NIST SP 800-171 Is Now More Important Than Ever: Are You Following the Framework?

Sep 26, 2019 | Cyber Security, IT News

The National Institute of Standards and Technology, more commonly referred to as NIST, puts out extremely important guidelines to follow, and we have covered those guidelines at length in past articles. However, there have been quite a few changes since we last wrote about them. Today, we’re putting out a refresher on the subject for readers who are unfamiliar with NIST compliance, as well as sources for some of the more recent, important updates to NIST standards.

What Is NIST?

Officially, the National Institute of Standards and Technology is a non-regulatory government agency that develops technology, metrics and standards to drive innovation and economic competitiveness at U.S.-based organizations in the science and technology industry. As part of this effort, NIST produces standards and guidelines to help federal agencies meet the requirements of the Federal Information Security Management Act, or FISMA. NIST also assists those agencies in protecting their information and information systems through cost-effective programs.

In a nutshell, NIST guidance provides a set of standards for recommended security controls for information systems at federal agencies. These standards are endorsed by the government, and companies comply with NIST standards because they encompass security best practices controls across a range of industries

Why Is NIST Compliance Important?

NIST SP 800-171 Is Now More Important Than Ever: Are You Following the Framework?Organizations of all types are increasingly subject to data theft and loss, whether the asset is customer information, intellectual property or sensitive company files. IT is not security, and security is not IT. Information security is about trying to protect information, while IT is about information sharing. You must have IT, and you need security, otherwise you’re only doing half the job. It’s about finding the balance between the two.

A comprehensive set of standards, methodologies, procedures and processes that align policy, business and technical approaches to address cyber risks is needed to protect both your organization and your customers.

What Are the Latest Revisions to NIST Guidelines?

The original version of SP 800-171 appeared in 2015 and provided 110 recommended requirements to ensure the confidentiality of Controlled Unclassified Information, or CUI, residing on the computers of contractors and other organizations that interact with the government. The original document, titled Draft NIST Special Publication (SP) 800-171 Revision 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, now has a new draft companion publication, NIST SP 800-171B, that offers additional recommendations for CUI in situations where that information runs a higher-than-usual risk of exposure. CUI includes a wide variety of information types, from individuals’ names and Social Security numbers to critical defense information.

NIST requirements should be applied far beyond the world of government contracting — especially in critical infrastructure systems. By adopting the NIST framework, you are taking an incredibly important step toward securing not only your business, but the privacy and trust of all who do business with you. Call us to ensure your organization is meeting those standards.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Cybersecurity Fatigue Is Real: How to Keep Employees Engaged Without Burnout

Employees play a critical role in cybersecurity, but constant warnings, training reminders, password prompts, and security alerts can lead to fatigue. This blog explains how small businesses and government contractors can keep employees engaged with cybersecurity without overwhelming them.

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic