Protecting Controlled Unclassified Information CUI
Overview
Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations is critical to federal agencies. The suite of guidance (NIST Special Publication (SP) 800-171, SP 800-171A, SP 800-172, and SP 800-172A) focuses on protecting the confidentiality of CUI and recommends specific security requirements to achieve that objective.
- August 16, 2023: NIST issues a summary and analysis of the comments received on the initial public draft (ipd) of SP 800-171, Revision 3.
- June 15, 2023: Webinar on Protecting CUI: What's New in Draft SP 800-171, Revision 3 recording and presentation slides are available!
- May 31, 2023: Due to overwhelming interest, the webinar has reached capacity and we are unable to register additional participants at this time. Please note that the webinar will be recorded. Slides and the recording will be available online after the event.
- May 15, 2023: Registration for Webinar on Protecting Controlled Unclassified Information: What’s New in Draft SP 800-171, Revision 3 on June 6 at 1:00 PM Eastern is open. Space is limited, sign up today!
- May 10, 2023: NIST issues draft SP 800-171 Rev 3 for comment through July 14. Additional files include an FAQ, a detailed analysis of the changes between Revision 2 and Revision 3, and a prototype CUI Overlay.
- February 16, 2023: A status update on SP 800-171 Rev 3 is available.

NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, provides a set of recommended security requirements for protecting the confidentiality of CUI.
NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, provides assessment procedures and a methodology to conduct assessments of the CUI security requirements in NIST SP 800-171.
NIST SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171, provides enhanced security requirements to help protect CUI associated with critical programs or high value assets in nonfederal systems and organizations from the advanced persistent threat (APT).
NIST SP 800-172A, Assessing Enhanced Security Requirements for Controlled Unclassified Information, provides assessment procedures and a methodology to conduct assessments of the enhanced security requirements in NIST SP 800-172.
Project Links
Additional Pages
Created June 13, 2019, Updated August 16, 2023