NIST SP 800-171
The security control set for protecting CUI in nonfederal systems.
Definition
NIST Special Publication 800-171 defines security requirements across access control, incident response, and configuration management for contractors that store or process Controlled Unclassified Information.
Why it matters
Your self-assessment score against these controls is reported in SPRS and referenced during source selection.
Example
A contractor documents 110 controls in a System Security Plan with a POA&M for gaps.
Related terms
- Cybersecurity Maturity Model CertificationDoD's tiered cybersecurity certification for contractors.
- Controlled Unclassified InformationSensitive but unclassified government information requiring safeguards.
- Defense Federal Acquisition Regulation SupplementDoD's supplement to the FAR, including cybersecurity requirements.
Stop translating solicitations by hand
RFP Scribe reads the solicitation, builds the compliance matrix, and drafts a response from your Company Brain in minutes.
Start freeServices that help with this
Buy just the piece you need — most start at a few dollars, no subscription required.
RFP Plain-English Summary
$3Translate jargon-heavy solicitations into clear, actionable language.
Buy NowGovCon Masterclass — Basics
$99Video courses on capture, proposals, and pricing strategy.
Enroll NowCompliance & Readability Scan
$2Verify your proposal addresses every stated requirement.
Buy Now