NIST SP 800-171

NIST (The National Institute of Standards and Technology)

Comprehensive framework for safeguarding Controlled Unclassified Information (CUI) in nonfederal systems.

NIST SP 800-171r2 & CMMC

Revision 2 provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when:

  1. The CUI resides in a nonfederal system or organization.

  2. The organization is not operating on behalf of a federal agency.

  3. No specific safeguarding requirements exist in law or regulation.

It serves as the baseline for compliance programs such as CMMC 2.0.

Explore Revision 2

Coming Soon

NIST SP 800-171r3 & CPCSC

Revision 3 emphasizes the evolution of CUI protection requirements, aligning with the latest cybersecurity standards and risk management practices. It enhances federal–nonfederal collaboration and refines security controls for systems that process, store, or transmit CUI.