NIST SP 800-171 controls are a set of security requirements that protect Controlled Unclassified Information, or CUI, when it lives on the systems of a company that is not a federal agency. If your business handles data for a defense contract, a manufacturing supply chain, or another government program, these controls define what “good enough” security looks like. The confusion for most small and mid-sized businesses is rarely the controls themselves. It comes from three quieter questions: which of my systems are even in scope, what counts as CUI, and which version of the rule I am being measured against. Answer those three, and the rest gets manageable fast.
The 5 Things SMBs Get Wrong About NIST 800-171
Most SMBs walk into NIST 800-171 assuming it is a technical checklist they can hand to their IT person. It is not. Here is what our compliance team sees trip up owners and operators most often, and what each one really means for a 20 to 500 person firm.
- Scope is a boundary problem, not a control problem. The hardest work is drawing a line around the systems that touch CUI, before you touch a single setting.
- CUI is broader than “classified.” It is unclassified information the government still wants protected, and it hides in email, spreadsheets, and shared drives.
- The version matters. Revision 2 carried 110 requirements across 14 families. Revision 3 reorganizes to 97 requirements across 17 families, and contracts differ on which they cite.
- A score is not a pass or fail. The DoD self-assessment starts at 110 points and subtracts for gaps, so you report a number, not a gold star.
- Documentation is half the job. A System Security Plan and a Plan of Action and Milestones are required artifacts, not optional paperwork.
What NIST SP 800-171 Controls Actually Cover
NIST SP 800-171 controls cover the practices a non-federal organization uses to keep CUI confidential, grouped into families that each address one area of security. Think of the families as chapters. Access control governs who can reach what. Identification and authentication governs how people and devices prove who they are. Audit and accountability governs what gets logged. Configuration management governs how systems are set up and kept consistent. The remaining families cover incident response, media handling, physical protection, personnel screening, risk assessment, and the systems that carry your data.
The number of families changed between versions, and that alone causes a lot of head-scratching. Revision 2 used 14 families. Revision 3 splits and adds a few, landing at 17, including a dedicated family for supply chain risk and one for planning. The practices did not get easier. They got reorganized to line up more closely with the broader federal control catalog. If you want the side-by-side on how these requirements map to certification, our breakdown of the differences between CMMC and NIST 800-171 walks through where the two frameworks meet.
Access Control and Authentication in Plain Terms
Access control and authentication decide who gets in and how they prove it, and this is where a surprising number of SMBs already have most of the answer. In agreement with the framework, if you run Microsoft 365 or a similar business platform, you likely have the building blocks: role-based permissions, conditional access, and multi-factor authentication. In opposition, having the features turned on is not the same as configuring them against the specific practices the framework names, such as limiting failed login attempts or enforcing session lock. Both things are true at once. You are further along than you fear, and there is still deliberate configuration work to do. The identification family alone spells out unique IDs for every user and device, MFA for network and privileged access, and protection against replayed credentials. We cover how that plays out under certification in our piece on identification and authentication controls.
Audit, Configuration, and System Integrity
Audit, configuration management, and system integrity are the families that ask you to prove your environment behaves predictably over time. On one hand, these read as routine IT hygiene: keep logs, patch systems, maintain a known-good baseline, scan for vulnerabilities. Many firms already do a version of this. On the other hand, the framework wants evidence that it happens on a schedule and that someone reviews the output, which is a governance habit smaller teams often skip. Neither reading is wrong. The practices are ordinary; the discipline of recording and reviewing them is what auditors actually check. This is why compliance so often turns out to be a governance and infrastructure question, not only an IT security one.
Media Protection, Physical Security, and People
Media protection, physical security, and personnel practices round out the families and remind you that CUI does not only live in the cloud. Supporters of a purely technical approach argue that if the data is encrypted and access-controlled, the physical layer matters less. The counterpoint is that a printed report left on a desk, an unwiped hard drive, or an unscreened contractor with server-room access all sit outside your firewall entirely. We hold both views without picking a side, because the right emphasis depends on how your firm handles CUI day to day. A design shop that prints fabrication drawings has a different physical exposure than a software vendor that never puts CUI on paper.
Why Scope and CUI Cause the Most Confusion
Scope and the definition of CUI cause more confusion than any single control, because they determine how much of the framework you have to apply at all. CUI is unclassified information that a law, regulation, or government policy still requires you to safeguard. It is not secret in the classified sense, which is exactly why people miss it. Contract technical data, engineering drawings, personally identifiable information tied to a federal program, and certain research all qualify. The trouble is that this information rarely stays put. It arrives by email, gets copied into a shared drive, ends up in a project folder, and quietly expands your footprint.
