What Is NIST 800-171 Compliance?

Posted November 14, 2022 by Nist Expert

Doing business with the Department of Defense (DoD) or other government agencies means ensuring your organization can effectively protect sensitive information in today’s environment of ever-increasing cybersecurity threats and the appropriation of business intelligence.

To codify contractors’ obligations in a set of required best practices, the National Institute of Standards and Technology (NIST) created NIST Special Publication (SP) 800-171 which details critical cyber security compliance initiatives to safeguard the government’s Controlled Unclassified Information (CUI). This is information that is not classified but is critical to the DOD and government operations and needs to be handled in a highly secure manner.

Why is NIST 800-171 Compliance Crucial?

The federal government has a long history of engaging private contractors, suppliers, and vendors — in fact, almost two-thirds of the government-wide contracting budget in 2020 was for defense contractors providing products and services totaling more than $400 billion. This army of contractors includes primary businesses as well as subcontractors and suppliers that number in the hundreds of thousands reaching around the world.

With so many participants and a growing reliance on cyber technology, there needed to be a way to guard CUI against bad actors and foreign adversaries that engage in industrial espionage as it relates to military aircraft, weapons systems, or armaments design.

Charged with creating standards for those non-government entities that do business with the DoD, NIST, a federal agency within the U.S. Department of Commerce, developed NIST SP 800-171 compliance. This protocol is meant to secure the processing, storing, and transmitting of sensitive information or CUI, as well as secure the physical access to facilities where design and manufacturing take place. This can include (but is not limited to):

  • Electronic files
  • Designs and specifications
  • Proprietary information
  • Emails and attachments
  • Hard-copy documents
  • Access to facilities and monitoring guests while on site
  • Double custody handling of CUI

How NIST SP 800-171 Was Developed

Understanding the breadth of the contractor compliance process and the need to streamline inconsistent standards in use by various government agencies, NIST incorporated rules for data handling, safeguarding, transmitting, and disposal of CUI and Federal Contract Information (FCI) into NIST SP 800-171. As with any government rule expansion, there was a period of public comments and input from interested parties before final standards were issued.

Finalized in 2015, NIST defined these areas to provide a framework for implementing and managing a contractor’s system security plans:

  • Identify — Understand potential cybersecurity risks to assets, data, systems, and capabilities.
  • Protect — Implement all appropriate safeguards to ensure the secure delivery of critical infrastructure services.
  • Detect — Implement appropriate detection activities to quickly identify a cybersecurity breach event.
  • Respond — Create a plan to take action once an event has been detected.
  • Recover — Create a process to restore services and capabilities as quickly as possible.

To that, we would add a sixth activity:

  • Continuous Monitoring — Cybersecurity issues are fluid with new and more complex criminal activities evolving all the time. Keep your organization well-protected by engaging an ongoing NIST 800-171 compliance partner who would be responsible for continuous and concurrent monitoring and detection processes that can evolve as technological capabilities expand.

How to Comply with NIST 800-171

NIST SP 800-171 brings together both administrative and technical requirements to protect CUI. These compliance requirements entail 110 controls within 14 specific areas that focus on systems and communications protection, access control and personnel security, risk assessment, and physical/technical infrastructure protections.

Keep in mind that these requirements are more than simply IT-related functions — they also address policies, procedures, and processes as they relate to sensitive information. NIST 800-171 includes these 14 domains or areas of control:

  1. Access Control
  2. Awareness and Training
  3. Audit and Accountability
  4. Configuration Management
  5. Identification and Authentication
  6. Incident Response
  7. Maintenance
  8. Media Protection
  9. Personnel Security
  10. Physical Protection
  11. Risk Assessment
  12. Security Assessment
  13. System and Communications Protection
  14. System and Information Integrity

Achieving implementation and compliance within these multiple domains can take a significant amount of time (up to 6 or more months) in which time your organization may be at risk of losing government contracts.

By incorporating an expert NIST partner, that time can be reduced significantly. Look for a NIST partner that has the expertise and capabilities to offer fast auditing and implementation services so that you don’t miss any revenue opportunities.

What is the Cybersecurity Maturity Model Certification (CMMC)?

Up until 2020, contractors were required to perform a self-assessment and submit their score on an honor system to the DoD. However, in 2020, the DoD announced that audits of contractor self-assessment scores showed that while contractors were in compliance there were perceived shortcomings in their actual performance.

With that, the DoD initiated a new Cybersecurity Maturity Model Certification (CMMC) program of standards that featured a verification component meant to enhance accountability and minimize barriers to NIST 800-171 compliance. As CMMC continued to evolve, November 2021 saw an updated CMMC 2.0 released with three maturity levels including all 110 controls and more.

What are Supplier Performance Risk System Scores?

The new expectations also saw a formalized reporting structure with Supplier Performance Risk System Scores (SPRS) that must be completed and posted for a company to be eligible for consideration in government contracting opportunities. Scores ranging from -203 (meaning you haven’t complied) to +110 let the DoD understand your security compliance efforts and are used to determine contract awards.

In addition to their SPRS score, each company has to submit a System Security Plan (SSP) and a Plan of Actions and Milestones (POAM) demonstrating their overall efforts at compliance.

Because of the complexity of CMMC’s requirements and posting a good SPRS score, it’s important to accelerate your company’s adoption of NIST 800-171 and CMMC 2.0 rather than wait until mandatory deadlines are imminent.

NIST SP 800-171 is Not an Option

Any companies that do business with the federal government, whether contractors, sub-contractors, vendors, or suppliers, are required to comply with NIST SP 800-171. Even if your organization doesn’t actually handle the CUI, you are still subject to flow-down requirements mandated by the primary contractor.

As CMMC continues to evolve, it’s likely that primary contractors will institute more stringent reviews of their sub-contractors, vendors, and suppliers since they are materially affected by non-compliance. Plus, misrepresenting compliance is a violation of the False Claims Act and penalties can include:

  • Loss of existing contracts
  • Loss of future contracting capabilities
  • Heavy monetary fines
  • Criminal charges

Getting Started with NIST SP 800-171 Compliance

Becoming compliant requires quickly finding your baseline SPRS score, assessing potential risk points in your system, designing and deploying SSP and POAM, and managing ongoing compliance in a changing cybersecurity environment. The protocols can be time intensive to implement and you don’t want to let government contract opportunities slip away.

The ultimate overreaching goal is to strengthen the federal supply chain while ultimately protecting national security. However, achieving implementation and compliance on a per-company basis may take a significant amount of time (up to 6 or more months).

Partnering with a NIST 800-171 expert allows you to quickly understand any gaps in your cybersecurity system and your physical facility protocols, fill in those gaps and enhance your overall compliance, and rest easy knowing there is ongoing monitoring and maintenance in place.

Contact Business Lens to learn more about our discovery audit that micro-analyzes your business landscape and returns a detailed report in as soon as a week.