Back to blog
US & Americas

NIST SP 800-171 explained: the 110 requirements, and who they actually bind

The control set behind CMMC, and an obligation in its own right for anyone handling controlled unclassified information. What the requirement families cover, what the SSP and POA&M must contain, and how scoping decides the cost.
GRC Copilot Team
NIST SP 800-171 explained: the 110 requirements, and who they actually bind

NIST SP 800-171 is frequently discussed as "the CMMC controls", which understates it. It is an obligation in its own right, arriving through contract clauses, and many organisations are bound by it long before CMMC assessment enters the conversation.

What triggers it

Handling controlled unclassified information under a federal contract or subcontract. The obligation flows down the supply chain, so a company several tiers from the government can be bound by it through a purchase order. Check your contract clauses rather than your self-image — most organisations discover the requirement in a flow-down, not a regulation.

The practical difficulty is the same as under CMMC: CUI is often unmarked or inconsistently marked, and it turns out to be sitting in engineering shares, email attachments and CAD systems nobody considered in scope. Identifying where it actually lives is the largest task in the programme and precedes every control decision.

The 110 requirements

Organised into fourteen families: access control; awareness and training; audit and accountability; configuration management; identification and authentication; incident response; maintenance; media protection; personnel security; physical protection; risk assessment; security assessment; system and communications protection; and system and information integrity.

Nothing is exotic. What catches organisations out is the specificity — several requirements demand things a general security programme does not: FIPS-validated cryptography rather than merely strong encryption, multifactor authentication including for local and privileged access, and media marking and sanitisation with records.

The two documents that carry it

  • System Security Plan (SSP) — describes the system boundary and how each of the 110 requirements is met. Not a policy document; an implementation statement an assessor works directly from. A thin SSP produces a hard assessment regardless of how good your controls are.
  • Plan of Action and Milestones (POA&M) — what is not yet met, with dates and owners.
Self-assessment produces a score against a defined methodology, and that score may be submitted to a government system and relied on by primes. Scoring generously is not a private optimism — it is an assertion others act on.

Assess against 800-171 without a spreadsheet

GRC Copilot scores you requirement by requirement, holds evidence for each, and produces the gap list your SSP and POA&M depend on.

Scoping decides the cost

Applying 110 requirements to your whole corporate network is expensive and usually unnecessary. The alternative is a defined enclave where CUI is processed and stored, with everything outside it kept demonstrably CUI-free.

That narrows scope dramatically, and the trade-off is discipline: it only holds if CUI genuinely cannot leave. Email, file sharing, endpoints and the habit of copying drawings to a local drive all have to be controlled. Enclaves fail on user workflow far more often than on architecture.

Relationship to CMMC

CMMC adds verification. The control substance at the level most suppliers face is 800-171; CMMC determines whether you self-assess or are assessed by a third party. Work done for one is work done for the other — so treat 800-171 as the programme and CMMC as the assessment route.

Frequently asked questions

How do we know if we hold CUI?

Start with contract clauses and what the customer sends you. Markings are unreliable, so interviews and discovery tooling usually find more than the paperwork suggests.

Does ISO 27001 cover it?

It covers much of the substance and misses specifics — FIPS-validated cryptography and government incident reporting among them. Expect overlap, not substitution.

Can we use a POA&M indefinitely?

No. Some requirements cannot be deferred, and open items carry closure expectations. It is a bridge, not a parking area.

Does it apply outside the US?

The obligation follows the information, not your location — though data residency terms may constrain where it can be processed.

Key takeaways

  • It binds through contract flow-down, often several tiers down.
  • Finding where CUI actually lives is the largest task, and it precedes everything.
  • FIPS-validated cryptography and MFA scope are the usual specific failures.
  • An enclave cuts cost sharply but only holds if workflow supports it.
#nist-800-171 #cui #ssp #poam #defence-supply-chain #federal-contracts