Protect CUI without the spreadsheet
What is NIST 800-171?
NIST Special Publication 800-171 ("Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations") is a set of 110 security requirements that organizations must meet when they handle Controlled Unclassified Information on behalf of the US federal government. It is the operative standard underneath DFARS 252.204-7012 (and -7019/-7020/-7021), making it a baseline obligation for nearly every Department of Defense contractor and subcontractor.
The 110 controls are organized into 14 families and are derived from a tailored subset of NIST 800-53 controls. NIST published Rev. 3 in May 2024 — the current revision of the standard itself — but the Department of Defense still requires Rev. 2 (published 2020) for DFARS and CMMC compliance until a future rulemaking adopts Rev. 3. For defense contractors today, Rev. 2 remains the operative baseline.
Who needs 800-171
If you're a DoD prime or subcontractor handling Controlled Unclassified Information — or if you expect to be one — 800-171 applies to you. Many primes flow the obligation down to their entire supply chain via contract.
How episki helps
episki maps all 110 requirements to controls evaluated on every sync, derives the CMMC crosswalk through the SCF hub with recorded provenance, and turns a failing check into a POA&M item with an owner and a due date that syncs into Jira, Linear, or GitHub. The CUI boundary is enforceable through scope rules on cloud account, region, resource, and tag. Start a free trial or book a demo.
NIST 800-171 outcomes with episki
Why teams choose episki for NIST 800-171
- Access Control, Audit, AT, CM, IR, MA, MP, PE, PS, RM, CA, SC, SI
- Identification & Authentication, plus all enhancements
- Pre-built testing procedures per requirement
- SSP narrative composed from real controls
- POA&M items tracked to closure
- Self-assessment scoring per DFARS 252.204-7019/-7020
- CMMC Level 2 practice mapping
- C3PAO-friendly evidence packaging
- Reuse 800-171 evidence in your CMMC assessment
NIST 800-171 readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ 800-171 Rev. 2 control catalog at the requirement level
- ✓ SSP narrative generated from control evidence
- ✓ POA&M tracking with milestone management
- ✓ DFARS self-assessment scoring methodology
- ✓ Supplier Performance Risk System (SPRS) score export
- ✓ CMMC Level 2 practice mapping