---
title: "What Is NIST SP 800-171? CMMC Definition"
description: "NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2."
url: https://policycortex.com/cmmc/glossary/nist-800-171
sealed: 2026-07-02
amended: 2026-09-03
register: cmmc/glossary/nist-800-171
records: 3
digest: sha3:5bb790e86688ac7b9d66688d80160f9c03b9b73b9f288fa45650c64d19046851
---

# What is NIST SP 800-171?

Register / Glossary

NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2.

Sealed 2026-07-02 · Amended 2026-09-03

NIST Special Publication 800-171 defines 110 security requirements across 14 control families, from Access Control to System and Communications Protection. CMMC Level 2 is, in practice, an assessment against these 110 controls.

Revision 2 remains the assessment baseline under DoD's current class deviation. Revision 3 restructures the families and introduces Organization-Defined Parameters, but CMMC has not yet moved its assessment baseline to Rev 3.

Each control is scored, and unimplemented controls subtract points from a maximum of 110 — which is how an environment that feels 'mostly compliant' can produce a deeply negative SPRS score.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [CUI: Controlled Unclassified Information](https://policycortex.com/cmmc/glossary/cui): CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. |
| [SPRS: Supplier Performance Risk System](https://policycortex.com/cmmc/glossary/sprs): SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations. |
| [SSP: System Security Plan](https://policycortex.com/cmmc/glossary/ssp): An SSP is the document describing how an organization implements each required security control across its in-scope environment. |
| [POA&M: Plan of Action and Milestones](https://policycortex.com/cmmc/glossary/poam): A POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates. |
| [NIST 800-171 Cloud Compliance Guide](https://policycortex.com/blog/nist-800-171-cloud-compliance-guide) |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: 2026-09-03
- **Record**: https://policycortex.com/cmmc/glossary/nist-800-171

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | aff2611bd0ac | 16a60f665d9c |
| REC 0001 | DEFINITION | 7a6acaf1e5f2 | aff2611bd0ac |
| REC 0002 | RELATED RECORDS | 5bb790e86688 | 7a6acaf1e5f2 |

Head sha3:5bb790e86688ac7b9d66688d80160f9c03b9b73b9f288fa45650c64d19046851. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
