Governance Briefing — NIST publishes SP 800-171 Revision 2
NIST issued Special Publication 800-171 Revision 2, keeping the existing 110 security controls for protecting Controlled Unclassified Information while setting the stage for assessment procedures. Defense and federal contractors must align their system security plans and POA&Ms to the unchanged control set ahead of CMMC assessments.
Executive briefing: NIST released Special Publication 800-171 Revision 2. The update retains the 110 security requirements for safeguarding Controlled Unclassified Information (CUI) in contractor systems and clarifies that assessment procedures are documented separately in SP 800-171A.
Why it matters
- Steady requirements: Contractors cannot defer control implementation on the assumption of new requirements; the baseline remains unchanged.
- Assessment alignment: DoD’s CMMC and self-attestation efforts reference the same control set, so SSPs and POA&Ms must stay accurate.
- Federal audits: Agencies can continue to enforce the established control set in grants and contracts without revision delays.
Operator actions
- Update documentation: Confirm your SSP, POA&M, and inheritance statements map to the unchanged Rev. 2 controls.
- Prepare for assessment: Align evidence to NIST SP 800-171A assessment objectives ahead of CMMC readiness reviews.
- Flow down: Communicate the steady control expectations to subcontractors handling CUI and update contract language accordingly.
Continue in the Governance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Public-Sector Governance Alignment Playbook — Zeph Tech
Align OMB Circular A-123, GAO Green Book, OMB M-24-10 AI guidance, EU public sector directives, and UK Orange Book with digital accountability, risk management, and service…
-
Third-Party Governance Control Blueprint — Zeph Tech
Deliver OCC, Federal Reserve, PRA, EBA, DORA, MAS, and OSFI third-party governance requirements through board reporting, lifecycle controls, and resilience evidence.
-
Governance, Risk, and Oversight Playbook — Zeph Tech
Operationalise board-level governance, risk oversight, and resilience reporting aligned with Basel Committee principles, ECB supervisory expectations, U.S. SR 21-3, and OCC…




