// US Standards
NIST SP 800-171 Protecting CUI Compliance Software
Protecting Controlled Unclassified Information in non-federal systems. Aligned with NIST 800-53.
Framework at a glance
Short name
NIST 800-171
Version
—
Category
US Standards
Controls
110
What NIST 800-171 covers
110 controls across 63 domains — every one tracked, owned and evidenced in Cyber Horizon.
Access Control
7 controls- 3.1.1 Authorised access control
- 3.1.2 Transaction and function control
- 3.3.9 Limit audit management
- 3.4.5 Access restrictions for change
- 3.8.2 Limit media access
Data Flow
1 controls- 3.1.3 Control CUI flow
Separation of Duties
1 controls- 3.1.4 Separation of duties
Least Privilege
1 controls- 3.1.5 Least privilege
Privileged Access
2 controls- 3.1.6 Non-privileged account use
- 3.1.7 Prevent privileged function execution
Authentication
5 controls- 3.1.8 Unsuccessful logon attempts
- 3.5.2 User authentication
- 3.5.4 Replay-resistant authentication
- 3.5.11 Obscure authentication feedback
- 3.13.15 Communications authenticity
Policy
1 controls- 3.1.9 Privacy and security notices
Session
3 controls- 3.1.10 Session lock
- 3.1.11 Session termination
- 3.13.9 Network disconnect
Remote Access
4 controls- 3.1.12 Remote access control
- 3.1.15 Privileged remote access
- 3.7.5 Remote maintenance MFA
- 3.13.7 Split tunnelling prevention
Cryptography
3 controls- 3.1.13 Remote access cryptography
- 3.5.10 Cryptographic passwords
- 3.13.11 FIPS-validated cryptography
Network
3 controls- 3.1.14 Remote access routing
- 3.1.20 External system connections
- 3.13.1 Boundary protection
Wireless
2 controls- 3.1.16 Wireless access authorisation
- 3.1.17 Wireless access protection
Mobile
1 controls- 3.1.18 Mobile device management
Encryption
4 controls- 3.1.19 Encrypt CUI on mobile
- 3.8.6 Encrypt portable storage
- 3.13.8 Data in transit encryption
- 3.13.16 Data at rest
Media
5 controls- 3.1.21 Portable storage restriction
- 3.7.4 Check media
- 3.8.1 Protect media
- 3.8.7 Control removable media
- 3.8.8 Prohibit unidentified media
Data Handling
1 controls- 3.1.22 Control public CUI
Training
2 controls- 3.2.1 Role-based training
- 3.2.2 Insider threat awareness
Insider Threat
1 controls- 3.2.3 Insider threat training
Logging
5 controls- 3.3.1 System auditing
- 3.3.2 User accountability
- 3.3.3 Review and update events
- 3.3.6 Audit reduction
- 3.10.4 Maintain access logs
Monitoring
6 controls- 3.3.4 Alert on audit failure
- 3.10.2 Protect and monitor
- 3.12.3 Monitor security controls
- 3.14.3 Security alerts
- 3.14.6 Monitor for attacks
SIEM
1 controls- 3.3.5 Correlate audit review
Time Sync
1 controls- 3.3.7 Authoritative time source
Log Integrity
1 controls- 3.3.8 Protect audit information
Baseline
1 controls- 3.4.1 Baseline configurations
Hardening
3 controls- 3.4.2 Configuration settings
- 3.4.6 Least functionality
- 3.4.7 Non-essential functionality
Change Management
2 controls- 3.4.3 Track configuration changes
- 3.4.4 Security impact analysis
Application Control
1 controls- 3.4.8 Application execution policy
Software Control
1 controls- 3.4.9 User-installed software
Identity
2 controls- 3.5.1 User identification
- 3.5.5 Identifier management
MFA
1 controls- 3.5.3 Multi-factor authentication
Credentials
1 controls- 3.5.6 Authenticator management
Passwords
3 controls- 3.5.7 Password complexity
- 3.5.8 Password reuse
- 3.5.9 Temporary passwords
IR Plan
1 controls- 3.6.1 Incident handling
Reporting
1 controls- 3.6.2 Incident reporting
Testing
1 controls- 3.6.3 Incident response testing
Operations
2 controls- 3.7.1 Maintenance
- 3.7.2 Maintenance controls
Media Sanitisation
1 controls- 3.7.3 Equipment sanitisation
Personnel
1 controls- 3.7.6 Maintenance personnel
Disposal
1 controls- 3.8.3 Sanitise or destroy
Classification
1 controls- 3.8.4 Mark media
Backup
1 controls- 3.8.9 Protect backups
Screening
1 controls- 3.9.1 Screen individuals
HR
1 controls- 3.9.2 Personnel termination
Physical Access
1 controls- 3.10.1 Limit physical access
Visitors
1 controls- 3.10.3 Escort visitors
Remote Work
1 controls- 3.10.6 Alternate work sites
Risk Management
1 controls- 3.11.1 Risk assessment
Vulnerability Management
1 controls- 3.11.2 Vulnerability scan
Remediation
1 controls- 3.11.3 Remediate vulnerabilities
Assessment
1 controls- 3.12.1 Security control assessment
POA&M
1 controls- 3.12.2 Plan of action
Documentation
1 controls- 3.12.4 System security plan
Architecture
1 controls- 3.13.2 Architectural and design
Segregation
1 controls- 3.13.3 Role separation
Data Protection
1 controls- 3.13.4 Shared resource protection
Network Segmentation
1 controls- 3.13.5 Public access system separation
Firewall
1 controls- 3.13.6 Network communication deny-by-default
Key Management
1 controls- 3.13.10 Key management
Privacy
1 controls- 3.13.12 Collaborative device prohibition
Application Security
1 controls- 3.13.13 Mobile code
Communications
1 controls- 3.13.14 VoIP
Patch Management
1 controls- 3.14.1 Flaw remediation
Malware
3 controls- 3.14.2 Malicious code protection
- 3.14.4 Update malware protection
- 3.14.5 System scanning
How Cyber Horizon automates NIST 800-171
Every NIST 800-171 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is NIST SP 800-171 Protecting CUI?
Protecting Controlled Unclassified Information in non-federal systems. Aligned with NIST 800-53.
How many controls does NIST SP 800-171 Protecting CUI have?
NIST SP 800-171 Protecting CUI has 110 controls in Cyber Horizon's catalogue, organised across 63 domains.
How does Cyber Horizon help with NIST SP 800-171 Protecting CUI?
Cyber Horizon maps NIST SP 800-171 Protecting CUI into a shared control library alongside every other framework you run, so evidence collected once counts towards NIST 800-171 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More US Standards frameworks
See NIST 800-171 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of NIST 800-171 in Cyber Horizon.