How can I help with NIST 800-171?

Free AI guidance for NIST 800-171 CUI compliance.

About the NIST 800-171 assistant

Seeded with NIST SP 800-171 concepts for protecting Controlled Unclassified Information (CUI) in nonfederal systems: scoping the environment that stores, processes, or transmits CUI, the security requirement families, and the DoD assessment methodology used for defense contracts. For covered contractor information systems subject to DFARS 252.204-7012, current DoD and CMMC Level 2 assessments use Revision 2, with its 110 requirements across 14 families, while Revision 3 (published by NIST in 2024, with 97 requirements across 17 families and organization-defined parameters) is the newer NIST edition, and contractors should follow the revision their contract specifies. It also covers the DFARS clauses 252.204-7012, 7019, and 7020, the Supplier Performance Risk System (SPRS) score, the system security plan, the plan of action and milestones, and how the standard relates to CMMC Level 2.

  • Identify the Controlled Unclassified Information that enters your organization, define the boundary of the systems that store, process, or transmit it, and, where appropriate, isolate that environment from the rest of your network, so your NIST SP 800-171 scope reflects where CUI actually lives rather than your whole estate.
  • Work through a self-assessment using the DoD assessment methodology: check your systems against the security requirements, calculate the summary score that starts at 110 and subtracts weighted points for each requirement you have not met, and prepare to post a current score in SPRS as DFARS 252.204-7019 and 7020 expect.
  • Turn the results into a system security plan that records how you meet each requirement, capture the gaps and target dates in a plan of action and milestones, and prioritize the fixes that raise your score, while understanding how this work feeds CMMC Level 2, which is built on NIST SP 800-171.

It gives guidance to speed up your work. NIST SP 800-171 is a set of requirements, not a certification: where the DFARS rules apply, a contractor completes a self-assessment and records a current summary score in SPRS, and a CMMC assessment, when a contract requires it, is carried out separately. This is not a certification or assessment service, and it is not legal advice.

Read the full NIST 800-171 guide