What is NIST SP 800-171? CUI Protection and the 800-53 Comparison
NIST SP 800-171 is the control set behind DFARS 7012 and CMMC Level 2. What it requires, how Rev 3 changes it, how it differs from 800-53, and why it matters in defense M&A.
What 800-171 Requires
The Fourteen Families (Rev 2)
Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each family contains basic requirements drawn from FIPS 200 and derived requirements drawn from 800-53. The 110 requirements are the practices a CMMC Level 2 assessor scores.
The System Security Plan and POA&M
800-171 requires two governing documents. The System Security Plan describes the system boundary, where CUI lives, and how each requirement is implemented. The Plan of Action and Milestones lists unimplemented requirements and the dates by which they will be closed. Both are assessed. An SSP that describes controls the environment does not actually enforce is the single most common finding in a failed assessment, and the single most common basis for a False Claims Act theory.
Scoring and SPRS
The DoD assessment methodology assigns each requirement a weight of 1, 3, or 5 points. A contractor starts at 110 and subtracts for each unimplemented requirement. The result is posted to the Supplier Performance Risk System, where contracting officers can see it. A score can go negative. A score of 110 with an SSP that cannot support it is a worse position than an honest 70 with a credible POA&M.
800-171 vs 800-53
The two documents are frequently confused and the confusion is expensive. NIST SP 800-53 is the comprehensive catalog: twenty control families, over a thousand controls and enhancements, tailored into low, moderate, and high baselines for federal information systems and FedRAMP cloud providers. 800-171 is derived from the 800-53 moderate baseline, with controls that are uniquely federal (physical security of federal facilities, for example) or that are the government's responsibility rather than the contractor's removed. What remains is the contractor's share of protecting CUI.
The practical consequences. An organization that has implemented 800-53 moderate has implemented 800-171 by construction. An organization that has implemented 800-171 has not implemented 800-53; it has implemented the subset a supplier needs. A risk register that carries 800-53 control IDs can produce an 800-171 crosswalk mechanically, because every 800-171 requirement cites its 800-53 source. The reverse is not true. This is why a register built on 800-53 is more useful to a defense contractor than one built on 800-171 alone: it serves the CMMC assessment today and the FedRAMP or prime-contractor flowdown tomorrow.
Revision 3: What Changed and When It Applies
Fewer Requirements, More Objectives
Rev 3 consolidates the 110 requirements into 97 and adds three families: Planning, System and Services Acquisition, and Supply Chain Risk Management. The consolidation is not a reduction in work. The companion assessment guide, 800-171A Rev 3, contains materially more determination statements than Rev 2, because Rev 3 eliminated words like periodically and limit in favor of organization-defined parameters. Where Rev 2 said review audit logs periodically, Rev 3 requires the organization to define the frequency, document it, and be assessed against it.
CMMC Still Assesses Against Rev 2
As of this writing, DoD's class deviation keeps Rev 2 as the standard for DFARS 7012 compliance and CMMC Level 2 assessment. DoD has placed a rule on its regulatory agenda to transition CMMC to Rev 3, and has published proposed organization-defined parameter values. Until that rule is final, assessment guides are reissued, and SPRS accepts Rev 3 scoring, contractors are assessed, scored, and certified against Rev 2. The right posture is to certify against Rev 2 and map the environment to Rev 3 in parallel, particularly the three new families, so the transition is a documentation exercise rather than a remediation project.
800-171 in Defense-Sector M&A
Defense and aerospace roll-ups are among the most active PE theses of the decade, and every target in them carries 800-171 exposure the buyer inherits at close. Three questions belong in diligence. First, what is the target's SPRS score, when was it posted, and can the SSP support it? An inflated score is a False Claims Act liability that transfers with the entity. Second, where does the target sit in the CMMC rollout, and which contracts will require Level 2 certification at their next option period? A target that cannot achieve certification before that date is at risk of losing the revenue the valuation assumes. Third, has the target's environment ever been assessed for active compromise, or only for control implementation? CUI that has already been exfiltrated is a disclosure event under DFARS 7012, which requires reporting within 72 hours, whether or not the SSP was accurate.
Post-close, the 100-day plan for a defense portco typically includes an independent 800-171 gap assessment, SSP reconciliation, and SPRS score correction. Correcting a score downward is uncomfortable. Leaving a known-inaccurate score in SPRS after acquisition converts the seller's misrepresentation into the buyer's.
Executive Implications
For a CFO, the SPRS score is a certification the company has made to its largest customer. For a GC, it is a representation that has been litigated under the False Claims Act, with the Department of Justice's Civil Cyber-Fraud Initiative pursuing contractors whose cybersecurity claims did not match their environments. For a board, 800-171 is a revenue-continuity control: on CUI contracts, the ability to bid depends on it. None of that requires understanding the 110 requirements. It requires knowing whether the SSP describes the environment that exists.
Related Reading
Real-World Example: The Score That Did Not Match the Tenant
A pattern that recurs in Cloudskope's defense-sector diligence work: a target posts an SPRS score in the high 90s or at 110, supported by an SSP prepared by a consultant, and the buyer accepts the score as evidence of posture. An independent assessment of the Microsoft 365 GCC High or commercial tenant then finds that the requirements scored as implemented (MFA for all users, audit logging with adequate retention, controlled use of privileged accounts, restrictions on external sharing) are partially implemented or exist as policy without enforcement.
The gap has two consequences. The immediate one is remediation cost, which is knowable and can be priced. The larger one is that the score posted to SPRS was a representation to the government that was not accurate, and the Department of Justice has settled False Claims Act cases on exactly that fact pattern. The buyer who closes without reconciling the score inherits the exposure. The buyer who finds it in diligence prices it, corrects it post-close, and has the documentation to show the correction was made in good faith.
Requirements in NIST SP 800-171 Revision 2 versus Revision 3. The count fell; the assessment burden rose, because Rev 3 replaced vague language with organization-defined parameters that must be documented and defended. CMMC assessments remain against Rev 2 until DoD completes rulemaking.
How Cloudskope Can Help
Cloudskope’s risk register is built on NIST SP 800-53, which means the 800-171 crosswalk is mechanical rather than interpretive: every finding already carries the control ID an 800-171 requirement cites. Cloudskope SARTUS™ assesses the Microsoft 365 or GCC High tenant, the endpoint estate, credential exposure, and active-compromise indicators in three days, then closes the identity, cloud, and logging gaps that most often hold up a Level 2 assessment in the next three. For sponsors in defense roll-ups, the same engagement reconciles the SPRS score to the environment before it becomes the buyer’s representation. See the framework mapping.
.png)