NIST SP 800-171 is the National Institute of Standards and Technology publication that specifies how non-federal organizations must protect Controlled Unclassified Information stored, processed, or transmitted on their systems. It is the standard defense contractors are measured against, and it is the control catalog that CMMC Level 2 uses for its certification.
What does NIST SP 800-171 require?
Revision 2, the version DoD contracts point to today, defines 110 security requirements organized into 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. NIST published Revision 3 in May 2024, which restructures the families and adds organization-defined parameters, but the DoD CMMC program still runs on Rev 2. Contractors score their compliance using the DoD Assessment Methodology, out of a maximum of 110, and post the result to SPRS.
Who needs to comply with NIST SP 800-171?
Any non-federal organization that handles Controlled Unclassified Information under a federal contract. In practice that means the entire Defense Industrial Base: primes, subcontractors, and suppliers. The obligation reaches contractors through DFARS clause 252.204-7012, which has required 800-171 compliance since 2017, and it now flows down through CMMC. A subcontractor that receives CUI from a prime inherits the same requirement.
How does NIST SP 800-171 relate to CMMC?
800-171 is the catalog of controls. CMMC is the enforcement layer. For years contractors self-attested to 800-171, and DoD found that self-attestation was unreliable. CMMC Level 2 keeps the same 110 controls but adds a third-party assessment by a C3PAO and an Affirming Official who certifies the result. Same requirements, verified instead of asserted.
Why does NIST SP 800-171 matter for OT?
800-171 does not carve out the plant floor. When a CNC machine runs a CUI-bearing part program or an HMI displays controlled drawings, that asset is in scope for controls like access control (3.1), audit (3.3), identification and authentication (3.5), and denying network traffic by default (3.13.6). Most industrial equipment cannot meet those controls natively. The accepted answer is to move enforcement off the asset and onto the network, or to place the equipment inside a scoped CUI enclave so the requirement applies to a bounded environment.
How Access Gate helps
Access Gate carries several 800-171 families for OT assets that cannot carry them alone: identity and authentication (3.5) and access control (3.1) at the network boundary, audit logging (3.3) for devices that produce none, and deny-by-default communications (3.13.6) enforced by policy. It draws the enclave boundary in software instead of re-cabling the plant. See Defense & Government Contracting.