Scope is the act of drawing a boundary around every system that stores, processes, or transmits that CUI. Do it well, and you can shrink the number of systems in scope, which shrinks the number of controls you must satisfy and the cost of proving it. Do it loosely, and your entire network falls in scope, which means every laptop and every mailbox now has to meet the framework. Our compliance team spends the first phase of nearly every engagement here, because a tight boundary is the single biggest lever an SMB has. A well-designed cybersecurity compliance program starts by isolating CUI into a defined enclave rather than sprawling it across the business.
How NIST 800-171 Connects to CMMC and Your Score
NIST SP 800-171 controls are the technical backbone of CMMC Level 2, so the two frameworks are related but not identical. CMMC is the Department of Defense certification program that verifies a contractor actually meets the controls, while NIST 800-171 is the requirements list those controls come from. Level 2 of CMMC maps directly to the 110 requirements in Revision 2, and assessors confirm them rather than take your word. If you contract with the DoD or sit in a defense supply chain, you are almost certainly being measured against both. Our CMMC certification services exist to close that gap between the paper requirement and a verified result.
The scoring model is where the “pass or fail” instinct breaks down. The DoD self-assessment methodology starts you at 110 points and subtracts weighted values for each control you have not fully implemented, so the result is a score that can land negative. You submit that number, along with your System Security Plan and a Plan of Action and Milestones that lists what you still owe and when you will finish it. A partial score with a credible remediation plan is a normal, reportable state. We often pair the technical work with a zero-trust architecture so the score improves structurally rather than through one-off fixes, and we treat compliance as one outcome of a broader cybersecurity practice rather than a standalone project. For firms that want compliance to extend past this one framework, our view on compliance beyond a single standard shows how the same controls carry over to HIPAA and SOC 2.
Frequently Asked Questions
How many controls are in NIST SP 800-171?
NIST SP 800-171 Revision 2 contains 110 security requirements organized into 14 families, while Revision 3 reorganizes the material into 97 requirements across 17 families. The count difference reflects restructuring, not a reduction in effort. Check your contract to confirm which revision you are being held to, because both are still cited in the field in 2026.
Is NIST 800-171 the same as CMMC?
No, though they are closely linked. NIST 800-171 is the list of security requirements, and CMMC is the Department of Defense program that certifies you have met them. CMMC Level 2 maps to the 110 requirements in NIST 800-171 Revision 2, and an assessor verifies compliance rather than accepting a self-attestation for higher-trust contracts.
What is CUI under NIST 800-171?
CUI, or Controlled Unclassified Information, is unclassified information that a law, regulation, or government-wide policy still requires an organization to protect. It includes contract technical data, engineering drawings, and certain personal and research information tied to federal programs. Identifying every place CUI lives is the first step in defining what falls under the controls.
Do I need to meet every control to win a contract?
Not always at first. The DoD self-assessment produces a score from a 110-point baseline, and you can report a partial score alongside a Plan of Action and Milestones that commits to closing the gaps on a timeline. Many contracts allow a documented remediation path, though the acceptable score and deadline depend on the specific award.
Can an SMB implement NIST 800-171 without a large IT team?
Yes. Most of the confusion for smaller firms is scope and documentation, not raw technical difficulty, and a tight CUI boundary keeps the number of systems in scope small. Working with a compliance partner lets a lean team meet the requirements without hiring a dedicated security staff, which is a common path for the SMBs we support.
Talk Through Your NIST 800-171 Scope With Us
NIST SP 800-171 stops being confusing the moment you separate the three questions that actually drive the work: what is my CUI, which systems touch it, and which version of the rule applies to my contract. Answer those, and the 110 requirements turn into a defined, scorable project instead of a wall of jargon. Our team has guided small and mid-sized firms through exactly this, drawing tight boundaries so you satisfy the controls that matter without dragging your whole network into scope. We handle the System Security Plan, the Plan of Action and Milestones, and the technical implementation as one connected effort, and we have done it across industries from manufacturing to healthcare, including the firms behind our CMMC compliance work in Florida. If a defense contract or supply-chain requirement is pushing NIST 800-171 onto your desk, book a free strategy call and we will map your scope, your score, and your fastest realistic path to meeting the requirements.

