NIST SP 800-171
NIST (The National Institute of Standards and Technology)
Comprehensive framework for safeguarding Controlled Unclassified Information (CUI) in nonfederal systems.
NIST SP 800-171r2 & CMMC
Revision 2 provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when:
The CUI resides in a nonfederal system or organization.
The organization is not operating on behalf of a federal agency.
No specific safeguarding requirements exist in law or regulation.
It serves as the baseline for compliance programs such as CMMC 2.0.
Coming Soon
NIST SP 800-171r3 & CPCSC
Revision 3 emphasizes the evolution of CUI protection requirements, aligning with the latest cybersecurity standards and risk management practices. It enhances federal–nonfederal collaboration and refines security controls for systems that process, store, or transmit CUI.