Skip to content
Cyber Defense Technologies

Compliance

The 14 NIST SP 800-171 Families in Plain Language

A practical tour of the 110 requirements that protect Controlled Unclassified Information: what each control family asks for, what assessors look for, and where organizations most often fall short.

By Cyber Defense Technologies October 14, 2025 5 min read

If your organization handles Controlled Unclassified Information (CUI) for the Department of War (DoW), NIST Special Publication 800-171 is the standard you are measured against. DFARS 252.204-7012 requires it, and CMMC Level 2 assesses it. Revision 3 was published in 2024, but the Department has kept Revision 2, with its 110 requirements, as the contractual baseline.

The standard is written for security professionals. This guide translates each of its 14 families into plain language, with notes on what assessors expect to see.

NIST SP 800-171 Rev. 2 at a glance

security requirements
110
control families
14
points deducted per unmet requirement, by weight
5 · 3 · 1
starting score in the DoD Assessment Methodology
110

1. Access Control (22 requirements)

The largest family answers one question: can only the right people, processes and devices reach CUI, and only in the ways they should? It covers account management, least privilege, separation of duties, remote access, wireless access, mobile devices, session locks and controlling CUI on publicly accessible systems.

Common gaps: shared or generic accounts, users with administrator rights they rarely need, remote access that is not routed through managed, monitored points, and no records of periodic access reviews.

2. Awareness and Training (3 requirements)

People must understand the risks of their roles and be trained to spot threats, including insider threat indicators. Privileged users need role-specific training.

Common gaps: generic annual training with no insider threat content, and no evidence of who completed what and when.

3. Audit and Accountability (9 requirements)

Systems must create logs that can trace actions to individual users, protect those logs, review them, and alert when logging fails. Time sources must be synchronized so events can be correlated.

Common gaps: logs collected but never reviewed, no alerting on logging failures, and administrators who can delete the audit trail of their own actions.

4. Configuration Management (9 requirements)

Organizations must maintain baseline configurations and inventories, control and review changes, restrict nonessential software and functions, and apply least functionality.

Common gaps: inventories that do not match the network, no documented baselines, and change control that exists on paper but is bypassed in practice.

5. Identification and Authentication (11 requirements)

Users and devices must be identified and authenticated before access. This family includes multifactor authentication (MFA) for privileged accounts and for network access to non-privileged accounts, replay-resistant authentication, password complexity and reuse rules, and protection of stored credentials.

Common gaps: MFA that covers email but not administrative interfaces or VPNs, and service accounts with non-expiring, widely known passwords. MFA is a high-weight requirement; it must be met, not planned.

6. Incident Response (3 requirements)

Organizations must have an operational incident-handling capability covering preparation, detection, analysis, containment, recovery and user response. Incidents must be tracked, documented and reported, and the capability must be tested.

Common gaps: a plan that has never been exercised, and no connection between the plan and the 72-hour DoW reporting requirement in DFARS 252.204-7012.

7. Maintenance (6 requirements)

System maintenance must be performed and controlled, including tools, remote maintenance sessions and maintenance personnel without the required access. Equipment removed for off-site repair must be sanitized of CUI.

Common gaps: vendors with unsupervised remote access, and no process for sanitizing devices sent out for repair.

8. Media Protection (9 requirements)

CUI on paper and digital media must be protected, marked, controlled in transport, and sanitized or destroyed before disposal or reuse. Removable media use must be controlled, and CUI on portable storage encrypted.

Common gaps: unrestricted USB storage, and no records showing how retired drives were destroyed.

9. Personnel Security (2 requirements)

Individuals must be screened before being given access to CUI, and access must be removed promptly when people leave or change roles.

Common gaps: accounts that remain active weeks after departures, often because HR and IT processes are not connected.

10. Physical Protection (6 requirements)

Physical access to systems, equipment and operating environments must be limited to authorized individuals. Visitors must be escorted and monitored, access logs kept, and physical access devices managed. Alternate work sites, including home offices, need safeguards too.

Common gaps: no visitor logs, and no guidance for employees who handle CUI while teleworking.

11. Risk Assessment (3 requirements)

Organizations must periodically assess risk to operations, assets and individuals, scan for vulnerabilities on a schedule and when new vulnerabilities are identified, and remediate according to risk.

Common gaps: unauthenticated scans that miss most issues, and no evidence that findings are tracked to closure.

12. Security Assessment (4 requirements)

Organizations must periodically assess their controls, develop and implement plans of action to correct deficiencies, monitor controls on an ongoing basis, and maintain a System Security Plan (SSP) describing the boundary, environment and how each requirement is met.

Common gaps: SSPs written once for an audit and never updated. Without an SSP, an assessment cannot proceed.

13. System and Communications Protection (16 requirements)

The second-largest family covers the network and cryptography: monitoring and protecting boundaries, separating public-facing components, denying traffic by default, preventing split tunneling, protecting CUI in transit and at rest with FIPS-validated cryptography, controlling mobile code and VoIP, and protecting session authenticity.

Common gaps: flat networks where CUI systems sit beside everything else, and encryption that is enabled but not FIPS-validated.

14. System and Information Integrity (7 requirements)

Organizations must identify and correct system flaws promptly, protect against malicious code, monitor security alerts and advisories, and monitor systems to detect attacks and unauthorized use.

Common gaps: patching without timeframes, and monitoring that collects data but does not generate actionable alerts.

Where to start

Not every requirement carries the same weight. The DoD Assessment Methodology deducts 5 points for high-impact requirements such as MFA, incident response capability and FIPS-validated encryption, and only 1 point for many administrative ones. If you are building a remediation plan, close the 5-point gaps first, then the 3-point gaps.

Just as important: implement in a way you can prove. For every requirement, ask "What would I show an assessor?" If the answer is "nothing written down," you have found your next task.

Frequently asked questions

Do all 110 requirements apply to us? If you handle CUI in a system, all 110 requirements apply to that system. Some may not be applicable in specific circumstances, such as wireless requirements where no wireless exists, but that must be documented and verifiable.

What about Revision 3? NIST published Revision 3 in 2024, reorganizing the requirements. The Department of War continues to use Revision 2 as the contractual baseline for now.

How CDT can help

CDT's CMMC and NIST SP 800-171 readiness team performs evidence-based gap assessments, builds practical remediation roadmaps and implements the technical controls. Our free CMMC readiness self-check walks through the families in a few minutes.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.