NIST 800-171
Definition
NIST 800-171
NIST 800-171 is the US publication setting security requirements for controlled unclassified information held on non-federal systems. It exists because government data sits with contractors, which makes it the most outsourcing-shaped document that NIST now publishes.
Every other federal security publication addresses federal systems.
This one starts from a different fact — a great deal of government information lives on machines the government does not own, operated by companies it does not control, in buildings it has never visited.
The requirements are written for that situation specifically, which is why they turn up in so many commercial contracts.
Key takeaways
- The full title is Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.
- Revision 3 was published in May 2024, superseding Revision 2 from January 2021.
- The requirements are imposed through contracts rather than applying directly by law.
- Defence contracts impose them through DFARS clauses with a 72-hour incident reporting duty.
How it works
The publication is Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Revision 3 was published in May 2024, superseding Revision 2 from January 2021.
The mechanism is contractual, and NIST says so. The requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations.
So the obligation reaches a provider through a clause — there is no direct statutory duty on a commercial company to implement these requirements absent a contract imposing them.
Defence contracting is where they bite hardest. The defence acquisition rules carry clause 252.204-7012, alongside notice and assessment provisions at 252.204-7019 and 252.204-7020.
Two numbers from those rules matter operationally. Cyber incidents must be reported rapidly, defined as within 72 hours of discovery, and assessments must be current — not more than three years old unless the solicitation says otherwise.
| Element | What a contractor must do |
|---|---|
| Requirement source | Implement what the contract cites, at the cited revision |
| Assessment currency | Keep it under three years old |
| Incident reporting | Report within 72 hours of discovery |
| Subcontractor flow-down | Pass obligations down and collect report numbers |
| Revision cited | Check whether the contract names Revision 2 or 3 |
The revision question is a live one. Contracts written before May 2024 may cite Revision 2, and implementing the wrong revision is a compliance failure even when the newer one is stronger.
Examples
Controlled unclassified information travels into commercial systems constantly, and the requirements follow it through the contract chain. The four situations below are the ones that generate the most buyer confusion.
A manufacturer handling defence drawings implements the requirements because its contract cites them. Without the clause there would be no obligation at all.
A subcontractor receives flow-down terms and must report incidents up the chain. Its report number comes from the prime, which received it from the department.
A provider’s assessment is four years old when a new solicitation arrives. Currency is a stated requirement, so the stale assessment disqualifies it, which surprises government outsourcing bidders regularly.
An offshore delivery team handles covered information without anyone checking whether the arrangement was permitted. That is a vendor management outsourcing failure with contractual consequences.
Related terms
Federal information security spans catalogues, contract clauses, programmes and the general services around them. Each line below is one sentence, bounded so the next term stays properly distinct.
- Government outsourcing: public sector contracting, the route these requirements arrive by.
- Cybersecurity outsourcing: buying security capability to implement the requirements.
- Compliance outsourcing: delegating regulatory work, which does not remove a contractual duty.
- Information security analyst: the role implementing and evidencing the individual requirements.
- Vendor management outsourcing: running supplier assurance, including flow-down verification.
- Risk outsourcing: transferring exposure, which flow-down obligations specifically prevent.
- Data center outsourcing: the hosting arrangement covered information frequently sits in.
FAQ
What is controlled unclassified information?
Government information that requires safeguarding but is not classified. The category is defined in federal regulation and identified in the contract.
Which revision is current?
Revision 3, published in May 2024. It superseded Revision 2 from January 2021, though older contracts may still cite the earlier one.
Does the publication apply automatically?
No. It applies through contract terms. Federal agencies incorporate the requirements into agreements with non-federal organisations.
What is the incident reporting deadline?
Under the defence acquisition rules, cyber incidents must be reported rapidly, which is defined as within 72 hours of discovery.
How old can an assessment be?
Not more than three years, unless a shorter period is specified in the solicitation. Stale assessments can disqualify a bid.
Do subcontractors have to comply?
Yes, where obligations flow down. Subcontractors also pass incident report numbers up through the contracting tiers.
Start at Outsource Accelerator and check whether the information in scope is genuinely covered.







Independent




