← Back to Field notes
WINROVE / Compliance

NIST 800-171 Controls Every Contractor Should Know

NIST SP 800-171 has 110 controls across 14 families. Here's what they mean in plain English and how small contractors can implement them practically.

March 7, 2026 · Winrove Team

Cover illustration for NIST 800-171 Controls Every Contractor Should Know

Why NIST 800-171 Is Non-Negotiable for DoD Contractors

NIST Special Publication 800-171: "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations": is the cybersecurity standard that defines what it means to adequately protect CUI in the defense supply chain. It's required by DFARS 252.204-7012, referenced in CMMC Level 2, and increasingly cited in civilian agency contracts beyond DoD.

If you're a government contractor handling any information labeled CUI (or legacy labels like FOUO, Sensitive But Unclassified, or Law Enforcement Sensitive), NIST 800-171 applies to your IT systems. Understanding what each of the 14 control families actually requires: in practical terms: is the foundation of an effective compliance program.

The 14 Control Families: What They Require

1. Access Control (AC): 22 Controls

The largest control family, Access Control governs who can get into your systems and what they can do once inside. Key requirements:

  • Least privilege: Users get only the access they need for their job: not admin rights by default, not access to files unrelated to their work
  • Account management: Document who has accounts, terminate access promptly when employees leave, review access periodically
  • Remote access controls: Control and monitor remote connections; use VPN with MFA for any remote access to CUI systems
  • Mobile device management: Control what mobile devices can connect to your network and access CUI

Practical implementation for small contractors: Use Azure AD or similar identity management. Implement MFA for all accounts. Conduct quarterly access reviews. Terminate access within 24 hours of employee departure.

2. Awareness and Training (AT): 3 Controls

Requires that all personnel with access to CUI receive security awareness training, and that those with privileged access receive role-based training. Annual training for all, more frequent for admins and those handling CUI regularly.

What's commonly missed: Documentation. Training completion records must be maintained and available for audit. An untrained employee who "knows the material" doesn't satisfy the control.

3. Audit and Accountability (AU): 9 Controls

Create, protect, and review audit logs. Systems that process CUI must log user activity, failed access attempts, and system changes. Logs must be protected from unauthorized modification and retained long enough to investigate potential incidents.

Practical note: Many small contractors have no centralized logging. A SIEM (Security Information and Event Management) tool isn't required, but you do need logs from servers, workstations, and network devices consolidated somewhere reviewable.

4. Configuration Management (CM): 9 Controls

Establish and maintain secure baseline configurations for all CUI systems. Before making system changes, assess the security impact. Restrict unnecessary software, ports, protocols, and services.

What this means in practice: Document what software is authorized on your systems (whitelist). Use CIS Benchmarks or DISA STIGs as your baseline configuration guide. Implement a change management process: no undocumented changes to production systems.

5. Identification and Authentication (IA): 11 Controls

Verify who users are before granting access. Require complex passwords, implement MFA, manage authenticators (passwords, tokens, smart cards) carefully. This family has become more important as credential theft has become the dominant attack vector.

Bottom line: MFA everywhere. Unique accounts: no shared credentials. Password manager encouraged. Privileged accounts used only for privileged tasks.

6. Incident Response (IR): 3 Controls

Establish, maintain, and implement an incident response capability. This means having a documented incident response plan, training people on it, and testing it. For DoD contracts with DFARS 252.204-7012, you also have specific reporting obligations when cyber incidents affecting CUI occur.

The 72-hour rule: When a cyber incident affecting CUI is identified, DFARS requires you to report it to DoD within 72 hours via the DIBNet portal. Your IR plan must account for this requirement.

7. Maintenance (MA): 6 Controls

Perform, control, and monitor maintenance of organizational systems. Remote maintenance must be controlled and authenticated. Maintenance equipment (tools and diagnostic equipment) must be sanitized before use.

8. Media Protection (MP): 9 Controls

Protect CUI on physical media (drives, USBs, printed documents). Control access to media, sanitize or destroy media before disposal, and maintain accountability for media containing CUI throughout its lifecycle.

What's commonly overlooked: Printer output. Documents containing CUI printed from your systems must be treated as CUI media: secured, controlled, and properly destroyed.

9. Personnel Security (PS): 2 Controls

Screen individuals before authorizing access to CUI and ensure CUI access is terminated when an individual leaves. For cleared contractors, your personnel security program connects here: clearance is a form of personnel security screening.

10. Physical Protection (PE): 6 Controls

Limit physical access to CUI systems to authorized individuals. Control and monitor physical access. Protect and monitor CUI system infrastructure in alternate work locations (home offices, remote sites).

Remote work implication: If employees work with CUI from home, your physical protection controls extend to their home workspace. This is an increasingly complex area as hybrid work becomes standard.

11. Risk Assessment (RA): 3 Controls

Periodically assess risk to organizational operations and assets. Scan for vulnerabilities at defined frequencies. Remediate vulnerabilities in accordance with risk assessments. Annual vulnerability scans at minimum; quarterly is better practice.

12. Security Assessment (CA): 4 Controls

Periodically assess security controls, develop and implement plans of action to address deficiencies, monitor security controls on an ongoing basis. This is the foundation of your System Security Plan and Plan of Action & Milestones (POA&M).

13. System and Communications Protection (SC): 16 Controls

Protect communications and implement architectural decisions to prevent information leakage. Monitor and control communications at external boundaries. Implement subnetworks for publicly accessible system components. Encrypt CUI in transit and at rest.

Most practical requirement: Encrypt CUI at rest on all devices and in all storage systems. Use TLS 1.2 or higher for all network communications. This is table stakes and one of the first things assessors check.

14. System and Information Integrity (SI): 7 Controls

Identify, report, and correct system flaws in a timely manner. Deploy malicious code protection (antivirus/EDR). Monitor systems for attacks and indicators of potential attacks. Patch critical vulnerabilities within defined timeframes.

Patching requirements: Critical patches (CVSS 9.0+) within 30 days. High severity (CVSS 7.0-8.9) within 90 days. These timelines are benchmarks: document your patching process and any exceptions.

Starting Your NIST 800-171 Journey

If you haven't formally assessed your compliance with NIST 800-171, start with a gap assessment:

  1. Download the NIST 800-171 Self-Assessment Handbook (NIST 800-171A)
  2. Work through each control family systematically: Implemented, Partially Implemented, or Not Implemented
  3. For each gap, estimate the level of effort to remediate and assign a timeline
  4. Build your System Security Plan and POA&M from this assessment
  5. Submit your score in SPRS (Supplier Performance Risk System): required for DoD contracts

NIST 800-171 compliance is achievable for small contractors. It requires commitment, documentation discipline, and consistent maintenance: but it's not out of reach, and the investment protects your business and your contracts.

Preserved Field Notes article. Original path /blog/nist-800-171-controls-every-contractor-should-know/. No unrelated help guide has been substituted.

Related Field notes

Reading a DPAS Priority Rating on a Federal Order: What Contractors Must Know ↗

Wide Area Workflow (WAWF) Invoicing Basics for New Federal Contractors ↗

Provisional Billing Rates and Indirect Rate Structures, Explained Simply ↗

Cost Realism: Surviving the Government Price Analysis ↗

The compliance matrix step most small contractors skip (and how it loses bids) ↗

NAICS Code Selection and Recertification: Avoiding the Small-Business Size-Standard Trap ↗