev. 3 is NIST’s final set of security requirements for protecting CUI in nonfederal systems and organizations. It was published May 14, 2024 and adds ODPs, revised tailoring, and clearer alignment with SP 800-53 Rev. 5. It is guidance and a requirements publication, not automatically a contract, certification, or C3PAO assessment.
Who does Rev. 3 apply to?
It is intended for nonfederal organizations that handle CUI under a federal contract, grant, or other agreement. The actual obligation depends on the CUI authority, contract language, customer direction, and system boundary. A federal-contractor label alone does not define identical scope.
What are the 17 Rev. 3 families?
Access Control; Awareness and Training; Audit and Accountability; Assessment, Authorization, and Monitoring; Configuration Management; Identification and Authentication; Incident Response; Maintenance; Media Protection; Physical and Environmental Protection; Planning; Personnel Security; Risk Assessment; System and Services Acquisition; System and Communications Protection; System and Information Integrity; and Supply Chain Risk Management.
How do examine, interview, and test differ?
Examine reviews documentation and records, interview obtains information from knowledgeable people, and test operates or exercises mechanisms and processes. SP 800-171A Rev. 3 uses these methods with depth and coverage tailored to the assessment purpose.
Does current CMMC use Rev. 3?
Do not assume so. Current contract and CMMC requirements may still reference Rev. 2 or a specific DoD methodology. Read the solicitation, clause version, 32 CFR Part 170, and program direction. ComplianceStack keeps the current CMMC Rev. 2 distinction visible rather than relabeling it as Rev. 3.
Can ComplianceStack perform a government or C3PAO assessment?
No. ComplianceStack provides directional readiness guidance, gap organization, and evidence-planning support. It is not a government assessment, C3PAO assessment, certification, attestation, legal opinion, or substitute for the assessment required by a contract or program.