Skip to main content
NIST Special Publication 800-171 establishes requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations. It is a mandatory requirement for US government contractors and subcontractors who handle CUI.

Who needs NIST 800-171?

Defense contractors

Companies in the Defense Industrial Base (DIB) that handle CUI from the Department of Defense.

Government suppliers

Any non-federal organization that stores, processes, or transmits CUI on behalf of US government agencies.

14 control families

How DSALTA helps

  • 110 security requirements mapped to NIST 800-171 control families
  • Gap assessment identifying missing controls
  • Evidence collection automated from integrations
  • Policy templates aligned with CUI protection requirements
  • Cross-framework mapping — strong overlap with SOC 2, ISO 27001, and CIS Controls
5 of DSALTA’s automated checks contribute evidence to this framework, drawn from 3 integrations. Browse them in the Compliance Tests catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

Frequently asked questions

CMMC (Cybersecurity Maturity Model Certification) builds on NIST 800-171. CMMC Level 2 aligns directly with NIST 800-171 requirements. Achieving NIST 800-171 compliance prepares you for CMMC Level 2 certification.
Currently, self-assessment is accepted, but CMMC 2.0 will require third-party assessments for Level 2 (equivalent to NIST 800-171). Prepare now for the transition.