Skip to content
CMMCPulsarby Federal Bid Partners

NIST SP 800-171

Build a defensible CUI protection program.

Revision 3 organizes the security requirements nonfederal organizations use to protect Controlled Unclassified Information in covered systems and environments.

Last updated: August 1, 2026

Important CMMC distinction

NIST published SP 800-171 Revision 3 in May 2024. Current CMMC Level 2 assessment requirements still reference the 110 requirements in Revision 2. CMMCPulsar treats Revision 3 as a separate readiness workspace so users do not mix control baselines or evidence.

What Revision 3 covers

NIST SP 800-171 Revision 3 applies to components of nonfederal systems that process, store, or transmit CUI, or that provide protection for those components. It establishes security requirements derived from the federal control catalog and tailored for protecting CUI.

17 control familiesRequirements are grouped by security capability and operating discipline.
System-focused scopeIdentify components that handle CUI or protect the environment that handles it.
Organization-defined parametersSome requirements require the organization to define values and frequencies.
Assessment companionSP 800-171A Revision 3 provides procedures for assessing each requirement.

The 17 control families

Access ControlAwareness and TrainingAudit and AccountabilityAssessment, Authorization, and MonitoringConfiguration ManagementIdentification and AuthenticationIncident ResponseMaintenanceMedia ProtectionPersonnel SecurityPhysical ProtectionPlanningProgram ManagementRisk AssessmentSystem and Services AcquisitionSystem and Communications ProtectionSystem and Information Integrity

Documentation and evidence that make the program usable

  • A defined authorization boundary and inventory of covered components.
  • A system security plan that describes how each requirement is implemented.
  • Policies and procedures that match actual operating practices.
  • Evidence with an owner, source, review date, and mapped requirement.
  • Risk decisions, inherited protections, providers, and interconnections.
  • Assessment results and remediation records that remain traceable over time.

A practical implementation sequence

1. ScopeFind CUI, covered components, external services, and protection assets.
2. DescribeDocument the current implementation before assigning a status.
3. MapConnect requirements, evidence, owners, providers, and architecture.
4. AssessUse the 800-171A procedures to test whether the requirement is satisfied.
5. RemediatePrioritize gaps by CUI exposure, likelihood, and operational impact.
6. MaintainRefresh evidence and reassess when systems, threats, or requirements change.

Official NIST sources